Network & connectivity
Switches and routers: count before comparing
A switch does not make a network faster. It decides how many devices fit, and how many of them can be powered over the cable.
It is this family’s commonest purchase and its most often badly motivated one. A switch gets replaced to go faster, and it almost never does that.
What a switch decides is how many devices fit, how many of them can be fed by the cable itself, and what becomes possible to separate. Three counting questions, none of them about speed.
The network article sends the second of its two figures down here, the power available per port. That is what decides how many cameras and access points an installation can carry, and it is the figure nobody checks before ordering.
This page handles that counting, the real difference between a managed switch and a plain one, the operator’s router, and what to obtain with equipment so as not to depend on whoever configured it.
A switch does not make the network faster
It is the sentence this page exists for, and it contradicts half the requests we get in this family. Replacing a working switch almost never gains any speed.
The reason is the family article’s: a network is a chain. If the limiting link is a damaged cable, a badly terminated socket or the operator’s line, no equipment in the middle changes the result. The switch becomes limiting only when it is genuinely saturated, which is rare in a twenty-person business.
There is an exception, and it has to be named for the rule to be usable: very old equipment supporting only a superseded generation genuinely limits every machine. That is checked in a minute, by looking at the speed negotiated on a port, and it is not a matter of opinion.
Outside that case, the question to ask before any replacement is the family article’s: which segment is genuinely limiting? In most installations we audit, the answer sits upstream of the switch and costs less than it does.
What replacing a switch genuinely brings, when it is justified, is elsewhere: more ports, power over the cable, and the ability to separate networks as the family article describes. Three real benefits, none of which is measured in speed.
What a switch does, what a router does
The two words are used interchangeably all the time, including by sellers, and the confusion produces duplicate purchases or gaps in an installation.
A switch connects the devices of one network to each other. It works inside the building, it knows only what is on your premises, and its job is to make each message go to its recipient rather than to everybody.
A router connects two different networks — yours and the operator’s. It decides what goes out, what comes in, and under what identity. It is also what hands out the addresses the family article discusses, and what carries the filtering rules.
In a small installation the two functions often coexist in a single box supplied by the operator, which explains the confusion. As soon as a business grows past a few machines they separate, and it becomes useful to know which of the two is being replaced.
The practical consequence is a question to ask before buying: is the problem about movement inside the building, or about going out? The first calls for a switch, the second for a router, and buying one to solve the other is spending with no effect.
Count the ports before comparing
Sizing a switch is a counting exercise, and that is where installations go wrong — not on the brand, not on the generation, but on the number.
Count what gets plugged in, and count everything: machines, network printers, wireless access points, cameras, the recorder, each office phone if there are any, the till, the server, and the link to the router. That list is always longer than the one we get given on the phone.
Then add a reserve, and the right proportion is a quarter. A switch filled to the brim is a switch that will produce, in two years, exactly the small box under the desk that the cabling article describes as the hardest fault to diagnose.
There is a counting trap specific to this family: the port linking two switches consumes a port on each side, and it carries all the traffic between the two halves. A two-floor installation that did not plan that link discovers the problem on assembly day.
Finally, count separately what has to be powered over the cable, because that count decides the next section and it cannot be recovered by adding a box.
Power over the cable, and the budget people forget
The same network cable can carry data and electricity. That is what allows a camera on a ceiling or a wireless access point in a corridor without calling an electrician, and it is this page’s most useful function.
It is standardised across three successive generations, and the power available per port is not the same in all three. The first edition, published in 2003, grants 15.4 watts to the port. The second, in 2009, rises to 30 watts. The third, in 2018, goes up to 90 watts for the most demanding equipment.
The middle figure is the one to know, because it is the one everybody assumes they have. A motorised camera with a heater, a recent access point or a phone with a screen regularly exceed the first generation, and a switch built to it will feed them badly.
The symptom is deceptive and it deserves describing, because it is never blamed on power: the devices work while there are few of them, then the fourth or fifth restarts on its own, in the afternoon, when the others are drawing most. It looks like a network fault and it is an electrical one.
The second check is the total budget, distinct from the maximum per port: a switch states an overall power figure, and it is almost always below the sum of its ports. Add up your devices’ real consumption before buying, not their number.
IEEE standards on power over network cable, 2003, 2009 and 2018 editions
Managed: when it helps, when it gets in the way
The price difference between a plain switch and a managed one is real, and justifying it requires knowing exactly what is gained. Three things, and no more.
