Every switch and wireless refresh starts as a hardware comparison and ends as a licensing argument. That is the wrong sequence. Over a realistic seven-year life, the acquisition price of the hardware is usually the smallest line in the total, and in some models it is under a fifth of the spend.
What follows is the model we use when a client asks us to evaluate a campus refresh across these four vendors, the cost categories that decide the outcome, and an honest read on where each vendor puts the money.
Disclosure, because it matters when you read a comparison: BlackHawk Data is a Fortinet Platinum Partner (with EPSP, ETSP and OT specializations), a Cisco Premier Partner and an Arista Elite Partner. We are not an HPE Aruba partner. We have deployed and operated all four. Read the framework and apply your own numbers — the methodology is the part that transfers.
The six categories that make up lifecycle cost
Most TCO spreadsheets have two columns: hardware and support. That is why most TCO spreadsheets are wrong by a factor of two.
1. Hardware acquisition. The number on the quote. Discounting is deep and varies by vendor, program, deal registration and timing. Treat list price as a unit of comparison, not a prediction.
2. Software licensing. Whether features you rely on are in the base image or behind a tier, and whether that tier is perpetual or a subscription with an expiry date. This is the category with the widest variance between these four vendors.
3. Support and maintenance. TAC access, RMA, firmware. Support commonly runs from roughly 8% of list per year at entry tiers to over 20% at premium tiers with onsite and fast replacement. Compounded over the asset life, support frequently accounts for 50–80% of the total cost of the asset — more than the hardware ever cost.
4. Operations labour. The hours your team or your provider spends configuring, patching, troubleshooting and documenting the estate. Nobody puts this in the spreadsheet and it is often the largest real number. A platform your team already knows costs less to run than a cheaper one they do not.
5. End-of-life exposure. Hardware rarely fails at seven years; support ends. The refresh trigger is a vendor date, not a failure rate. What matters is the gap between end-of-sale and last-day-of-support, and what you lose at each milestone in between.
6. Exit cost. What it costs to leave. Co-terminated subscriptions, licence portability, configuration lock-in and whether hardware keeps forwarding packets when the subscription lapses.
What happens at end of life — and why it drives the budget
Enterprises typically refresh switching every five to seven years, driven by support expiry and capacity, not by equipment dying. Physically, most of these switches will run for a decade.
The milestones matter individually, because each one changes what your support contract actually buys:
| Milestone | What you lose |
|---|---|
| End of sale | Cannot buy more of the same model; spares market only |
| End of new feature releases | Platform is frozen; new capability requires new hardware |
| End of routine bug fixes | Only critical security fixes remain |
| End of vulnerability support | No more security patches — this is the real deadline |
| Last day of support | No TAC, no RMA |
The date that belongs in your budget is end of vulnerability support, not last-day-of-support. Running network infrastructure that will never receive another security fix is a risk decision, and in regulated environments it is an audit finding. Most organizations discover this eighteen months too late to plan the capital.
Where each vendor puts the cost
Cisco
Cisco's model concentrates cost in subscription licensing plus support. Catalyst switching splits capability across Network Essentials and Network Advantage tiers, with management and automation licensing layered above. Indicative list pricing for a three-year term on a 48-port access switch runs roughly $1,300 for the entry tier to $4,000+ for the advantage tier, with wide variance by model, term and agreement structure. Add support at 8–22% of hardware list annually.
What you get for it is the deepest feature set, the largest installed base, the widest talent pool and a mature automation platform. What you pay for it is complexity: tier boundaries that are genuinely hard to predict at design time, and renewals that arrive as a significant recurring commitment. Meraki changes the shape again — a single co-terminated subscription covering hardware, features and support, simple to administer, all-or-nothing on true-ups, and with hardware that stops functioning when the subscription lapses.
Choose it when: you need the ecosystem breadth, you have Cisco-skilled staff, or a compliance or integration requirement names it.
