Skip to Content
Data center infrastructure Networking and connectivity Cybersecurity Cloud and managed IT Riyadh, Saudi Arabia

Supply Pillars

Data center and network infrastructure, delivered and supported in Saudi Arabia.

Supply Pillars designs, supplies, and supports the layer your business systems actually run on — racks, power, and cabling through switching, firewalls, and cloud.

Survey and design Supply and build Support and monitoring
Infrastructure scope Design · Supply · Support
Data centerRacks, power, cooling
NetworkingSwitching, routing, wireless
SecurityFirewalls, segmentation, access
CloudMigration, backup, recovery
CablingCopper and fibre plant
Managed ITMonitoring and support

Infrastructure we design, supply and support

Servers Storage Switching Routing Firewalls Racks & power Structured cabling Wireless

Supply Pillars Solutions

Four practice areas, one accountable contractor.

Data Center Infrastructure

Rack layout, power distribution and UPS, cooling, structured cabling, and server and storage deployment — specified, supplied, installed, and labelled.

Networking & Connectivity

Switching, routing, wireless, and SD-WAN — designed, configured, and rolled out across single sites and multi-branch estates, with the config documented.

Cybersecurity

Perimeter and internal firewalls, network segmentation, access control, and endpoint hardening — built to a written baseline you keep a copy of.

Cloud & Managed IT

Cloud migration, backup and disaster recovery, monitoring, patching, and day-to-day support under an agreed scope and response target.

Switching

Access, distribution, core — sized for the load that is actually there.

Most switching complaints are sizing decisions made months earlier. A closet switch chosen on port count runs out of PoE budget the day the access points go in; a single uplink becomes the bottleneck the day someone starts moving files. We size against the device list and the traffic, then leave you the diagram.

CORE DISTRIBUTION ACCESS

Access layer

Where users, phones, cameras and access points plug in. Power budget matters more than port count here — a 24-port switch with a 370 W supply will not run 24 PoE+ access points, and finding that out on cutover night is expensive.

  • 802.3at / 802.3bt
  • PoE budget in watts
  • 10G SFP+ uplinks
  • BPDU guard
  • Voice VLAN

Distribution layer

Aggregates the access switches and routes between VLANs. Dual uplinks, redundant power, and enough backplane that it does not quietly become the bottleneck at nine in the morning.

  • Inter-VLAN routing
  • Dual uplinks
  • Redundant PSU
  • RSTP root bridge
  • QoS trust boundary

Core / aggregation

Only justified once there are multiple distribution blocks or a server estate behind it. High-speed host connectivity, sub-second failover, and no single chassis carrying the entire site.

  • vPC / stacking
  • 10G and 25G to hosts
  • Sub-second failover
  • No single chassis

What we specify, and why it is on the list

PoE budget
Total watts, not port count. 802.3af gives about 15 W a port, 802.3at about 30 W, 802.3bt up to 60–90 W. Wi-Fi 6E radios and PTZ cameras sit at the top of that range.
Uplinks
A single gigabit uplink stops being enough at a handful of modern access points. 10G SFP+ from access to distribution, in pairs where the site cannot take an outage.
Stacking
One logical switch, one configuration, one firmware image. It simplifies day-two operations more than any other single choice on this list.
Layer 3 placement
Routing at distribution keeps broadcast domains small and keeps failover local instead of dragging the whole site through the core.
Redundant power
Anything aggregating other switches gets two supplies. Access switches usually do not need it; the thing they all hang off does.
Loop protection
RSTP with the root bridge set deliberately rather than elected by accident, plus BPDU guard on access ports so a desk switch cannot take the floor down.
QoS
Voice and video marked and trusted end to end. Left at default, a file copy and a call compete on equal terms and the call loses.
VLAN plan
Separate data, voice, wireless, CCTV, guest and management — with the management VLAN unreachable from user VLANs. This is also the foundation the firewall policy is written against.