The first is the network separation the family article makes its section 8: guests, surveillance, payment. It is not possible on plain equipment, and it is the only argument that decides on its own.
The second is visibility. Managed equipment says which port is active, at what speed it negotiated, how many errors it counts. That is exactly the information that finds a damaged cable without unplugging it, and it turns an hour’s diagnosis into a five-minute one.
The third is being able to shut a port down remotely, which is useful on the day one device starts saturating the network and nobody knows which it is.
What managed equipment costs in exchange is a skill: it gets configured, the configuration gets lost, and a configuration nobody understands six months later is worse than none. That is the reason for this page’s section 8, and it is what honestly decides between the two — if nobody will keep the configuration page, take the plain equipment.
The router the operator supplies
It is the one piece of equipment in the whole pillar that is inside your building without belonging to you, and that ambiguity produces problems that are not technical ones.
What it does well: it terminates the line, it is replaced free when it fails, and it is the only device the operator will agree to diagnose. Those are three real advantages and they suffice for many installations.
What it does badly: its filtering functions are limited, its updates do not depend on you, its configuration can be changed remotely by the operator, and full administrative access is not always given to you.
The arrangement we recommend as soon as a business has requirements of its own is easy to describe: keep the operator’s box for what it does well — terminating the line — and put a router of your own in front of it, carrying the filtering, the separations and the remote access. It costs one piece of equipment and it makes the configuration genuinely yours.
The drawback has to be stated rather than sold alone: it adds a device, therefore a point of failure, and it moves the responsibility boundary. On the day of an incident you will need to be able to show the problem is upstream, which the family article explains in a sentence: one device plugged straight into the delivery point.
Factory passwords, and what stays open
Every piece of network equipment leaves the factory with an administrative login and a password everybody knows, printed in a manual. That is normal; what is not is that it is still there three years later.
We find that arrangement in a large share of the installations we audit, and it is not down to negligence: the equipment works perfectly untouched, so nobody has a reason to open its interface, so nobody changes anything.
Three actions close most of it and take ten minutes per device. Change the administrative password and write it into the access inventory from the audit article. Disable administration from outside, which is enabled by default on many routers. And disable the automatic configuration services nobody uses.
The fourth action concerns wireless where the equipment carries it: the password printed on the label on the back is known to everybody who has been able to read that label, which is to say every visitor and every former employee. It gets changed once, at installation.
Those ten minutes per device are, with labelling, the most profitable intervention in this whole family. They produce nothing visible, which is exactly why they are never done.
Updating network equipment
A switch or a router receives updates like any equipment, and it receives them even less often than a server because it never asks and nothing reminds anybody.
The rule differs from the one for workstations and it has to be said plainly: on network equipment, you do not update on principle. You update when a version fixes a problem you have, or when it fixes an announced security flaw.
The reason for that caution is that updating network equipment means interrupting everybody, and a failure partway can leave the device unusable — at which point the fault is no longer one machine but the whole building.
Three precautions make the operation safe: a configuration backup exported beforehand, a window chosen outside working hours, and assurance of stable power during the operation. The third is the forgotten one, and an outage at the wrong moment is the only scenario that genuinely breaks things.
The reasonable rhythm for a small business is an annual review: look at whether a version fixes something that concerns you, apply if so, do nothing if not. An update that brings nothing is a risk with no counterpart.
The configuration has to fit on one page
Managed equipment contains dozens of possible settings, and the temptation is to use them. That is the most reliable way of making an installation incomprehensible to the next person — including to yourself in two years.
The rule we apply is a deliberate constraint: everything configured fits on one page. Which separations exist and why, which ports belong to what, which addresses are reserved, and what has been disabled.
That page is a deliverable, not an internal note. It is dated, it is handed to the client, and it lives beside the installation drawing the network article discusses. A configuration with no document is a configuration the next person will undo, because they will not know what they are breaking.
The constraint has a useful side effect: it forbids over-fine configurations. If a rule does not fit on the page, it is probably more complicated than the problem it solves, and a twenty-person business does not need it.
Add the exported configuration file, in the same folder as the page. It is the only way to bring identical equipment back up in twenty minutes after a hardware failure, instead of redoing by hand settings nobody remembers.
The stack of small switches
It is the arrangement we find most often in businesses that grew without a plan: a main switch, a second plugged into it, a third plugged into the second, and a small box under a desk.
