Securing and managing traffic between users, branches, and cloud services becomes more complex as networks expand. Separate security and routing systems increase cost and management effort. HPE Aruba Gateways address this by combining routing, security, and policy enforcement in a single platform.

At network edges, branches, and data centres, they control traffic between users and applications. This reduces hardware sprawl, lowers management overhead, and applies consistent security policies across the network.

HPE Aruba Gateway Quick Specs & Key Features

  • Secure Network Edge Control: Provides routing, policy enforcement, and traffic management between branch, campus, and data centre networks.
  • Integrated VPN Services: Supports encrypted connectivity between sites and remote users across public and private networks.
  • Centralised Policy Enforcement: Applies user and device policies consistently across wired, wireless, and WAN environments.
Read more
  • Dynamic Traffic Steering: Directs application traffic across available links based on performance and policy requirements.
  • Zero Touch Provisioning: Enables automated deployment of new devices with minimal manual configuration.
  • High Availability Options: Supports redundancy and failover to maintain connectivity during link or hardware failure.
Steel City Consulting logo

Comparing multiple platforms? Our experts are available to help.

No commitment needed, no hard sells. Just straightforward technical guidance tailored to your infrastructure.

Find your ideal HPE Aruba Gateway

Full technical specifications are available on each product page.

Model Popularity Deployment Deployment Scale Maximum Access Points Supported Maximum Clients Supported Controller Throughput (Gbps) VPN Throughput (Gbps) Maximum WLANs Maximum Interface Speed
HPE Aruba 9012 Gateway HPE Aruba 9012 Gateway Branch Small 2000 6 3 512 1G View
HPE Aruba 9240 Gateway HPE Aruba 9240 Gateway Large Campus Large 2048 32000 20 10 4096 25G View
HPE Aruba 9004 Gateway HPE Aruba 9004 Gateway Branch Small 32 2000 2 2 512 1G View
HPE Aruba 9106 Gateway HPE Aruba 9106 Gateway Campus Medium 2000 8000 10 5 4096 10G View

HPE Aruba Gateway Deployment Scenarios and Industries

Retail & Branch Networks

Retail organisations connect stores where wireless traffic, applications, and user access must be managed locally. HPE Aruba 9004 and 9012 Gateways support these environments by providing on-site control, segmentation, and secure connectivity across distributed branch locations.

Healthcare & Clinical Sites

Healthcare providers manage wireless networks, clinical devices, and user access across sites where security and control are required. Aruba 9004 and 9106 Gateways support these deployments with policy enforcement and segmentation across clinical and administrative networks.

Hotels and Hospitality & Guest Networks

Hospitality operators connect guest devices, staff systems, and on-site services where access must be separated and managed. Aruba 9012 and 9106 Gateways support these environments with secure segmentation and traffic control across guest and operational networks.

Enterprise & Campus Networks

Enterprise teams manage wireless infrastructure and user access across campus environments where central control and scalability are required. Aruba 9240 Gateway supports these deployments by aggregating traffic and applying policy across large-scale campus networks.

Finance & Secure Network Access

Finance organisations control access to applications and data where network security and segmentation are required. Aruba 9106 and 9240 Gateways support these environments with policy-based control and secure traffic handling across user and application networks.

HPE Aruba Gateway Management and Licensing Options

Aruba Central

Manage your entire switching, wireless, and WAN estate from a single cloud-native dashboard. Aruba Central delivers AI-powered network insights, automated configuration and firmware management, and real-time anomaly detection across all sites — reducing operational overhead and giving your team full visibility without being on-site.

Ask us about Aruba Central

Aruba ClearPass

Enforce consistent, policy-driven access control across wired and wireless networks regardless of device type or user role. ClearPass authenticates every endpoint before granting access, segments traffic dynamically, and provides full visibility into who and what is connected across your environment — reducing your attack surface and simplifying compliance reporting.

Ask us about Aruba ClearPass

As an authorised HPE partner, we’re here to help your organisation select, configure, and manage the right combination of platforms and services to efficiently scale and support your new solution long-term. Contact our HPE specialists for guidance today.

Shop All HPE Aruba Gateway Models

Browse our full range below, or contact our team for tailored configuration advice.

Designing & Supporting HPE Aruba Gateway Solutions

Backed by decades of expertise in the IT sector, our specialists support every stage of your deployment — from initial selection through to long-term lifecycle management.

