Arista Networks is looking to simplify data protection at the edge of enterprise networks with a new security package that combines branch office security with SD-WAN connectivity in a single platform.
The company announced AI-driven , Arista’s vice president, AI, routing, and switching platforms, in a .
ETM security policies are managed in VeloCloud Orchestrator. “Admins can build and assign reusable policies consisting of predefined objects and templates. This design makes updating security policies possible by a few simple clicks, while the associated changes are propagated throughout the network within minutes,” Arista stated.
VeloCloud Orchestrator is the central management, configuration, and monitoring hub for VeloCloud SD-WAN and SASE networks.
In addition, VeloCloud edge routers collect threat intelligence data from a variety of sources to determine in real-time the trustworthiness and identity of hosts inside and outside the network. Through integration with .
Integration with Arista’s AVA policy assistant is aimed at simplifying management of branch security policies. AVA continuously analyzes configuration states and translates complex, multi-site security rules into plain English, Gibbs explained. For example, NetOps administrators can use AI with Ask AVA to predict “how specific traffic will be handled before committing to a deployment, preventing manual configuration errors that leave branches exposed,” Gibbs wrote.
Arista also touted support for network-wide segmentation policies. “The flexible security policy configuration within the Edge Threat Management policy management extends the security coverage from the data center to the branch,” the vendor stated. “Security operations administrators can build access policies that are enforced across a distributed network. The centralized design enables admins to configure and deploy consistent zone based policies across the entire distributed network.”
ETM is a significant addition to the Arista VeloCloud portfolio. Arista and compete more broadly with enterprise networking vendors such as Cisco, Palo Alto Networks, and Fortinet.
In the SASE and SD-WAN world, vendors such as Cisco, Palo Alto, Fortinet, Cato Networks, and Versa Networks are among the most balanced suppliers, with both SD-WAN and SSE contributing meaningful revenue streams, according to a recently published report from Dell’Oro Group.
“We forecast that SASE will remain on a double-digit growth path in 2026, with SSE-first rollouts remaining the most common entry point, and SD-WAN supported by branch modernization, software attach, and branch security refresh,” Dell Oro stated.
“AI is changing the SASE discussion from access and inspection to governance, data protection, and control over agents and machine traffic,” Mauricio Sanchez, senior director, enterprise security and networking at Dell’Oro Group, stated in the report. “A 21 percent Y/Y quarter shows that SASE is not waiting for a future AI refresh cycle; it is already absorbing the early security and networking requirements created by AI adoption,” Sanchez added.
ETM for VeloCloud SD-WAN will be available in Q4 of 2026 and will be available for all current VeloCloud hardware and virtual edge platforms.
SOCIAL SHARE CARD GENERATOR