HPE Aruba Networking enterprise networking

From server-room switches to ceiling-mounted Wi-Fi access points, one brand covers all five layers of enterprise networking. Switches, access points, and gateways can all be managed centrally through Central. Suits new builds and replacements for a single large site.

HPE ARUBA NETWORKING — CAMPUS NETWORK
The complete five layers of campus networking
Switches, access points, gateways, network access control, and WAN all come from the same brand. Switches, access points, and gateways can be managed centrally through Central.
CX Series switches Wi-Fi 7 access points Central cloud management (including on-premises edition) ClearPass network access control EdgeConnect SD-WAN

What this is

HPE Aruba Networking is the enterprise networking brand of Hewlett Packard Enterprise (HPE). It is one of the leading enterprise networking brands worldwide. Its predecessor was founded in 2002, starting out in enterprise Wi-Fi. It was acquired by HP in 2015, later moved to HPE when HP split into two companies, and was formally renamed to its current brand name around 2022 to 2023.

It specializes in campus networks: office buildings, plants, schools, and hospitals - large physical spaces where many people and many devices need to be online at the same time. The hard part in these environments is not bandwidth. Hundreds of devices need to coexist without interference, users walking from the first floor to the fifth must not lose connection, and the network needs to tell an employee apart from a visitor or a camera.

Enterprise networking is usually split into five layers: switches, access points, gateways, network access control (NAC), and WAN (SD-WAN), with a management platform on top. SD-WAN is software-defined WAN: it connects branch offices using broadband, 4G/5G, and other ordinary internet lines instead of expensive leased lines. What sets HPE Aruba Networking apart is that it has its own product for all five layers plus the management platform. Customers do not have to deal with five vendors, five consoles, and five maintenance contracts at once. For what each layer does, see Enterprise Networking.

We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.

Main products

Below is a plain-language overview of the vendor's product line. Actual model numbers and feature scope depend on project size and deployment method, and are confirmed item by item during planning.

CX Series switches (AOS-CX operating system)

The same operating system runs from the front door to the server room. Every network cable plugs into it, and it can power devices directly over the cable (PoE, Power over Ethernet), so ceiling-mounted access points and cameras need no separate power source. The campus line includes CX 6000 / 6100 / 6200 / 6300 / 6400 / 5420. CX 4100i is an industrial-grade model suited to factory floors and high-heat, high-vibration environments. CX 8100 / 9300 / 10000 are core and data center class; the CX 10000 has a built-in distributed firewall that can micro-segment virtual machines at the switch layer. Micro-segmentation splits traffic into many small zones, so a compromised host cannot spread laterally.

PoE powerIndustrial-grade 4100i25G / 100G
Wi-Fi 7 access points (750 / 740 / 730 / 720 series)

Per the vendor's specifications, the flagship 750 series has dual 10 Gbps network ports, with a combined peak rate of up to 28.8 Gbps. It also has dual built-in IoT radios that can act directly as a Bluetooth / Zigbee IoT gateway, saving the cost of building a separate sensor network. The difference from a home router is that tens to hundreds of units can be deployed together, automatically coordinating their channels and power. Users stay connected while moving around.

Wi-Fi 7High-density environmentsIoT radios
HPE Aruba Networking Central cloud management

One web console manages all switches, access points, and gateways: configuration, monitoring, troubleshooting, and reporting. Unbox a new device, plug in the network cable, and it applies its configuration automatically. There is also a Central On-Premises edition and a private-cloud deployment option. For public-sector bodies and financial institutions that cannot use the public cloud, and manufacturers with data residency requirements, this is a key condition.

On-premises COPData residencyUnified reporting
ClearPass Policy Manager (network access control / NAC)

Before any device connects to the company network, it answers three questions: who are you, what kind of device are you, and is your status compliant. Permissions are then assigned by role - for example, a guest can only access the internet, and a camera can only reach the recording server. The vendor states that ClearPass can manage devices that are not HPE Aruba Networking equipment. It supports both RADIUS and TACACS+ authentication protocols and can integrate with 150 types of third-party systems. It can be deployed without replacing existing equipment first, which usually makes it the best starting point.