  • Tailored Gateway Selection: Our specialists evaluate your wireless environment from the ground up — AP count, site topology, client density, redundancy requirements, and management preferences all considered before a recommendation is made. Whether you’re deploying a centralised campus controller, distributing intelligence across branch sites, or transitioning to a cloud-managed architecture, you get the right gateway platform for your environment, not a compromised shortcut in either direction.
  • Deployment & Integration: Our engineers manage end-to-end gateway installation and WLAN integration — AP provisioning, RF profile configuration, SSID and VLAN design, client roaming policies, and integration with existing switching infrastructure, NAC platforms, and network management tools — fully configured and tested so your team inherits a stable, well-structured wireless network from day one.
  • Cloud & On-Premises Management: Choosing the right management architecture is critical to getting full operational value from your wireless gateway investment. Our specialists help you identify the right platform and licensing model for your needs — whether that means on-premises controller management, cloud-based orchestration, or a hybrid approach spanning multiple sites.
Read more
  • High-Density & Large Venue Deployments: Our team has hands-on experience deploying wireless gateway infrastructure in demanding, high-density environments — open-plan offices, education campuses, healthcare facilities, warehouses, and large public venues. We design and commission controller architectures built to maintain consistent performance and roaming behaviour where client scale and RF complexity would overwhelm a standard deployment.
  • Access Policy & Secure Onboarding: Our specialists provide guidance on role-based access control, guest portal configuration, and NAC integration — helping your team enforce consistent, identity-aware wireless policies across user groups, device types, and locations without unnecessary complexity in day-to-day network operations.
  • Lifecycle Support & Management: We provide proactive gateway monitoring, firmware management, and support packages built around your wireless infrastructure — with remote diagnostic capability and response times matched to the criticality of each environment, from a single-site deployment to a multi-campus controller estate.
  • Strategy & Roadmapping: Our specialists provide structured consultations to assess your current wireless architecture, identify performance bottlenecks and coverage gaps, and produce a clear gateway roadmap — whether you’re scaling an existing controller deployment, consolidating a multi-site estate, or planning a migration to a cloud-managed wireless platform.

HPE Aruba Gateway FAQ

How do the 9000, 9100, and 9200 Series within HPE Aruba Gateways divide by deployment role?

The 9000 Series (9004 and 9012) are branch gateways designed for small and medium branch offices, combining SD-WAN, routing, and security in a compact form factor. The 9100 Series (9106) is a hybrid gateway for large branch and small campus environments, running AOS-10 for greater AP and client scale with 10GbE uplinks. The 9200 Series (9240) is a campus gateway for medium and large enterprises, scaling to 2,048 APs and 32,000 devices, and is purpose-built for high-density environments where continuous availability is critical.

What is the difference between the 9004 and 9012 within HPE Aruba Gateways 9000 Series?

Both run the same software and support the same SD-WAN, security, and WLAN gateway functions. The 9004 has four GbE ports and is sized for smaller branch sites. The 9012 has 12 GbE ports, six of which support PoE+ at up to 120W total, making it the right choice for branches where the gateway also needs to power a small number of devices — such as IP phones or lightweight access points — directly without a separate PoE switch. Both support up to 32 access points and 2,048 clients.

What does SD-Branch mean in the context of HPE Aruba Gateways, and when does it apply?

SD-Branch is an operating mode where the gateway manages WAN connectivity, routing, security, and wireless policy enforcement from a single platform rather than separate devices. In this mode, the gateway handles traffic steering across multiple WAN links — such as MPLS and broadband — alongside Dynamic Segmentation policy for connected users and IoT devices. It applies when a branch has multiple WAN connections to manage or when a unified policy across wired, wireless, and WAN is required without deploying separate appliances for each function.

How does the 9200 Series campus gateway within HPE Aruba Gateways scale capacity without hardware replacement?

The 9240 ships as a hardware-only unit that supports 512 APs and 16,000 devices at 20 Gbps throughput. Capacity can be increased by applying a Silver perpetual licence (1,024 APs, 24,000 devices, 30 Gbps) or a Gold perpetual licence (2,048 APs, 32,000 devices, 40 Gbps). The physical hardware does not change — the capacity increase takes effect through the licence. This allows organisations to start at a lower capacity and expand as the network grows without a hardware refresh.

How is high availability handled across HPE Aruba Gateways?

All three series support clustering, where multiple gateway units are grouped together so that if one fails, others continue serving the network. The 9000 Series supports N+1 or NxN redundancy at the branch, allowing two gateways to share the load. The 9100 and 9200 Series both support live upgrades — software can be updated on a gateway without dropping connected users or APs during the process. This is a specific capability that standard gateway platforms do not offer and is particularly relevant in environments that cannot tolerate planned downtime.

What security enforcement does HPE Aruba Gateways provide at the wired and wireless edge?

All models include a built-in Layer 4–7 Policy Enforcement Firewall that applies access policy based on user identity, device type, application, and location — rather than just the port or VLAN a device is on. This means a contractor and an employee connecting to the same network segment receive different access levels automatically. When deployed in SD-WAN mode, the 9000 Series adds IDS/IPS, inspecting both east-west traffic between internal devices and north-south traffic to and from the WAN. Deep Packet Inspection provides visibility and control over more than 3,800 applications.

Need a different solution?

If these options aren’t the right fit for your environment, we provide a wide portfolio of product series and solutions that may better suit your infrastructure. Explore below, or speak to our team and we’ll help you find the right match.

Ready to discuss your requirements?

Whether you know exactly what you need or you’re still evaluating options, our team is available for a no-obligation conversation.

A group discussing IT solutions