Rough platform fit by site profile

Site profileTypical fitWhat drives the choice
Up to ~25 users, single closet Cisco Catalyst 1300, Meraki MS130, Ubiquiti UniFi PoE for phones and access points, one uplink, no stacking requirement
~25–150 users, one or two floors Cisco Catalyst 9200, Meraki MS130/MS150 Stacking, dual 10G uplinks, PoE+ across the whole estate
150+ users, multi-floor Catalyst 9300 access with a 9500 core Layer 3 at distribution, redundant supplies, sub-second failover
Server room / aggregation Cisco Nexus 9300 series vPC pairs, 10/25G to hosts, low and predictable latency

A starting point for conversation, not a quotation. The right model depends on the port and power count, the uplink strategy, and what is already installed — which is what the site survey establishes.

Platforms

The equipment we standardise on.

We build on mainstream enterprise platforms rather than unbranded hardware. It costs slightly more at purchase and saves considerably later: firmware keeps shipping, spares are available in the region, licensing is transferable, and any competent engineer can pick the system up if you ever move away from us.

Networking

  • Cisco Catalyst
  • Cisco Nexus
  • Cisco ISR
  • Cisco Meraki
  • HPE Aruba
  • Ubiquiti UniFi
  • MikroTik

Security

  • Fortinet FortiGate
  • FortiSwitch
  • FortiAP
  • FortiAnalyzer
  • Palo Alto
  • Sophos

Compute & storage

  • Dell PowerEdge
  • HPE ProLiant
  • Lenovo ThinkSystem
  • Synology
  • QNAP

Power & racking

  • APC by Schneider Electric
  • Vertiv
  • Eaton
  • Panduit
  • CommScope

Cloud & software

  • Microsoft 365
  • Microsoft Azure
  • VMware vSphere
  • Proxmox
  • Veeam
  • Acronis

Product and company names above are trademarks of their respective owners. They are listed to describe the equipment Supply Pillars deploys and supports, and do not by themselves indicate a partnership, authorisation, or reseller status.

Firewalls

What actually matters when you choose a firewall.

Firewalls are usually bought on the headline throughput figure, which is the one number guaranteed not to describe your traffic. Below is what we size against instead — and the questions we will ask you before recommending anything.

Inspected throughput, not the headline
Datasheet firewall throughput is measured with inspection switched off. The figure to size against is threat-protection throughput with IPS and antivirus running, which is a fraction of it. Sizing on the wrong number is the single most common mistake we are called in to fix.
SSL/TLS inspection
Nearly all traffic is encrypted, so a firewall that cannot see inside it is filtering very little. Inspection is expensive in capacity and needs a certificate strategy on the endpoints. Decide before you buy, not after.
Session limits
Concurrent sessions and new sessions per second often run out before bandwidth does — particularly on NAT-heavy networks, CCTV estates, and anything doing lots of short-lived connections.
High availability
An active-passive pair with configuration sync and a dedicated heartbeat link turns a hardware failure into a failover instead of a day without internet. On a single-appliance site, a spare on the shelf is the minimum.
Internal segmentation
A perimeter firewall does nothing about movement between internal systems. Segmentation — VLAN policy, internal firewalling, or both — is what limits how far an incident travels.
Licensing
Subscription bundles determine which features actually run. IPS, antivirus, web filtering and application control are licensed capabilities, and without them a next-generation firewall is an expensive router.
Logging and retention
Logs need somewhere to live and an agreed retention period. FortiAnalyzer or syslog to a collector, decided at design time — because the moment you need six months of history is the moment you discover you kept six days.
Remote access
IPSec site-to-site for branches, dial-up IPSec or SSL for staff, and multi-factor in front of all of it. Remote access without MFA is a credential leak waiting for its turn.

Rough FortiGate class by site profile

Site profileTypical classNotes
Up to ~25 users, single site FortiGate 40F / 60F Desktop form factor, integrated switch ports, modest inspection headroom
~25–100 users FortiGate 80F / 100F Rack-mount, enough capacity to enable SSL inspection, HA pair realistic
~100–500 users FortiGate 200F Internal segmentation, higher session ceilings, redundant power
500+ users or data centre edge FortiGate 400F and above High session rates, 10G interfaces, HA treated as mandatory

Deliberately no throughput figures here. They change between models, firmware versions and enabled feature sets, and a number quoted from memory is worse than no number. We confirm sizing against the current published datasheet for the exact model and feature set at design time.

