→ Back to Home
Cloud Networking

Arista Enhances SD-WAN with AI-Driven Zero Trust for Branch Security

Arista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN. This new offering integrates zero trust security directly into enterprise branch offices, aiming to simplify and unify network and security operations at the WAN edge. Key features include advanced firewalling, threat prevention, zone-based segmentation, Geo-IP filtering, DNS filtering, and AI-powered policy insights, all delivered locally at the branch WAN edge. The ETM functionality will be generally available in Q4 2026 and will support all current VeloCloud hardware and virtual edge platforms. For cloud and DevOps practitioners, this announcement signifies a critical step towards consolidating the increasingly fragmented security and networking stack at the edge. Managing separate firewalls, intrusion detection systems, and SD-WAN appliances across numerous branch locations is a significant operational burden. By embedding zero trust security directly into the SD-WAN platform, Arista is enabling organizations to reduce vendor sprawl, simplify policy enforcement, and enhance their overall security posture. This is particularly relevant as hybrid work models and distributed applications push more traffic and sensitive data to the branch edge, making it a prime target for cyber threats. This development aligns with the broader industry trend of Secure Access Service Edge (SASE) and Network as a Service (NaaS), where networking and security functions converge into a unified, cloud-delivered architecture. The integration of AI for policy insights and threat detection further reflects the growing reliance on intelligent automation to manage complex, dynamic network environments. Companies like Palo Alto Networks, Fortinet, and Zscaler have been aggressively pursuing SASE strategies, emphasizing the need for a single-vendor, integrated approach to secure connectivity. Arista's move with ETM for VeloCloud SD-WAN positions them more strongly in this competitive landscape, offering a compelling solution for enterprises seeking to modernize their branch office infrastructure with a focus on both performance and security. Practitioners should evaluate how this integrated solution can streamline their branch office deployments and ongoing management. The promise of a "single pane of glass" for both networking and security policies through the VeloCloud Orchestrator could significantly reduce operational overhead and accelerate incident response. Organizations currently grappling with disparate security tools at the branch might find this a viable path to consolidation. However, it will be crucial to assess the depth and breadth of the integrated security features against their specific compliance and threat landscape requirements. Furthermore, understanding the AI-powered policy insights and how they translate into actionable security improvements will be key to leveraging the full potential of this offering. This move by Arista underscores the imperative for networking and security teams to collaborate closely, as the lines between these domains continue to blur.
#sd-wan#zero trust#network security#branch office#ai#edge networking
Read original source