HPE Aruba aims to ensure consistent security policy enforcement across all domains, including the campus, branch, data center and cloud. In its latest move, the vendor is extending Application visibility and access policy enforcement capabilities to campus and WAN networks and IoT devices via its Networking Central NetConductor and SD-WAN.

“What specifically we're announcing is that the ability to understand policy and to enforce policy throughout the network is being extended to our core switching capabilities to CX 6300 and 6400 Switches, which is basically the bread and butter of our campus switching portfolio,” Larry Lunetta, VP of portfolio solutions marketing at HPE Aruba, told SDxCentral.

“And we've extended it there as well as SD-WAN. And the way we've extended it is we've given them Application awareness, so they'll be able to understand the Application destinations of the traffic that's flowing through the network,” he added.

Aruba introduced the Networking Central NetConductor last year, initially as the access control approach, Lunetta said. “What we're doing now is up-leveling the policies so that the network administrator or the security team doesn't have to know about this specific device. They just simply have to know what the business rule is that they want to execute, and that gets translated automatically behind the scenes to specific device configurations and controls.”

Expanding app visibility and policy control to campus Switch

Aruba’s latest enhancements are designed to bring Application visibility and policy enforcement to its CX 6300 and 6400 switches, expanding zero-trust network access (ZTNA) to campus and WAN fabrics.

The Central NetConductor helps define application-aware role-based policies propagate L2-L7 network access policies and adds Application firewall capabilities to the switches.

“Previously, to access control policies, you needed to program each Switch to set the ACLs [network access control list] and the VLANs associated with the policies that you're trying to enforce. So that's time-consuming. It's manual, it's error-prone and it's hard to keep up to date,” Lunetta said. “So what we've done is eliminated that part of the process by virtue of being able to express policies in terms of business intent and applications.”

“It's almost like having an Application layer firewall in the Switch itself,” he added, adding this is part of Aruba’s security-first networking strategy to deploy more security functionalities natively inside the network.

Security enhancements via SD-WAN

In addition to campus switches, HPE Aruba has also propagated application-aware access policies across the distributed Enterprise via their Networking EdgeConnect SD-WAN and SD-Branch solutions.

“We've now made our SD-WAN gateways policy-aware and application-aware such that they can actually maintain that policy tag, as they move the traffic geographically out, whether it's to the cloud or whether it's to another physical location,” Lunetta said.

Additionally, Aruba uses standard protocols such as EVPN-VXLAN, which extends unified policy management to third parties that also support these protocols. “With WAN support for standards-based EVPN-VXLAN gateway, organizations can now define policy once and enforce everywhere, from the edge to the cloud,” the vendor claims.

Zero-trust security for IoT

Aruba’s Networking Central NetConductor also aims to enable network and security teams to discover, fingerprint, define and enforce policies for IoT devices for user access control based on zero-trust principles.

“What we do is we have special software that can find and fingerprint IoT devices because that's a big problem for security teams that they can't see what's there, because a lot of times they come on this network outside of the IT environment,” Lunetta said.

He added the security services edge (SSE) capabilities from HPE’s recent Axis Security acquisition will “give the cloud part of the solution more visibility into IoT.”

A vision for unified security policies across all connections

Aruba's goal is to provide a universal security policy across all connection methods. Networking Central NetConductor and SD-WAN bring the strategy to campus, WAN and IoT networks; while SASE to the cloud environment.

The SSE is “the cloud version” of this unified security policy strategy, which bolsters the vendor’s secure access service edge (SASE) solution.

“It's easier to make a SASE decision for Aruba as we have a single policy that can be enforced, no matter how you're accessing the network,” Lunetta said. “Building a winning strategy here is basically to extend SASE to all parts of the network, not just the cloud.”

Lastly, for data center networks, the unified security policy is enforced by the hardware, he added. The HPE Aruba CX 10000 data center Switch series “uses technology from AMD Pensando to build hardware assists for things like inline firewalling so [users can enforce] the same policies.”

Aruba plans to expand this unified policy management capability to more campus and data center Switch series in the future.