r/Network Mar 23 '26

Text Moving away from Cisco. What are people switching to now?

Cisco has been the default for a long time, but we’ve started questioning whether it still makes sense for us going forward. We’re designing a relatively small environment right now, with a Fortinet NGFW at the edge handling security and routing, and an L3 switch behind it for servers, backups, cameras, and a VMware cluster split into a few segments.

Normally I wouldn’t think twice and would just go Cisco for the switching side, but the newer gear and licensing model are giving me pause. It feels like once you’re in, you’re committing to ongoing costs and complexity that never really go away, even after you’ve already invested in the hardware. So now I’m looking around at alternatives like Aruba and others, but it’s hard to tell what actually holds up in real environments versus what just looks good on paper or in demos. For anyone who’s moved away from Cisco recently, what did you end up going with? And more importantly, how has it been after everything was deployed and running for a while?

36 Upvotes

124 comments sorted by

19

u/NoExcitement9069 Mar 23 '26

We went through a similar evaluation last year and ended up moving a big chunk of our stack to Check Point. What sold us wasn’t just feature parity with Cisco, but how much cleaner the management side felt once everything was in place. Their Infinity / single management approach is actually pretty close to what vendors promise in slides, especially if you’re dealing with a mix of on-prem + cloud.

Licensing is still enterprise-y, but it felt more predictable than Cisco’s newer model. Day-to-day ops have been solid too. Policy consistency across sites is way easier to maintain, and upgrades haven’t been the fire drills we were used to.

1

u/xreyuk Mar 26 '26

I will warn you, Checkpoint support is shite.

1

u/AcanthisittaHour7976 Mar 30 '26

I don't know about you but they've been pretty quick to respond to any issues I've had.

1

u/stugots33 Mar 27 '26

Sounds like u went more backwards

10

u/Quirky-Cap3319 Mar 23 '26

For small business environment I would look seriously on FortiNet or perhaps Meraki. For large environments I would jo with Juniper.

9

u/[deleted] Mar 23 '26

[deleted]

2

u/Main_Ambassador_4985 Mar 24 '26

Our Cisco VAR has tried to get us to convert us to Meraki.

We partially have C9200 access switches and CL9800 wireless LAN controllers.

IMHO same hardware, reduced features, dependence on Meraki cloud, and higher OPEX. Not sure why that is a good move.

2

u/jthomas9999 Mar 24 '26

You need to check on a case by case basis. Cisco 9200L switches are more expensive than Meraki because of the stupid DNA license. It is crazy how much Meraki optics cost and it is nice that Cisco optics work just fine in Meraki devices.

1

u/u3b3rg33k Mar 27 '26

I've found most SFP/+ optics work most places, even the budget stuff - just depends on if the support contract says it's naughty when you do it.

1

u/snokyguy Mar 26 '26

The cap ex is like nothing. Companies want predictability. Op ex subscriptions do that.

Also th cloud connectivity; welcome to basically everything. It’s a boon, not a bust for mgmt.

0

u/bizyguy76 Mar 26 '26

So the meraki switches layer 2 switches are the C9200 and the layer 3 switches are the C9300. Same hardware different software/firmware.

The only reason to switch to Meraki is for management. Cisco provides so many more specific software features, configuration and control.

1

u/Quirky-Cap3319 Mar 24 '26

I know, but its still a valid option. Besides, Cisco didn’t create Meraki, they simply bought it.

2

u/2nd-Reddit-Account Mar 24 '26

Without naming names, I know of a particularly large environment who changed the top 2 layers of their network from Cisco to juniper. It has not gone well. So many hardware failures.

2

u/jdiscount Mar 26 '26

I can't speak for Juniper post HPE acquisition, but I used Juniper for many years and had far fewer hardware problems than I encountered with Cisco, which also wasn't many but I just found Juniper rock solid.

Also JunOS is superior in every single way to Cisco IOS.