Fortinet
Fortinet's model concentrates cost in the firewall, then extends outward at low incremental cost. FortiSwitch and FortiAP managed through FortiLink become logical extensions of the FortiGate, which removes the separate wireless controller and its licensing from the design entirely. Access point cloud management and security services typically land in the $50–120 per AP per year range where they are needed at all.
Licensing is modular: perpetual with annual support, or term bundles (UTP, ATP, Enterprise) that you can stagger or strip down to services you actually use. That flexibility is real and is the main commercial argument for the platform.
The trade is architectural gravity. The economics are excellent when the FortiGate is the centre of the design and less compelling when it is not. Two operational notes worth planning around: SSL-VPN is being deprecated in favour of IPsec and ZTNA, so any remote-access design should assume that change; and campus scale beyond a few hundred access points deserves a design review rather than an assumption that the model extends linearly.
Choose it when: security and networking are converging in your estate, the branch or campus is FortiGate-anchored, or OT segmentation is a first-class requirement.
HPE Aruba
Aruba's historical advantage was licence-light switching — several lines shipped with lifetime warranty and no per-switch licence — and that legacy still shapes procurement expectations. The current direction is toward subscription: Aruba Central Foundation and Advanced tiers, sold on fixed terms of one to ten years, commonly in the $100–250 per AP per year range for wireless management.
Wireless is where Aruba is strongest, and the ten-year term option is genuinely useful for organizations that want to fix a cost curve for a full lifecycle rather than renegotiate every three years.
Choose it when: wireless is the centre of gravity, or long fixed-term pricing has real budgetary value to you.
Arista
Arista's model is the most transparent of the four: the vast majority of EOS features are in the base software cost, with CloudVision as the principal additional subscription. Wireless management (CV-CUE) sits in the $100–200 per AP per year range. There is no meaningful tier-decoding exercise at design time, which removes an entire category of procurement risk.
The operational argument is stronger than the licensing one. A single consistent operating system across the estate and a genuinely API-first posture reduce the labour category — the one nobody measures. Historically a data-center vendor, Arista's campus portfolio is now mature, but the ecosystem and the talent pool are smaller than Cisco's.
Choose it when: you want predictable licensing, you operate the network as code, or you already run Arista in the data center.
Building your own model
Do not accept a vendor's TCO slide. Build this in a spreadsheet, seven-year horizon, and be honest in every cell:
- Hardware, at the discount you will actually receive — get it in writing.
- Licensing, for the full term, including the renewal at year three or five. Model the renewal at a higher rate than today's; that is what has happened consistently.
- Support, per year, at the tier your SLA genuinely needs. Most organizations buy a higher tier than they use at the access layer and a lower tier than they need at the core.
- Labour, honestly. Estimate hours per year for patching, changes and troubleshooting, multiply by loaded cost. If your team does not know the platform, add training and a productivity ramp.
- Refresh trigger, from published end-of-vulnerability-support dates for the exact models quoted.
- Exit, at year seven: what is stranded, what is portable, what stops working.
Then run the sensitivity that changes decisions more than any other: what happens if licence pricing rises 15% at renewal and your headcount does not grow? Models that look close at signature diverge sharply under that question.
The uncomfortable conclusion
Across the four, the seven-year totals for a comparable campus land closer together than any vendor's slide deck suggests. What differs is where the cost sits and when it arrives:
- Cisco — highest recurring licensing, deepest capability, largest talent pool.
- Fortinet — lowest incremental cost per access-layer device when the firewall anchors the design; commercially flexible.
- Aruba — wireless-led, subscription-trending, long fixed terms available.
- Arista — most predictable licensing, lowest operational overhead, smallest ecosystem.
The decision should turn on which cost curve fits your funding model and which platform your team can operate without heroics — not on the hardware quote. And whichever you choose, put the end-of-vulnerability-support date in the capital plan the day you sign.
BlackHawk Data builds these models for clients as part of an architecture review, and our network health check covers the installed base and its lifecycle exposure. Vendor practice detail is at Fortinet and intelligent networking.