Multi-vendor environmentsBYODAudit evidence
HPE Networking EdgeConnect SD-WAN and HPE Aruba Networking unified SASE

Connect several ordinary internet lines at once, and the system decides in real time which one to use, so losing one line does not mean losing connectivity. EdgeConnect has a built-in next-generation firewall and intrusion detection and prevention (IDS/IPS). It can replace a branch office's existing traditional firewall. unified SASE brings SD-WAN and cloud security services (SSE, including zero-trust access, ZTNA) together in a single console.

Multi-link failoverBranch firewallZTNA
UXI experience sensor (User Experience Insight)

A small box that plugs into a wall socket. It continuously simulates a real employee, repeatedly testing whether Wi-Fi connects, whether cloud services load, and whether video calls stutter. Its purpose is to resolve the standoff where users say the network is slow and IT says the equipment is fine: it points directly to whether the problem is the wireless signal, DNS, or the application itself.

Objective measurementMultiple sitesOperational evidence
Naming note: the vendor now labels the EdgeConnect product line as "HPE Networking". Other product lines are labeled "HPE Aruba Networking". This page and proposal documents follow the current naming used on each of the vendor's product pages.

Division of labor with web protection (WAF)

EdgeConnect's built-in next-generation firewall and the secure web gateway provided by SSE both protect traffic where employees and devices connect from inside out. Attacks launched from outside against websites and APIs fall under a different protection layer.

A web application firewall (WAF) handles SQL injection, cross-site scripting, bot traffic, and DDoS. These attacks target externally facing services and sit at the application layer. It belongs to a different product category from campus network protection, and the two are complementary.

For web and API protection requirements, see Web & API Protection (WAF), which covers the corresponding product selection and use cases.

Who this suits

The value of this product line comes from scale and density: the more devices and the higher the user density, the more operating time centralized management saves.

A single large site

Office buildings, corporate campuses, universities and K-12 schools, hospitals, and large plants. The common feature is high user density and large physical space, where wireless coverage is the main engineering challenge.

A dedicated networking team or clear owner

The depth of this architecture comes from its tunable detail: wireless spectrum, role-based policy, segmentation rules. It delivers the most value when a dedicated person takes over maintenance. Related configuration and operating documentation is handed over in full during training.

Values long-term stability and an international brand

Organizations that need to justify procurement decisions to a board, parent company, or auditor, especially listed companies and Taiwan branches of foreign firms. HPE is a major international vendor with a branch office in Taiwan.

Another common scenario: many sites, each small, lean IT staff, with security compliance and budget control as the main concerns. In that case, a firewall-centric all-in-one network architecture is a better fit. For the difference between the two architectures and how to choose, see Enterprise Networking and How to choose enterprise networking.

We carry out a site survey before deployment, then make recommendations based on site conditions, usage density, and existing equipment.

Also pairs well with hyperconverged infrastructure

Hyperconverged infrastructure (HCI) is an architecture that combines compute, storage, and virtualization in one server cluster. It needs a set of high-speed data center switches underneath, typically a 25G / 100G leaf-spine architecture. A leaf-spine architecture uses two layers of switches so that any two servers are the same short distance apart. HPE Aruba Networking CX 8100 / 9300 / 10000 fill exactly that role.

The CX 10000 in particular has a built-in distributed firewall that can isolate east-west traffic between virtual machines directly at the switch layer. Traffic no longer needs to route out to the perimeter firewall and back. For customers migrating off VMware who are asked to provide evidence of VM isolation, this is a practical combination.