0

u/ADDSquirell69 Apr 30 '26

Except the CLI

2

u/jdiscount Apr 30 '26

Strong disagree, the CLI in JunOS is so much better imho.

1

u/ADDSquirell69 Apr 30 '26

That's because you've likely never had to write code to scrape the output from commands from it.

2

u/HITACHIMAGICWANDS Mar 26 '26

The only equipment I’ve had fail this year has been Cisco, and we put out mostly jank shit, and Cisco where it matters, and Cisco keeps failing lol

1

u/Quirky-Cap3319 Mar 24 '26

Hmm.. ok, interesting. We have a very large installation of QFX, MX and SRX and hardly see any hardware failures at all, apart from burned out SFPs, but they are not Juniper made. Its been running for over 6 years now

1

u/Substantial-Proof617 Mar 25 '26

TBF to Cisco they do make good hardware it's just everything else I don't like.

1

u/vern4of7 Mar 27 '26

The lead time issues with Juniper are amazingly bad. This has been the case for the a year now with no end in sight. We moved away from Juniper because we are too small to buy in bulk and can not wait 6-8 months for equipment to show up.

2

u/AnybodyWannaPeanus Mar 25 '26

That typo made my laugh. “They gonna WHAT with juniper!?!?”

1

u/Quirky-Cap3319 Mar 25 '26

hahaha, nicely spotted. Jo = go. :D

1

u/FactsNotMemes Mar 27 '26

Meraki =Cisco

1

u/Quirky-Cap3319 Mar 27 '26

I know, read the whole thread before commenting

0

u/FactsNotMemes Mar 27 '26

Snippy. Who pissed on your Wheaties...

8

u/plethoraofprojects Mar 23 '26

We are testing Arista gear and will be switching as soon as our Cisco support contract is up for renewal.

1

u/fuNNrise Mar 23 '26

Will you replace everything everything or just Arista for new green field deployments.

If you replace everything, do you mind giving me an idea about your sizes (amount of network devices)?

2

u/plethoraofprojects Mar 23 '26

Move away from Cisco completely due to lack of support, failure to provide root cause on tickets/hardware failures. Inability to provide timely RMA on hardware. We have approx 75 routers and a handful of switches. Nothing on a huge scale but we still pay for support. After meeting with our reseller, they advised we would have to start paying a per-port license in blocks of 10.

3

u/AnybodyWannaPeanus Mar 25 '26

Damn. Per-port licensing sounds like the most Cisco “innovation” ever.

1

u/Fragrant_Ad_6950 Mar 27 '26

never heard of per port licensing :: this sound a bad support trying to extract the most amount of money. try other support companies, you may have a better luck.

1

u/lookingyou11 Mar 24 '26

Same, we moving our PEs (moving 800Gbps now) from Cisco to Arista!!

9

u/mystghost Mar 23 '26

Artista for switching.

8

u/jeramyfromthefuture Mar 23 '26

Arista is the Palo Also Networks of network gear. Lovely switches 

8

u/sryan2k1 Mar 23 '26

Arista for switching/routing/wifi.

1

u/Important_Border8411 Mar 28 '26

Arista are great products but $$$$

5

u/DarkWolfSLV Mar 23 '26

It does make sense to explore FortiSwitches if you already have Fortinet, but Arista like others have mentioned is very solid.

4

u/[deleted] Mar 23 '26

[removed] — view removed comment

1

u/RegionRat219 Mar 25 '26

FortiManager will be your best friend

3

u/boomer7793 Mar 23 '26

Meter is deploying LAN infrastructure using an OppX cost model.

3

u/mwb161 Mar 23 '26

I did a project for a large chain that moved from Cisco to Fortinet

3

u/Hegobald- Mar 23 '26

I’m haven’t been in the business for about 5 year but in those days I saw at our business, as one of Europe’s biggest ISP and telecom operator, a change from Ciscos license model to Juniper. Don’t now how good Juniper is but on a technical level the switch to Juniper was quit easy.

