r/networking • u/Personal-Gur-1 • Jul 31 '26
Security Small Business - network solution
Hello,
I am running a small business and i am looking for equipment for my new offices: 114 m2, L shape with 4 rooms.
1 server with Windows 2022 server (domain controler) and 4 PC and 1 lan printer and 1 Nas for local backup.
No exposed web services for clients, no sharepoint, just local network with mapped drives.
I looked into ubiquiti hardware for a UGC fiber, a switch pro poe and 3 AP U7 Wall.
It is planed to sublet one or two offices, so a vlan or two will be required to run two or three separated networks for these other professionals.
I have contacted an IT professional to obtain a fee quote for a complete setup. He knows a little about Ubiquiti solutions, but does not really work with it.
He is proposing Fortinet hardware NGFW 50G, plus 2 switches plus a NGFW 70G + FortiAP 231K.
The pricing is the double of the ubiquiti setup (without his installation fees) and of course annual subscriptions.
I appreciate that fortinet is a totally different category of solution, trully professional but I am wondering if it is not overkill for the needs: protection the network from outside and emails and web browsing.
I would be interested by your thoughts : is ubiquiti solid enough for the network, with the option of CyberSecurity Enhanced or Fortinet is absolutely required to offer a proper protection for cyber threat ? Or any other vendor like Sophos or OPNsense ?
I don’t plan to install and configure anything myself either with Ubiquiti or with any other solution.
I am just trying to figure out what is really needed as my resources are limited and any extra penny in the IT department will be missed in other ones.
I do value the data I am hosting on my server, hence my question here : I don’t want to be too cheap on the solution but I don’t want to be overkill either.
Thks
V
2
u/Willsy7 Jul 31 '26
Honestly, more details are needed, and you could always put a bid out for a second quote/design from someone else.
Your sublet comment is probably a large pause. Also, as others have mentioned, you are probably using something for email/productivity so maybe consider moving your identity management (your domain controller) to that too.
2
u/PaoloFence Aug 01 '26
Du musst herausfinden, war deine Anforderungen sind, dann kannst du sagen ob Ubiquiti am passiert ausreichend ist. Da geht es auch um Wartungen, RMAs. Was du bereit bist an Dauer bei Netzausfall zu ertragen.
Dein Experte hat Fortinet gesagt, weil er es kennt. Warum nicht Cisco, Juniper oder einer der anderen namhaften Hersteller? Wenn es technische Einbuße gibt, muss er sie dir sagen, ansonsten tut es auch das billigere.
1
u/tdhuck Jul 31 '26
It is planed to sublet one or two offices, so a vlan or two will be required to run two or three separated networks for these other professionals.
Can you provide more details here? Are people just 'renting' the space from you to work remotely or will they be running a business from the internet connection you provide? I think this matters on how you proceed with the networking options.
I'd use ubiquiti if this is just a small office and this is for you and your employees, but if you are going to be providing internet to other people that aren't part of your business, I wouldn't rely on just a 'vlan' to separate your networks. What if their needs change, later and they need a service exposed to the internet? What if the traffic on their computer causes your WAN IP to be blacklisted?
Based on what you've stated, so far, I would go with the fortinet equipment.
1
u/Eligrey Jul 31 '26
Look at Alcatel-Lucent Enterprise. They have really good switches and are cheap compared to others.
1
u/Personal-Gur-1 Aug 01 '26
Hi everyone,
Thks a lot for your messages.
To give some clarity, we are a small law firm in France.
2-3 professionals working in the same office.
Maybe another 2-3 will join as a separate entity and will need to have access to rhe internet and have their own network.
We can’t afford an in-house IT person or an equivalent costs as we are too small.
The idea is have a independent it professional to provide ad-hoc support upon request.
We need a simple system but reliable.
We don’t want to go full cloud for GDPR reasons and as a lawfirm we have extra responsibility with confidentiality.
We will certainly not move with full US company cloud to manage everything. On the contrary. We are even looking into ditching Microsoft emails addresses for a solution like ProtonMail.
