Arista Integrates Zero Trust Security into VeloCloud SD-WAN for Branches

Arista Networks will incorporate its Edge Threat Management technology directly into VeloCloud SD-WAN to unify connectivity, firewalls, and threat prevention on a single platform. The solution is slated for general availability in Q4 2026 as a software update for current VeloCloud physical and virtual devices.

The key features of Arista VeloCloud and Edge Threat Management in 30 seconds

  • Arista will embed advanced security into installed VeloCloud SD-WAN devices at branch locations.
  • The platform will include firewalls, segmentation, DNS filtering, geolocation controls, and threat prevention.
  • Administrators will manage connectivity and policies through VeloCloud Orchestrator.
  • Arista AVA will use artificial intelligence to explain rules and simulate their effects.
  • General release is planned for Q4 2026.

This approach aims to reduce the number of devices businesses need to maintain at offices, stores, factories, and other distributed sites. Currently, many networks run SD-WAN connections and firewalls on separate hardware, with different consoles, licenses, and update cycles.

Edge Threat Management (ETM) will be offered as a software extension atop VeloCloud infrastructure. Customers will be able to add these functions without necessarily replacing their existing SD-WAN devices.

Arista presents this integration as a zero-trust architecture. The term does not refer to a specific product but to a security model where users, devices, and connections must be verified and policy-compliant before gaining access to resources. Installing a firewall at the branch alone does not make the entire network zero-trust, but it can provide essential controls to support it.

Unified connectivity and security platform

The new solution will include advanced firewall, threat prevention, zone-based segmentation, geolocation filtering, DNS control, and granular policies for branch traffic.

These functions will run locally at each site’s WAN edge, allowing inspection and control of traffic without always routing it through a central data center or cloud security service.

Local inspection is especially useful when applications reside on the internet or in nearby cloud platforms. Forcing all traffic through a central site adds latency, distance, and bandwidth consumption.

Organizations can manage network and security functions via VeloCloud Orchestrator. Arista promises a unified operating system, a single policy engine, and a centralized console for connection status and rule updates.

Administrative simplification is a major benefit highlighted. Managed service providers operating thousands of branches may struggle to maintain consistent configurations if each site runs separate routers, firewalls, and tools with different interfaces.

T&A Systeme, a German company managing over 7,500 locations across 98 countries, notes that this integration will allow adding security services onto existing SD-WAN infrastructure. They emphasize that this avoids installing and managing separate devices or interfaces, especially in small branches.

Reducing hardware can also cut space, power consumption, and support requirements. However, centralizing controls introduces risks: a failure or misconfiguration in the unified platform could impact both connectivity and security at the site.

Therefore, companies must review high availability, function segregation, recovery procedures, and device behavior during loss of connection to the central orchestrator.

Arista AVA will clarify and test security policies

ETM will leverage Arista AVA, the company’s virtual assistant, to help interpret security rules. Two announced functions are Policy Explainer and Traffic Simulation.

Policy Explainer will translate technical policies into simpler language, aiding review of complex rules and helping administrators understand what traffic is permitted, blocked, or redirected.

Traffic Simulation will enable proactive testing of how a policy might affect a specific connection. An admin could use it to determine if a rule would block access for a particular application before deploying it across all sites.

While this AI-powered assistance can reduce human errors, it does not eliminate the need for manual validation. Arista has not detailed the models behind AVA, the data it uses for explanations, or how accurately simulations replicate real network conditions.

Security policies often include exceptions, shared objects, priorities, and changes made by different teams. Automated explanations can help identify conflicts, but final approval will still rest with the administrators.

The reference to AI does not imply the system will autonomously modify rules. The announcement emphasizes recommendations, explanations, and simulations to support, not replace, human management of security.

First significant integration following VeloCloud acquisition

This launch comes roughly a year after Arista acquired Broadcom’s VeloCloud SD-WAN portfolio. The deal was announced on July 1, 2025, extending Arista’s reach from data center and campus networks into distributed branch connectivity.

VeloCloud had become part of Broadcom via its acquisition of VMware. Arista later purchased this business segment to expand its enterprise networking offerings, complementing its switches, wireless access points, and management tools.

Integrating Edge Threat Management is one of the first visible efforts to unify technologies previously in separate product lines. Arista states that ETM was developed internally and will operate on the VeloCloud platform.

This move coincides with changes to its previous security lineup. In March 2026, Arista announced the phase-out of several physical devices from the ETM NG Firewall Q Series. It also announced the end of virtualized network function services that supported third-party firewalls within certain VeloCloud subscriptions.

These shifts suggest a strategic realignment toward embedded security at the SD-WAN edge, although Arista continues to support connections to external Security Service Edge (SSE) providers for organizations that prefer cloud-based inspection.

Both approaches can coexist: local security is used for segmenting branches, controlling direct connections, and maintaining protection during cloud service outages. SSE platforms enable consistent policies across remote users, SaaS applications, and distributed sites from a global network.

Arista will need to demonstrate that its integrated solution meets the performance and operational standards of standalone firewalls. The announcement lacked details on inspection throughput, signature management, logs, SIEM integrations, or licensing models.

Pricing details have not yet been disclosed. ETM will be available as an update for current VeloCloud physical and virtual platforms, but organizations must verify whether their equipment can handle simultaneous connectivity, inspection, and threat prevention workloads.

General availability is expected in Q4 2026. Until then, these capabilities and claims should be considered as announced features, not yet broadly tested in production environments.

Frequently Asked Questions

What is Edge Threat Management for VeloCloud SD-WAN?

It’s a security extension developed by Arista to integrate firewalls, segmentation, and threat prevention into VeloCloud SD-WAN devices.

Will current VeloCloud devices need replacement?

Arista states ETM will be available for existing physical and virtual platforms. Each organization should verify whether their devices have sufficient capacity for the desired features.

When will the new solution be available?

General availability is planned for Q4 2026. Pricing and detailed licensing information have not yet been announced.

Will AI automatically modify security policies?

The focus is on explaining rules and simulating their impact via Arista AVA. There is no indication that the system will autonomously change policies without administrator input.

Scroll to Top