When planning a virtualization platform replacement, whether to upgrade the underlying network bandwidth at the same time should be assessed in the same architecture plan. Do not wait until the cluster is live to discover the switches have become the bottleneck. See Hyperconverged Infrastructure & VMware Alternatives for details.

Scope of services

We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.

1
Requirements interviews and architecture planning
Site survey, wireless coverage assessment, inventory of network port and PoE power requirements, and rack and server room layout. Model recommendations are based on the vendor's published product lifecycle and support end-date information. Also includes POC validation and TCO (total cost of ownership) estimation.
2
On-site build and installation
Rack mounting, cabling, switch and access point installation, AOS-CX and Central configuration tuning, VLAN and role policy configuration, and cutover. A VLAN is a virtual local area network that splits one set of physical equipment into logical segments that cannot reach each other.
3
System migration
Migration of configuration, VLAN, and authentication policy when replacing existing switches and wireless equipment, with a phased cutover to reduce downtime risk.
4
Training and knowledge transfer
Training on the Central management console, guidance on maintaining ClearPass policy, day-to-day inspection procedures, and documentation handover. The goal is for your own IT staff to handle routine work independently.
5
Annual maintenance contract
Business-hours support, troubleshooting, periodic health checks, firmware version management, and vendor renewal handling.

If your organization already uses an integrated operations management platform (such as Hitachi JP1), Central alerts can be forwarded via standard syslog or API into the overall operations view. This is an integration through standard interfaces, not a vendor-certified integration package. For the full range of services, see Services.

FAQ

Is this suitable for a company of around thirty people?

This product line's value comes from unified management of large numbers of devices and high-density wireless environments. For smaller sites, we generally recommend a firewall-centric all-in-one architecture. See How to choose enterprise networking for how to decide.

Does Central have to keep data in the cloud?

Not necessarily. Besides the cloud edition, there is a Central On-Premises edition and a private-cloud deployment option, suited to public-sector bodies, financial institutions, and manufacturers with data residency requirements. Available features vary by deployment method and are confirmed item by item during planning.

My existing network equipment is a different brand. Can I deploy just ClearPass first?

Yes. The vendor states that ClearPass supports multi-vendor environments and both RADIUS and TACACS+. So network access control can be deployed first, without replacing existing switches and access points, to close the gaps most often flagged in audits. Equipment replacement can then be planned gradually afterwards.

Is it worth deploying Wi-Fi 7 now?

Two things need checking first. First, much of Wi-Fi 7's benefit comes from the 6 GHz band. Its availability and permitted power in Taiwan directly affect real-world performance, so current regulatory conditions should be confirmed before proposing a solution. Second, once access points are switched to Wi-Fi 7, the uplink bandwidth and PoE power of the switches underneath also need assessing. Replacing just the access points often does not deliver the expected result.

How is cost estimated?

Cost breaks down into three parts: hardware is mostly a one-time purchase, hardware also needs a separate vendor support contract, and Central and EdgeConnect/SSE are subscriptions. When a subscription lapses, some management features may be limited. This is the kind of issue that often only surfaces in year three; the actual features affected are confirmed item by item against the vendor's licensing documentation. During planning we build a TCO estimate covering all three parts together, not just the hardware price. Actual figures are estimated based on real project scale; this website does not list prices.

What is your company's relationship with HPE Aruba Networking?

GN-AI is an independent systems integrator. We source vendor products and support through authorized channels in Taiwan. This website is not authorized, sponsored, or endorsed by the vendor.

Trademark notice: HPE and HPE Aruba Networking are trademarks of Hewlett Packard Enterprise Company and/or its affiliates. GN-AI has no affiliation with HPE.

← Back to Brands

Contact us about enterprise networking planning

Leave your contact details and a description of your needs. An engineer will contact you to help assess the architecture plan, deployment approach, and annual maintenance scope.

Send an enquiry

Want to start with a health check to see whether your current network can keep up?

Contact us See Enterprise Networking
LINE Ask us on LINE