Skip to content

WestPoint · Networks · HPE Aruba Networking

Its strength is not the switch. It is knowing who has just plugged in.

High-end switching and Wi-Fi with a speciality that in video is worth gold: that every device identifies itself when it connects and ends up on the network it belongs to, even if it is plugged into the wrong port.

What kind of manufacturer it is, and how you recognise it.

HPE Aruba Networking — Switching and Wi-Fi with network access control. And that last part is what really sets it apart.

Aruba competes at the high end with solid equipment and with prices somewhat below the reference brand, but what it clearly puts first is control over who enters the network. It has a product dedicated to that and they have spent years building around the same idea: the network is not a pile of ports, it is a list of who can talk to what, and an unidentified device should not reach anywhere.

What it gives up, looked at honestly, is universality of knowledge: there are fewer people in the market who know how to configure this than the reference brand, and that matters the day somebody has to be replaced. In exchange, its modern switching system is convenient to automate and its programming interface is well made, which is what lets an IT team with few people run a lot of equipment.

You recognise it on campuses: universities, hospitals, large corporate headquarters, public administrations, places with a lot of Wi-Fi and a lot of people coming in with their own device. Where the network's problem is the identity of what connects, not the number of ports.

How it is administered.

Three routes, and here the interesting one is the third.

There is a command line, there is a web interface on the equipment itself and there is centralised management from the manufacturer's cloud to administer many sites from one screen. The three live together, and unlike a cloud-only brand, the network carries on working and can still be touched locally if the connection to the cloud goes.

The third route is the one that changes the work: the whole configuration is available as a programming interface, so a change can be described in a file and applied to forty cabinets, and it can be checked from outside that the network is as the document says. Anyone administering hundreds of ports notices it straight away; anyone with two switches is never going to use it, and it is worth knowing that before paying for it.

Where it fits well in a security installation.

At the access layer of a large campus, and there its speciality solves a real security problem that almost nobody raises: the camera as a way in. A camera is a small computer hanging from a pole within arm's reach. If somebody unplugs it and puts their laptop into that cable, on a normal network they are inside. With identification at the port, the laptop is not the camera, it does not identify itself, and it gets nowhere.

The other way round is just as useful day to day: the camera identifies itself and the switch puts it on the camera network automatically, on whichever port it is. That means the electrician moving a camera cannot get the network wrong, and that nobody has to go and reconfigure a port every time a point is moved. In an installation of hundreds of cameras that is a lot of hours and a lot of mistakes that do not happen.

Where we would not put it.

In small installations. Everything that makes it valuable — identification at the port, automation, managing many sites — is governance infrastructure, and in an industrial unit with thirty cameras there is nothing to govern: cameras have to be powered and the traffic taken to a recorder. You pay a lot for capabilities nobody is going to switch on.

What really decides things in a video project.

Five. The first two are about power, because that is where things go wrong most.

  • The power budget, and how much is left when a power supply fails. Here the high end gives generous numbers and that does not excuse you from the sums: the total is set by the power supply installed, and with redundant power it is worth calculating with a single one, because the night the other one dies the surveillance cannot switch off.
  • The fine negotiation of the power, which is a concrete advantage of the high end and is always wasted. The switch reserves watts according to the class the camera declares, not according to what it uses, so with cameras that declare a lot and use little the budget runs out on paper before it does in reality. If the camera knows how to negotiate its real consumption with the switch, more cameras fit on the same unit. It has to be switched on and checked camera by camera, and then the saving is a whole switch.
  • The identification of the camera at the port, done properly and with a plan B. It is the headline function and it has small print that has to be resolved in the design: what happens if the service that decides who gets in is not available. If the answer is that the cameras are left off the network, you have built an installation that goes down when a server goes down. A fallback behaviour is configured and it is tested by switching that server off, not by reading about it.
  • How long a cut takes to recover. Two units behaving as one and grouped links give recovery of under a second, which is what is needed for the recorder not to lose the cameras' sessions. That is checked on commissioning day, by unplugging a cable with the stopwatch in your hand and writing down how many seconds of recording are missing afterwards.

Licences and subscriptions, and what happens when they expire.

There are two different things and it is worth separating them. The switch and the Wi-Fi access point are bought, and they work. What goes by subscription is the centralised management in the cloud and the support, with tiers according to what you want to see and how long the data is kept.

When that subscription expires, the equipment does not stop: it carries on switching and carries on giving power. What you lose is the central screen, the history and the right to support and to new firmware. The network stays administrable locally, which is very different from being left without a network, and it is a difference worth knowing when brands are compared.

The part that controls who enters the network carries its own licence by number of devices or users, and there you do have to think about it: if the installation depends on that service for the cameras to get onto their network, the licence stops being an administrative extra and becomes part of how it works. It is sized by counting the cameras, which are devices like any other, and it is put in writing who renews it and when.

Who administers it when we leave.

Here there is almost always an IT team, and this brand is designed for that team to be in charge.

Where there is Aruba there is normally an IT department with judgement, with written security rules and with a way of working. The healthy thing is for the network to carry on being theirs entirely, including the part the cameras pass through: it is their network, and the cameras are devices connected to it.

The boundary that falls to us is narrow and clear: from the camera to the port, the power, the throughput that has to be guaranteed and the behaviour we need from the video system. From the port onwards, them. And the agreement is written down: which network the cameras go on, how they identify themselves, what happens if the identification service does not answer, how many watts we reserve, how much sustained traffic we ask for and what can talk to what.

That last list is what turns a difficult meeting into an easy one. An IT department running a campus network has no appetite at all for putting two hundred devices from another trade inside it, and they are right. Turning up with the sums done and with a specific request changes the conversation. And if what they offer us does not reach what is needed — because the power does not stretch, because the path narrows or because we are asked to mix traffic — it is said in writing, with numbers and before signing. It is not argued with opinions.

What we do, and what we do not promise.

We have no contractual relationship with the manufacturer to tell you about, and we are not going to tell you this one is better than another. What we can demonstrate in the first technical meeting is that we know what happens to a campus when you hang four hundred cameras off it.

What gets decided before choosing a network brand

Get started

A large campus and hundreds of cameras?

Tell us how many buildings there are, how many cameras per building, what is fitted today and what security rules your IT department has. The first thing we will do is the power and traffic sums, and a list of what we need from their network. With that the meeting lasts half an hour.