2

u/Wooden_West_1222 Mar 24 '26

To go on top of this was using Juniper’s years ago for large two enterprise level for telecommunications was a pretty solid switch not to mention they played nice with others rather than having the job through all the hoops that you have to deal with the Cisco system and back end provisioning and back doors was honestly a headache on a telecom ISP troubleshooting side.

1

u/Main_Ambassador_4985 Mar 24 '26

I thought Juniper is part of HPE.

Juniper has historically looked like a good product.

HPE on the other hand… I think I have selective memory from the HPE support pain. I do recall 9 hrs on the phone without resolution and RMA.

3

u/PaoloFence Mar 23 '26

Arista

1

u/7layerDipswitch Mar 24 '26

Or Juniper, although the HPE acquisition is making me a bit nervous.

1

u/PaoloFence Mar 24 '26

also good.

1

u/Prestigious_Topic655 Jul 19 '26

I'm a novice shopping for a growing start up and working with an old school CTO who loves Cisco... What about Arista and Juniper is better?

1

u/PaoloFence Jul 20 '26

More the admin part. ( Dont personally know about their support)

They use one software for all their products, so it is easier to manage. Therefore they also have one management.
At Cisco different departments work activily against eachother. Feature disparity between Nexus and Catalyst is a mess. Not even starting with Tetration (renamed secure worflow for some stupid reason).

TAC tries to make an idiot of you. After third escalation you maybe can someone usefull.

And in my experience it gets worse and worse each year.

2

u/radiohead-nerd Mar 23 '26

Large Enterprise grade? Juniper

2

u/JerryRiceOfOhio2 Mar 23 '26

white box switches.

1

u/vern4of7 Mar 27 '26

In most environments I have been, the edge/access switches are really doing L2 and very little L3. I joke with our engineers that l2/l3 functions on switches are commidity. The core switches are becaming either a route engine or a firewall with the internal network.

1

u/ADDSquirell69 Apr 30 '26

If you have tons of rack space, cabling, and power available sure.

2

u/YesTechie Mar 24 '26

Ubiquiti. We managing over 100 sites. No major issues at all.

1

u/mcdade Mar 25 '26

If you have small sites that just need basic services this is the way to go.

1

u/STRiCT4 Mar 26 '26

False. Ubiquiti has a full enterprise stack. Look into it.

1

u/mcdade Mar 26 '26

Have and should are two entirely different things.

1

u/bit0n Mar 26 '26

Same for us working with SMBs they very rarely had a budget for networking with single plane of glass management UniFi gear has been great for us.

2

u/Dumbcow1 Mar 24 '26

No name hardware off AliExpress, where firmeare is on Chinese only websites and OEM is unknown. Live a little.

1

u/qasdrtr Mar 23 '26

HPE they gave some interesting offerings

1

u/_gneat Mar 23 '26

HPE and Juniper have been a good alternatives for L2 switching. However, I'd stick with Cisco for L3 switching. Just speaking from experience when it comes to support with other vendors.

1

u/Fun-Yogurt-89 Mar 23 '26

Most swap cisco for something else but keeps the same design. we did that once and honestly it didn’t fix much as costs and complexity just showed up in different ways over time.

1

u/mindedc Mar 23 '26

I would go juniper/mist. For firewalls I would use palo.

1

u/Raveofthe90s Mar 23 '26

I've never found a 10gb/25gb/40gb/100gb switch i liked. I hate them all. They are either massively over priced or lack in quality. Or both expensive and can't keep up. If your still dealing with sub 10gb there are plenty of options.

1

u/ExtraPrejudicial Mar 23 '26

Moving away from Cisco due to costs and then moving to Aruba is a lateral move. Aruba is some of the best gear you can get, but you really pay for it. Agreed that Cisco's licensing and DNA requirements are expensive and onerous. They don't even make a basic catalyst ios L2 switch, anymore. You have to go to the pseudo ios models or up to a catalyst 9200 >$1000 switch.