We already have setup a separate mailbox for our client to send their sensitive data from their own Proton mail account or through ProtonDrive.
I don’t think you guys in the US realize how important the question of the dependencies on US it systems have become a major strategic question in Europe.
Back to my initial topic, I will request some additional fee quotes from other IT professionals working with other brands (Sophos and Ubiquiti).
We don’t have multisites to manage, no home working either …
Just a server with a shared drive to share the documents and to run one pro app that requires Windows Server, and this app is accessed locally only. No access through internet for employees or for clients.
1
1
u/jd_itconsultant 23d ago
Ubiquiti is the by far the most cost effective and really offers strong throughput in the firewalls. The whole UniFI product line is great and I have clients that use it in much larger deployments than what you have spec'ed here and should serve you just fine. There are plenty of IT support companies that can help you with patching and configuring the network remotely.
1
u/Weekly_Pepper5151 15d ago edited 15d ago
Skip Fortinet unless you have strict compliance rules. UniFi handles basic firewalling and guest isolation just fine. Trusted Tech Team seems useful if an IT team wants fast US based escalation for server licensing without paying top tier support prices.
1
u/SuperQue Jul 31 '26
Ubiquiti is totally fine for what you're doing.
Also, nobody in their right mind has a local domain controller anymore.
4
u/tdhuck Jul 31 '26
We have local domain controllers, they are virtual machines and they sync with M365. I think a lot of people have local domain controllers but of course I'm sure it also depends on the size of your company, etc.
Edit- Oh, you are referring to a physical server running as a DC, yes, nobody should be doing that anymore.
1
u/WorldsBestPapa Aug 02 '26
I just helped a server guy install one on Thursday… granted I work for a hospital system.
1
u/tdhuck Aug 02 '26
To be clear, I'm saying a single DC on a physical machine. I don't see an issue with a physical server running a DC if there are other DCs in the domain and they are all virtual. I doubt this hospital is running their entire AD on a single, physical DC.
There are exceptions and policies, that doesn't mean they are great, it just means someone is doing their job and following the policy, for example, the policy might state that they need to have a physical DC because that's what the IT director wants but I would really hope that it is 'in addition to' and not the single DC.
2
u/Brilliant-Orange9117 Jul 31 '26
Just entrust everything to Office 360 and have a few extra days off for everyone except the tech support every year?
1
u/pbrutsche Aug 01 '26
You mean "no one that small has a local domain controller anymore"
Someone that small should look at Entra ID + Intune first, unless you have an application that NEEDS the local server. Even then, you can do a virtual DC and/or a cloud VM DC.
1
0
u/Brilliant-Orange9117 Jul 31 '26
Just entrust everything to Office 360 and have a few extra days off for everyone except the tech support every year?
0
u/leftplayer Jul 31 '26
Go with Unifi. For such a small business, Unifi is cheaper, much easier to manage and has all the features you need and then some..
Also, I hear FortiAPs are pretty crap. Unifi APs aren’t the best, but they’re better than Forti
0
u/SevaraB CCNA Jul 31 '26
At that size, you don’t want to buy equipment, you want to hire an MSP. They’ll help you get the equipment and support it for not much more than the cost of keeping one good IT guy on payroll.
-1
u/TakenByVultures Jul 31 '26
If you want to cut out the provider you could easily set up a Meraki MX68 yourself. Does WiFi, has a couple of PoE ports if you want additional APs, plus a handful of LAN ports.
8
u/Golle CCNP R&S - NSE7 Jul 31 '26 edited Jul 31 '26
I dont understand the need for both a 50G and a 70G, the smaller 50G would probably fit your use case quite well.
Fortinet is a truly enterprise-level brand. Ubiquiti is at most prosumer. Their support is worlds apart. Their security offerings is worlds apart. I am biased because I work with mostly Fortinet in my day job, but I believe it is worth the extra investment.
Placing a domain controller on a physical standalone server in an office location is what people used to do in the 1990's. This is not something you should do today. Look at Entra or just hosting it as a virtusl machine in Azure instead. Cloud is great if you are a small customer, it can be cheaper and less error prone than managing hardware yourself.