Engagements

The work people usually call us for.

Most requests fall into one of six shapes. If yours does not, describe it anyway — the survey step exists precisely to scope work that does not fit a template.

New office or branch fit-out

Structured cabling, patch panels and racks, a FortiGate or Cisco edge, wireless coverage planning, and access switching — from bare shell to users working.

Server room refresh

Replacing ageing racks, UPS, cooling and cabling, then migrating servers and storage against a written cutover plan with a rollback position.

Segmentation and hardening

Turning a flat network into VLANs with an enforced policy on FortiGate or Cisco, tightening administrative access, and leaving you the documented rule base.

Multi-site connectivity

Linking branches over resilient WAN with site-to-site VPN or SD-WAN policy, consistent configuration per site, and one place to watch it all from.

Cloud migration and backup

Moving mail and workloads to Microsoft 365 or Azure, with Veeam or Acronis protecting what stays on site — and a restore actually tested, not assumed.

Taking over an existing estate

Inheriting a network nobody documented: we map what is actually installed, list the gaps and risks, then agree a support scope from that baseline.

How we work

From site survey to signed handover.

Every engagement runs as a documented project. You end up knowing what was specified, what was actually installed, and who is accountable for it once we leave.

  1. Survey and designSite assessment, power and capacity requirements, and a written design with a bill of materials you can price against.
  2. Supply and buildEquipment sourced and delivered, then racked, cabled, configured, and tested against that design.
  3. Handover and supportAs-built documentation, configuration handover, and an agreed support and monitoring scope.

Why Supply Pillars

Why Supply Pillars?

Most infrastructure problems are not technical failures. They are accountability gaps — the cabling contractor blames the network vendor, the network vendor blames the firewall, and nobody owns the outcome. We take the whole stack so that cannot happen.

One contract, one owner

Cabling, racks, hardware, network and security sit under a single scope, so there is no seam for a problem to fall through and no vendor to point at.

You keep the documentation

Rack elevations, IP plan, VLAN map, firewall policy and configuration exports are handed over as deliverables. If you ever replace us, none of it walks out with us.

Supportable platforms

Cisco, Fortinet, Dell, HPE and Microsoft rather than whatever was cheapest that month — equipment with a firmware roadmap and regional spares.

Riyadh-based, Kingdom-wide

A local team in your timezone, working in Arabic and English, able to reach a site rather than troubleshoot everything down a phone line.

RiyadhSaudi engineering base
24hInitial response target
KSAKingdom-wide projects

Questions

Before you send a request.

Do you supply the equipment as well as install it?

Yes. We quote, source and deliver the hardware, then install and configure it. You can also buy the equipment yourself and use us for design and installation only — we will still hand over the same documentation.

Which firewall and switching platforms do you work with?

Mainly Fortinet FortiGate for security and Cisco Catalyst and Nexus for switching, plus Cisco Meraki, HPE Aruba and Ubiquiti UniFi where they suit the scale and budget better. We will recommend against a platform if it is wrong for the site, including one we sell.

Will you support equipment you did not install?

Yes, and it is a common starting point. We begin by documenting what is actually in place and listing the gaps and risks we find, then agree a support scope from that baseline rather than inheriting an unknown.

How do you price a project?

The site survey and design come first and produce a bill of materials and a fixed scope. Supply and installation are then quoted against that document, so you are comparing like for like if you tender it elsewhere.

Where do you work?

We are based in Riyadh and take projects across Saudi Arabia. Site work outside Riyadh is planned into the schedule and priced in the proposal rather than added afterwards.

How quickly will I hear back?

Our target is an initial response within 24 hours of receiving a request. Including the site location, rack or user count, and your target date lets us come back with something useful rather than a request for more detail.

Project desk

Tell us the site, the scale, and the timeline.

For a faster response, include rack or user count, site location, any equipment already in place, available power, and your target date.

Request received.

Thank you — your request has reached our desk and we will respond shortly.