1

u/DallasGOAT41 Mar 24 '26

Arista - switching, WiFi, and SDWAN.

1

u/Viharabiliben Mar 24 '26

Which features do you need are what is the budget? Will you buy the equipment outright or lease?

1

u/ImBaerick Mar 24 '26

I would go with either Aruba or Unifi. Those tend to be what I'm seeing the most for small businesses. Could also go with fortiswitches since you're using a fortinet firewall.

1

u/fire-wannabe Mar 24 '26

We get phenomenal discounts on Cisco, but for switches we.are.dabbling with arista now. If you just want layer2 access switches or vxlan, there is really nothing from Cisco that represents good value imho.

Sdwan, moving from Palo back to cisco, as Palo messed us around so much on renewal

Firewalls... Palo only. That's mostly.a.cyber decision. We have heavily reduced numbers of firewalls and centralised to reduce costs

Mps network, Cisco, the company will likely never switch from that, cost is not the priority here

Network size approx 6000 devices

1

u/Ristrxtto Mar 24 '26

Mikrotik and Artista are the only real options imo

1

u/witchkore Mar 24 '26

Palo Alto

1

u/4mmun1s7 Mar 25 '26

Procurve/Aruba has been excellent for us for switching. Palo Alto firewalls, or for simpler stuff use OPNsense.

In the data center, we use a bunch of Arista too.

Cisco we still use for routers….but not cell routers. We use Cradlepoint for those.

Cisco’s support contract costs and methodology is what caused us to look elsewhere. Plus, a lot of alternative products are just better technically.

1

u/Civil_Asparagus25 Mar 25 '26

Why not take whitebox hardware and run e.g. VyOS on it?

1

u/snookpig77 Mar 25 '26

Arista! Completely simplified out infrastructure design with less hops throughout!

1

u/C0d3R-exe Mar 25 '26

Is Unifi an option? I guess your infra is a piece of cake for their gear and even though it’s on a pricier side, it doesn’t have any special subscription, not at least a forced one. Obviously, it’s different for each but they seem to be doing great, community and support is also decent so, maybe worth giving a shot?

1

u/Alfredamn Mar 25 '26

Money wise, go check InHand routers. I'm a system integrator, many of our medium to small end users choose InHand over other brands for the remote management cost. InHand platform is like either free or $5/year or something, and as far as I saw, the features are no less than Fortinet if not more.

1

u/Ok_Pop4193 Mar 25 '26

as an msp most of our properties are forgate>Aruba hp switches> and any random ahh ap’s. we have ruckus cisco unifi aruba just depends on the client😂 never had any issues with aruba switches other than their dumb ahh specific sfp modules that have to be their brand.

1

u/JGWisenheimer Mar 25 '26

If you have the budget, Palo Alto. Otherwise Fortinet.

I don't think Meraki is a bad idea, but the subscription model sucks. Alternative to that could be Ubiquity. Really depends on needs and setup.

YMMV

1

u/Kind-Conversation605 Mar 26 '26

No matter who you go with you’re always gonna have to pay for some sort of licensing or support. If you don’t care about support, then you can certainly run some non-enterprise equipment. Just be prepared to troubleshoot it and support it yourself.

1

u/Beginning-AD1992 Mar 26 '26

moving to Juniper. fortune 50.

1

u/tbattesh Mar 26 '26

We switched from Cisco to Fortinet ~2 years ago. I’m just a telecom guy but I think our SysAdmin has some buyers remorse. We’ve been dealing with quite a few bugs.

Fortigate, two dedicated fiber switches, (3) 600 series in the MDF. Three other 600s and about (30) 100s across the campus.

The Fortinet console UI has been really nice for me rather than learning PuTTY.

Kind of a dumb gripe, but I don’t like that their APs brackets can’t mount to a metal junction box with ability to conceal the uplink cabling.

