Aruba Networks unleashed a wave of updates to its secure access service edge (SASE) platform during the company’s Atmosphere virtual event today.

The updates stitch together a swath of Aruba product lines under the company’s Edge Services Platform (ESP) SASE offering. ESP now features tight integrations with Aruba’s ClearPass Policy Manager, EdgeConnect SD-WAN — acquired through the $925 million purchase of Silver Peak — and Threat Defense platforms.

Additionally, Aruba extended support to a wider array of cloud security partners, which the company claims provides customers the freedom to deploy a SASE platform built around the cloud-security vendor of their choice.

“What we’re hearing from customers is that they’re kind of fighting this battle on two fronts: One is the exodus from the office for everyone working remote and trying to kind of manage that complexity. And the other one is really about: as I move more of my applications on-prem to cloud, how do I adopt some of these more modern security frameworks like SASE,” explained Paul Kaspian, senior product and solutions marketing manager at Aruba.

Kaspian said these challenges have informed Aruba’s trajectory as it has sought to build out its Edge Services Platform over the past year.

Silver Peak Meets ClearPass, Threat Defense

A key component of today’s announcement is the integration of Silver Peak’s EdgeConnect platform with Aruba’s ClearPass offering.

“The news is really around … bringing the dynamic segmentation and ClearPass to EdgeConnect so that we can really enforce those segmentation policies and those zero-trust best practices at the branch with the EdgeConnect SD-WAN gateways,” Kaspian said.

Aruba claims the integration of ClearPass into ESP will reduce the complexity associated with segmenting network traffic across the branch or data center.

“A lot of our customers, especially in the 50- to 500-site count, were starting to see an increase in devices on their network and really struggle with how to manage these devices from a security point of view,” said Rolf Muralt, senior director of product management at Aruba. “With laptops, you could maybe put an agent on that device. You can’t do that with an IoT device. More than that, it was really the issue that if a device was compromised there was this threat of lateral movement.”

Traditionally, this has been addressed using VLANs to segment traffic, however, Muralt argues that this approach, while functional, is difficult to manage. ClearPass enables a zero-trust model that takes advantage of Aruba’s custom first-packet-based application identification capabilities to segment traffic based on predefined policy.

“Automation is really the big piece that we’ve added here,” Muralt said. "There's no extra definition of users or devices that the IT administrator needs to do within our management or orchestrator. It’s all done on the ClearPass side.”

Meanwhile, Aruba consolidated the unified threat management capabilities from its SD-branch offering into EdgeConnect in order to deliver a consistent suite of security functionality, including intrusion detection and intrusion prevention systems, regardless of which SD-WAN technology is deployed.

Giving Customers Choice

Kaspian explained that the final piece of this was about making it easier for Aruba’s SD-WAN and branch customers to deploy a SASE architecture using their choice of cloud-security vendors.

Since announcing Aruba ESP, the company has focused much of its attention on building out the networking and automation functions of the SASE software stack and has left the cloud-delivered security component to partners like Netskope, Zscaler, and Check Point.

Prior to the acquisition, “Silver Peak was very busy at work focusing on these orchestration capabilities because they saw that customers wanted to adopt things like SASE, and they wanted to use things like Zscalar and Netskope to start doing security inspections closer to those cloud applications,” Kaspian said.

The problem was that because there weren’t always API-level integrations between the SD-WAN platform and the security platform, customers had to manually configure the tunnels to route traffic accordingly, he added.

“A lot of customers had a large number of sites,” he said. "If they had 300,0000, or 500,000 or more sites, it was just hours and hours and hours of tedious configuration work.”

Today's update addresses this by automating much of the work required to provision these tunnels, and thereby reducing the commitment required to adopt a SASE architecture.