From data center switches and ceiling-mounted wireless access points to network access control and multi-site connectivity, we handle planning, installation, and acceptance in one project. Offices in Taipei and Kaohsiung. We conduct a site survey before deployment, then propose an architecture based on site conditions and existing equipment.
An "enterprise network" breaks down into six things. The plain-language explanation below should let you work out roughly which piece you're missing.
The row of metal boxes in the data center that every network cable in the company plugs into. Besides connecting computers, printers, and cameras, it can power devices directly over the network cable (PoE, Power over Ethernet), so ceiling equipment doesn't need a separate power run.
The white discs on the ceiling. Three things set them apart from a home router. Dozens of them can automatically coordinate channels and power without interfering with each other. People can walk from the first floor to the fifth without dropping the connection. And they can run three separate wireless networks at once for staff, guests, and IoT devices, each with different permissions.
The brain that manages a whole fleet of wireless access points. It also serves as the network gateway between a branch office and headquarters, handling VPN (virtual private network) encrypted tunnels and traffic policy.
The network's access card reader. When a device plugs into a cable or joins the Wi-Fi, it is asked three things first: who are you, what device are you, and is your status compliant. Only then is it allowed through, and to which network segment.
When a company has three sites, such as Taipei, Kaohsiung, and a factory, it connects several ordinary network lines at once (including 4G/5G). Software decides which line is running best and routes traffic there. If one line goes down, operations don't grind to a halt.
One web page handles configuration, monitoring, and reporting for every device. New equipment applies its configuration automatically as soon as it's plugged in. IT doesn't need to travel to a branch office just to change one setting.
Nobody notices the network on an ordinary day. It usually only comes up for discussion when one of the following signals appears.
The equipment is discontinued. There are no spares if it fails, and firmware is no longer updated. When this kind of equipment fails, an entire floor often goes offline at once.
Video calls stutter, things collapse once a room fills up, and connections drop the moment someone walks into a meeting room. Usually the signal isn't too weak; the number, placement, and channel planning of access points was simply never done properly.
ISO 27001, customer supply-chain security questionnaires, and the Cyber Security Management Act (which applies to government agencies and specific non-government agencies designated by the competent authority) tend to ask the same question: "Do you know what devices are currently connected to your internal network?"
The number of network ports, rack layout, PoE wattage, and fiber routing all have to be decided before the interior design is finalised. Fixing this after the fact costs the most.
Sites are still paying for expensive leased lines, or each site buys and maintains its own equipment separately. The costs and the labor hours both stack up.
There is no "which vendor is better" in enterprise networking, only "which architecture fits your site and team better". We currently work mainly with the following two architectures.
The core is the FortiGate firewall. Switches (FortiSwitch) and wireless access points (FortiAP) can be managed directly from it, so one appliance is simultaneously a firewall, SD-WAN, switch management platform, and wireless controller. Every device runs on the same FortiOS and shares one management console, so procurement and maintenance go through a single point of contact. Suited to organizations with many sites, limited IT staff, and security compliance as the main goal: small and mid-sized enterprises, retail chains, and manufacturing sites.
From core data center switches and ceiling-mounted Wi-Fi 7 access points to network access control (ClearPass) and WAN connectivity (HPE Networking EdgeConnect), switching, wireless, access control, and WAN all come from the same vendor. The Central platform provides unified management and operations analytics, with an on-premises version available for organizations that cannot use the cloud. It has two particular strengths: wireless performance in high-density environments, and visibility across hundreds of devices. Suited to a single large site: an office building, campus, school, hospital, or large manufacturing site, and organizations with a dedicated network team.
Starting point: if your network is "many small sites", Fortinet's integrated architecture is usually more economical; if it's "one very large site", HPE Aruba Networking's wireless depth and network management breadth pay off better.
That's only a starting point. Floor layout, usage density, whether existing equipment can be reused, and rack power and space can all change the conclusion. We conduct a site survey before deployment, then propose an architecture based on floor layout, usage density, and existing equipment conditions. For a fuller comparison of scenarios, see the Enterprise Networking Selection Guide. For each vendor's product line, see the Fortinet and HPE Aruba Networking brand pages.
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.
NAC (Network Access Control) is the network's access-control system. The moment a device connects to the network, it verifies identity, identifies the device type, and checks its status, then assigns it to the appropriate network segment based on its role. A guest, for example, can only get online and cannot touch internal systems; a camera can only reach the recording server.
Organizations are usually asked to do this for two reasons:
Both architectures can do this, but the approach differs. Fortinet's FortiSwitch has built-in access control, which the vendor states does not require a separate license. HPE Aruba Networking's ClearPass can manage equipment from other vendors and supports the standard authentication protocols RADIUS and TACACS+. So even if your existing network is a different brand, you can still put access control in place first and plan a replacement later.
For NAC, device inventory and policy design take the most time; installation is secondary. The standard approach is to run in "log only, don't block" mode for a period. Once devices are classified and the exception list is complete, blocking is enabled by zone and by stage.
From site survey to annual maintenance, the same team of engineers handles all five stages. For details on how we work, see Services.
Headcount isn't the only factor. What matters is three things: whether you have multiple floors or sites that need consistent management, whether an audit requires you to retain connection logs, and whether a Wi-Fi outage would directly affect operations. If none of these apply, consumer-grade equipment can genuinely still hold up. If any one of them applies, enterprise-grade equipment is worth the investment.
Not necessarily. A common approach is to handle it in layers: replace the core and aggregation layers first, phase the access layer in by floor, and decide on wireless based on generation and current coverage. Equipment still under warranty with adequate performance can stay and be folded into the new management structure. How much can actually be reused depends on the model, firmware version, and port count.
Both vendors already have Wi-Fi 7 models in production, but two things need checking first. One: Wi-Fi 7's main benefit comes from the 6 GHz band, and Taiwan's regulatory status and available power limits for that band need to be confirmed before proposing anything. Two: once access points are upgraded, access-layer switch port speeds and PoE wattage usually need to be upgraded at the same time, and the budget has to account for both. For a fuller planning approach, see the related articles in Insights.
Risk is managed through staging. The standard approach is to run in "log only, don't block" mode first. Once device inventory and the exception list are complete, blocking is enabled by zone and by stage. Internal communication during deployment matters as much as the technical configuration.
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance. Our core value lies in architecture planning and on-site delivery, not in the equipment itself.
Networking, security, and data center architecture often need to be planned together, so these related topics may also be worth a look.
Web & API Protection (WAF) Hyperconverged Infrastructure & VMware Alternatives InsightsLeave your contact details and a description of your needs, and an engineer will get in touch to help assess architecture planning, installation approach, and annual maintenance scope.