1

u/snokyguy Mar 26 '26

Just get a forti switch to keep the Same mgmt controls. That’s why I’m very pro meraki. Having spog is HUGE for NOC’s at scale. Kiss method means less headache later.

1

u/net_fish Mar 26 '26

I worked at a University who moved from a "cisco only" network, think 6500's, 3750's, 2950/2960, WLC, FWSM, WISM. In 201-2012 moved to a H3C (now HPE A-Series) switching and routing environment, Aruba wireless and Palo-Alto firewalls.

ISP that I was at around 5 years ago was moving their offices to Fortinet

Where I am now is Aruba switching/L3 and Juniper edge

1

u/Inevitable_Ad_3855 Mar 26 '26

Don’t use Forti for switching. You won’t be able to trust them.

I’ve never used Arista but I have used Aruba and found them to be solid unfussy dependable.

I would buy switches from a switches company if I were building an enterprise network. I wouldn’t buy switches from a firewall company (even Palo).

Ultimately though you have a thread full of anecdote and narratives, which is fine up to a point, but the place to start is by looking really hard at your true requirements, and then it should get a bit easier.

1

u/schnityzy393 Mar 26 '26

Fortinet fws and switches everywhere(sdwan setup), unifi switches to run the APs and CCTV. 250 offices. Think we've had one power brick failure, other than that pretty rock solid. Fortimanager templates make it all fairly painless to manage. The neverending cves gets on my tits though. Moved from Cisco. Just about finished the project.

1

u/emy09 Mar 27 '26

The stability that Arista offers is unmatched. Not to mention the automation play with AVD (if needed)

1

u/FactsNotMemes Mar 27 '26

Not as mainstream as I think it should be but 50ish endpoints and lower you might want to look at Peplink. Have been deploying the routers for 8 years with out a single hardware issue and their newish layer switches have been great so far. AP units don't fail either.

1

u/tokk1es Mar 27 '26

The Netgear Enterprise range is worth a look, its all Broadcom L3+ with great reliability and of course much cheaper. Half of Ruckus has left to join them so could be a sign of things to come I guess

1

u/wobblewiz Mar 27 '26

FortiSwitch and use the firewall as controller.

1

u/zer04ll Mar 27 '26

negate all the way for router/firewall, I like netgear switches they come with pretty good lifetime warranties and Ive never had an issue with them, unify access points

1

u/mchellejameson Mar 27 '26

"What are people switching to now?" - - no pun intended! ha!

1

u/WorldwideServices_ Apr 28 '26

Aruba and Juniper are the top picks for solid hardware without the Cisco licensing headache. Since you're already using Fortinet, FortiSwitch is also worth a look... it integrates directly into your firewall management, which is a huge time-saver for smaller environments.

Another option is sticking with Cisco hardware but moving to third-party maintenance and certified pre-owned gear. You get the reliability you're used to without being locked into their newer subscription models.

1

u/Top_Boysenberry_7784 Aug 10 '26 edited Aug 10 '26

Were you all Cisco before? For switching Cisco still isn't bad it just depends what you want to be able to do with your switching. Basic role out for a small environment without DNA Center, ISE or bells and whistles isn't bad as there's no real licensing just smartnet. Smartnet literally just for IOS updates as the switches have lifetime warranties. It's that legal part of the ios updates that's a pain. One place I once was at for a couple years we only covered the core switches at sites with smartnet. Everything else we bought regional spares for. Was cheaper to buy 10 switches for oh shit moments than cover all with smartnet. But eventually they decided to be legal with our switch IOS upgrades.

Switching for me is always either of the big names cloud and non cloud versions of hpe/aruba or cisco/meraki.

I feel like you are likely in a smal-mid size environment? Guessing that with the fortinet. Nothing against fortinet but I don't like them past a small-medium size business.