Every level adds a point of failure and a point of saturation, because all the traffic of the lower levels goes through one cable. A problem on that cable takes down half the building, and it will be blamed on everything except itself.
The second effect is diagnosis: on an improvised stack, nobody knows which device is plugged in where. The one-page drawing, where it exists, describes the original installation, and the three layers added since are not on it.
That is not a design mistake, it is the normal consequence of a shortage of ports: each box was added on a day somebody needed to plug a machine in and there was no room left. It is exactly what section 2’s quarter reserve avoids.
The correction is not necessarily a replacement. Often one correctly sized switch replaces three boxes and frees a route, and the cost is below that of the annual diagnosis the stack causes.
What to obtain with the equipment
Network equipment delivered and configured by a supplier leaves you in a particular dependency: it works perfectly, and you can do nothing to it. Four things lift that dependency and get asked for at order time.
The administrative password, yours, written into the access inventory. That is the family article’s and the audit article’s line, and its absence is what turns changing supplier into a project.
The exported configuration file, handed over in a format the manufacturer can read back. That is what allows the equipment to be rebuilt elsewhere, and it is also what proves what was done.
Section 8’s configuration page, dated. And the drawing updated with the ports actually in use, which is the document the network article asks for and which is only worth something if it gets revised after every visit.
Finally, a piece of information rarely given and worth asking for: the installed version and the date of the last update. Without it, section 7’s annual review starts with an investigation, and therefore does not happen.
What we do, and what we will refuse to do
What we will refuse: replacing a switch to make a network faster. It is this family’s commonest request, it is an easy quotation to write, and in most cases the limiting segment is elsewhere and costs less.
We will refuse to hand over equipment whose administrative password is still the factory one, and to leave you without the exported configuration file. Those two omissions are invisible on day one and get paid for at the first change.
We will refuse to configure more rules than fit on one page. If a twenty-person installation demands more, we have misunderstood the problem, and a configuration nobody understands produces more faults than it prevents.
What we do: the full device count before any comparison, with the quarter reserve; the consumption of cable-powered devices added up rather than counted, and checked against the switch’s overall budget; factory passwords changed and recorded on installation day; the configuration exported and the dated page handed over with the equipment; and the drawing revised after every visit.
And what you can do this week without us: open your router’s interface using the password printed on its label. If you get in, you have just performed this page’s only security check, and you already know the result.
Frequently asked questions
Will changing the switch make the network faster?
Almost never. A network is worth what its limiting segment is worth, and that is usually upstream: a damaged cable, a badly terminated socket, the line. A replacement is justified by ports, by power over cable, or by separation — not by speed.
How many ports should we plan for?
Count everything that plugs in — machines, printers, access points, cameras, recorder, till, server, link to the router — then add a quarter in reserve. Without that reserve, a small box will appear under a desk within two years.
How much power does a camera need over the cable?
It depends on the generation of the standard: 15.4 watts per port in the 2003 edition, 30 in the 2009 one, up to 90 in the 2018 one. Check the switch’s overall budget too, which is almost always below the sum of its ports.
Do we need a managed switch?
Yes if you want to separate networks, see port status, or shut a port down remotely. No if nobody will keep the configuration page: a setting nobody understands any more produces more faults than it prevents.
Should we keep the operator’s router?
Keep it for what it does well — terminating the line, being replaced free, being diagnosed by the operator — and add your own router behind it if you need filtering, separations or remote access.
How often should network equipment be updated?
An annual review. Apply when a version fixes a problem you have or an announced flaw, not on principle. Export the configuration first, choose a window outside working hours, and make sure of stable power.
Where we come in
If the password printed on the label still opens the admin page, you have just done the only security check that matters here, on your own.
- We count every device before comparing any model, spare capacity included.
- We replace that password and hand you the new one in writing.
- We keep the configuration to one page; beyond that it is over-complicated.
A new box will not speed up a slow network, and that is not what we will propose: the cause is elsewhere, almost always.
Read next
The loop, the second DHCP and the switch under the desk
Five years of additions by whoever needed a port. The three faults that produces, and the order you unplug in to find them.Firewalls and VPNs: what goes out matters more than what comes in
What arrives unrequested is already blocked by any router. The useful half is the other one, and it is the half nobody configures.March’s temporary rule: rereading a firewall six months later
A rule added for a week is never removed. How to reread a rule set in two hours, and how to take one out without breaking anything.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.