How to choose enterprise networking? First check whether your network is many small points or one large point

Multi-site chains and factories need a different kind of network from a single large campus. This page does not score vendors; it simply lays out both approaches.

"Which vendor is better?" has no answer. What actually makes the difference is not the spec sheet, but your site and your team.

Start with a current-state review: answer these seven questions first

The starting point for selection is your current situation, not a product catalog.

  1. How many sites? One headquarters, three retail stores, or five plants? This is the first yardstick.
  2. How many people per site, and how dense? 200 people spread across three floors calls for a completely different wireless design than 200 people packed into one open office.
  3. How many access points? The number of access points (APs, the ceiling-mounted discs that broadcast Wi-Fi) is the most practical scale indicator.
  4. How many switches, and do you need PoE? A switch sits behind the network jack and routes traffic; PoE (Power over Ethernet) delivers power to APs and cameras over the same network cable.
  5. Do you have dedicated network staff? A single MIS person covering the whole company needs a different architecture than a team of two or three.
  6. When does existing equipment go out of warranty? This determines the replacement pace and whether to phase it across years.
  7. Are there audit requirements for NAC? Both the Cyber Security Management Act and ISO 27001 may call out network access control specifically. Under a compliance deadline, this can flip the priority order.

Write down answers to these seven questions and the selection is already half done.

Two approaches: networking built out from the firewall, and networking built out from Wi-Fi

No vendor is inherently better. Only some architectures fit your site and team better than others. The seven dimensions below carry no scores.

Many small points

Multi-site operations, retail chains, small-to-medium offices, factories. Many locations, each modest in scale.

One large point

A single large campus, school, hospital, or office building. Few locations, high usage density.

Where the product started

Fortinet is networking built out from the firewall. Its core is the FortiGate next-generation firewall (NGFW, a firewall that can identify applications and user identity); switches and access points were later folded into the same system, centered on security policy. HPE Aruba Networking is built out from enterprise Wi-Fi, centered on connection quality and visibility.

Site type

Fortinet is more common in multi-site operations, retail chains, and factories; HPE Aruba Networking is more common in large campuses, schools, and hospitals.

A rough scale threshold

A single site with roughly 50 or fewer APs and under 10 switches usually sits comfortably within Fortinet's range. With roughly 50 or more APs and 10 or more switches, HPE Aruba Networking's advantage in wireless tuning and management breadth becomes clear. This is only a rough spectrum.

The customer's main pain point

Talk of "security must pass," "IT headcount is thin," or "the budget needs to hold" points to Fortinet. Talk of "Wi-Fi absolutely has to work well" or "we need visibility into network conditions" points to HPE Aruba Networking. Most customers mention all of these, so rank them: which one is the real reason the budget was approved.

Management architecture

Fortinet follows a firewall-as-controller model: a single FortiGate acts as firewall, SD-WAN (software-defined wide area network) node, switch management platform, and wireless controller, with no separate controller or management platform to buy. Per vendor documentation, the NAC built into FortiSwitch is not licensed separately either. HPE Aruba Networking follows a cloud management model, using the Central platform for unified configuration, monitoring, and reporting.

Procurement and quoting

Fortinet means one vendor, one quote, one warranty, with fewer contacts to manage. HPE Aruba Networking typically prices hardware and cloud subscriptions separately, letting you adjust each item as needed.

On-premises deployment options

Some public-sector, financial, and regulated organizations are not allowed to keep network configuration and logs in an overseas cloud. Fortinet's on-premises options are FortiManager and FortiAnalyzer; HPE Aruba Networking offers Central On-Premises (COP) or a virtual private cloud. Both vendors have an answer, but we recommend adding this to your evaluation criteria from the start.

"Many small points" usually favors an integrated architecture with less to manage; "one large point" makes wireless depth and management breadth pay off more.

NAC can come first

If you have not settled on a direction yet, there is a low-threshold move with a visible payoff: start with NAC. NAC (Network Access Control) acts as the network's gatekeeper. When a device tries to join the company network, the system first verifies who you are, what device it is, and whether it meets policy, then grants access by role: guests can only reach the internet, cameras can only reach the recording server.

  • Low threshold: you do not need to replace the whole network first.
  • Visible payoff: the first scan usually turns up a batch of devices nobody can identify.
  • Audit credit: most audits ask how access control is implemented, and this is the easiest place to produce evidence.

There are two approaches. If your environment already has FortiGate and FortiSwitch, you can use their built-in NAC capability directly. When the network is multi-vendor, HPE Aruba Networking ClearPass Policy Manager is an option: the vendor explicitly states support for multi-vendor environments and the RADIUS and TACACS+ authentication protocols, integration with 150 third-party systems, and a Cloud Auth option for a cloud-based path.

It also forces out a complete device inventory, which is exactly the data that replacement planning usually lacks.

Selection assessment and deployment process

We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.

1
Site survey
An on-site look at floor layout, how building materials affect signal, the server room location, and existing cabling.
2
Wireless coverage assessment
Estimate AP count and placement from floor plans and occupancy density, with on-site testing when needed.
3
Existing equipment inventory
Record model numbers, firmware versions, and warranty expiry dates to decide what stays and what gets replaced first.
4
Architecture design and product selection advice
A recommendation with clear reasoning, including a phased multi-year approach and a TCO (total cost of ownership) estimate.
5
Build and migration
Rack mounting, cabling, installation, configuration tuning, cutover, and migration of existing settings.
6
Training and annual maintenance
Documentation handover and interface training; the annual maintenance contract provides business-hours support, troubleshooting, and periodic health checks.

The equipment list is proposed based on site survey results and actual requirements.

Related reading

Current-state review and wireless coverage assessment can start with scheduling a site survey.

Book a site survey See our services

Contact us about enterprise network planning

Leave us your number of sites, headcount, and a summary of your existing equipment, and an engineer will contact you to arrange a site survey and wireless coverage assessment.

Send an enquiry
LINE Ask us on LINE