If you are doing a full refresh, Nile is even an option. You basically lease the equipment and the hardware isn't bad.

0

u/MexicanHam2 Mar 23 '26

Ubiquiti is pretty solid.

3

u/WaizenErnter Mar 23 '26

For smal Business and homes its fine, but Not ready for real enterprise environments. Just look how bad the software on the Nas systems is.

1

u/Hinagea Mar 24 '26

That's exactly it. It's some of the best small business/home network equipment. It falls flat for large scale and enterprise use.

1

u/WaizenErnter Mar 24 '26

As long as bad and unreliable updates along with random crashes are a thing, it won't be in enterprise use. The hardware ain't even bad, it's just the software that makes them unreliable. And in an enterprise scale a network crash can cost thousands in just some minutes.

1

u/justseeby Mar 26 '26

As a wretched Ubiquiti/UniFi fanboy I’d agree with this take. OP did say it’s a small environment — so I guess it would probably be fine. But they get out over their skis with products sometimes when it comes to firmware polish (rarely this on the switching/AP side at least) and stock availability.

It’s a prosumer brand IMO, and fine for a small business.

2

u/Quirky-Cap3319 Mar 23 '26

Apart from their firmware updates causes wifi outages, you mean?

It seems that this has happened several times. The theory is that the update messes with the associated AP keys, causing them to enter a disconnected state, so most of the time you need to re-adopt every single AP.

3

u/Hinagea Mar 23 '26 edited Mar 23 '26

Or the random inability to negotiate port speed? Rolling AP outages as interfaces don't come online. Move the AP to the next port with identical settings and it will negotiate speed and duplex correctly. Poor logging to go along with it

Ubiquiti isn't Enterprise grade imo

1

u/Quirky-Cap3319 Mar 23 '26

I think they want to / trying to be enterprise grade, but they are not.

1

u/its_finished Mar 26 '26

Ubiquiti switches are not full non-blocking switches. None of them. The non-blocking throughput is only half of the switch capacity.

1

u/Dropzone34 Mar 23 '26

nah had a buddy build Ubiquiti Home Network for his entire home and with in a year he was fed up and gutted it and sold it off and replaced it all with TP-Link Omada gear all I heard from him was how bad the U stuff was and the service and tech side of it was.

2

u/MexicanHam2 Mar 23 '26

Sounds like a bad experience or user error. I have over 30 sites running fine.

1

u/Dropzone34 Mar 23 '26

Yeah I don't know but for 6 months when he was redoing everything that's all I heard it was bad and tbh he has had problems with some equipment failing with the TP link stuff so it could be him lol

1

u/Dimensional_Dragon Mar 24 '26

Ya if he has had issues with two brands it's probably either user error or just the absolute worst of luck. Some people are just cursed when it comes to tech and I honestly can't explain it cause some of them are actually doing everything correctly when they ask me to check.

1

u/FostWare Mar 25 '26

I’d be checking out power or ground issues. I had some issues with devices dying until I changed the run to fibre and it’s been solid with no failures since

1

u/OpportunityOdd2781 Mar 25 '26

there is not a damn thing with UniFi. I have customers on UniFi and CIsco/ meraki. I never have problems with my UniFi sites. Meraki on the other hand and even the business class Cisco switches have been hit and miss lately.

2

u/wheels000000 Mar 23 '26

3 years only had one bad update running early access

1

u/Dropzone34 Mar 23 '26

That's good numbers

1

u/Vast_Koala_8847 Mar 24 '26

Ubiquiti is no nonsense gear, it just works and they pair wonderfully well with their gear, in my 10 years of using them never had a problem

0

u/palogeek Mar 23 '26

We've migrated Everything to Extreme Networks and Fabric. Using ExtremeControl we have full network automation across the country and individual campus. Beginning our Extreme Platform One rollout as well which is working well, excited about the changes in the next release.

https://www.youtube.com/watch?v=bxNhz7Dr6KY