It's been a busy year for Hewlett Packard Enterprise’s (HPE) Aruba Networks as it embraces its newfound footing as a leading SD-WAN vendor.

The company spent the better part of 2021 integrating Silver Peak’s EdgeConnect SD-WAN platform, which it bought for $925 million a year earlier, into its Edge Services Platform (ESP). Aruba’s portfolio now encompasses wireless and LAN switching, IoT security, and SD-WAN capabilities.

The integration puts Aruba in a unique position in the market, Silver Peak founder and Aruba CTO David Hughes told SDxCentral in an interview.

“There is really no other company that does everything that we do with one platform,” he said in reference to rivals Cisco and VMware. “Even the big companies that have a lot of unified infrastructure have three different ways to manage things.”

“It’s very confusing for customers to figure out which one they should be using,” Hughes added. “They end up being split brained even though they’re buying from one company.”

Centralized Management for LAN, WAN, and Cloud

Much of Aruba’s early effort was spent tying Silver Peaks’ control plane into Aruba Central, the vendor’s cloud management dashboard. Priority No. 1 was making it easy for Aruba Central users to adopt Silver Peak, Hughes said.

However, this wasn’t as simple as adding a new control panel where customers could manage SD-WAN policy. Aruba saw this as an opportunity to extend networking and security policy across the WAN in a way that was consistent and easy to manage.

“We really identified five areas where there was a real opportunity for us to do something special for our customers,” Hughes said.

These opportunities included lowering the barrier of adoption, extending Aruba’s ClearPass across the WAN, simplifying remote access, unifying security policy, and leveraging artificial intelligence to inform decisions.

Aruba Drives Microsegmentation Into EdgeConnect

Aruba began work on the second of these efforts late last year when it extended support for its ClearPass microsegmentation technology to the EdgeConnect SD-WAN platform.

“It’s really the foundation of Aruba’s pioneering dynamic segmentation system. You can identify users by their role, you can identify devices by their type, and then based on this information, you can do dynamic segmentation,” Hughes said.

The technology enables network and security policy to be applied to any device on the network automatically, including agentless IoT devices. However, traditionally this segmentation was limited to the LAN.

In April, the vendor took a step further and integrated ClearPass into its entire ESP portfolio.

The integration was significant in that it allowed Aruba customers using ClearPass for role-and device-based segmentation on the LAN to extend that segmentation across the WAN to other branches, data centers, or the cloud.

Everything Is an SD-WAN Appliance

The next opportunity on Aruba's integration to-do list was to make it simpler for customers to deploy SD-WAN across their infrastructure.

Typically SD-WAN requires an appliance — either hardware or virtualized — for routing and path selection functionality between branch offices, headquarters, public or private clouds, and/or broken out to the open internet.

While Aruba still offers dedicated EdgeConnect appliances, the company has steadily extended SD-WAN functionality to its entire product stack, including its wireless access points and VPN client.

“Our access points are equipped with the ability to set up IPsec tunnels and be able to get access into a Silver Peak core,” Hughes said, adding this can be scaled up to Aruba’s SD-Branch offering, which is built on a tightly coupled set of gateways, switches, and access points.

The latter, Hughes explained, is ideal for customers with a large number of branch locations — such as retail — where the network configuration won’t differ much or at all from one to the next.

This fall, the vendor also extended SD-WAN functionality to its Micro Branch access points to address the challenges associated with securing remote workers' communications.

Aruba Gets Serious About Security

Unifying Aruba and Silver Peak’s security capabilities was another point of focus in 2021.

This spring, Aruba extended its unified threat management capabilities from its SD-branch offering into its EdgeConnect platform, enabling consistent security functionality to be applied regardless of which SD-WAN technology customers deployed.

The integration included intrusion detection and prevention systems in addition to daily threat feeds.

The update also saw Aruba announce integrations with leading cloud security vendors to automate the process of provisioning new tunnels, reducing the commitment required to adopt a secure access service edge (SASE) architecture. The company currently supports Netskope, Zscaler, Check Point, Palo Alto Networks, and Cloudflare.

Despite these efforts, Aruba's own security was tested in November when HPE disclosed that attackers exposed a “limited subset” of Aruba Central customer data. That attack used an unauthorized access key and exposed two data repositories.

One contained network telemetry data for most Aruba Central customers about WiFi client devices connected to customer WiFi networks. The second contained location-oriented data about WiFi client devices, including which ones were in proximity to other WiFi client devices.

The attackers only stole “a very small amount” of customer data, “if any at all,” according to HPE.

Aruba Melds AIOPs With SD-WAN

The leaked data was used as part of Aruba's artificial intelligence operations (AIOps) functionality, a keen area of focus for the vendor.

In June, the company looked to close the AIOps loop and enable machine learning-based insights to guide policy decisions and remediate issues without human intervention.

The technology was initially introduced in 2020 as part of Aruba Central AI Insights, but was limited to identifying network issues, alerting IT operators of problems, and providing recommendations for remediation.

Aruba expanded on those capabilities this summer to enable automated remediation for known issues. While human interaction is still required the first time a disruption is discovered, subsequent issues can be automatically remediated.

AIOps has become a key differentiator — especially among rivals Juniper Mist, Cisco Meraki, and Extreme Networks, which all offer some kind of AIOps functionality. However, many of these platforms stop short of automated remediation.

Aruba is now looking to extend these capabilities across its entire product stack including the WAN.

“When we think about things relative to EdgeConnect, we think of SD-WAN as being self-driving,” Hughes said. This means “being able to take high-level business goals and translate them into action versus configuring lots of devices and hoping that, if you get the device configuration right, it will do what you want.”

The technology is in growing demand among SD-WAN customers, according to Gartner's latest WAN Edge Infrastructure report. Analysts predict more than 40% of enterprise SD-WAN deployments will utilize some combination of AIOps to automate day-two operations by 2025, compared to fewer than 5% in 2021.

Aruba Isn’t Alone

While Aruba made significant progress integrating Silver Peak’s technology into its broader edge portfolio, the company is far from the only vendor pursuing a converged wireless, LAN, and WAN vision.

Cisco Meraki, Extreme Networks, Juniper Networks, and Fortinet are just a few of the vendors peddling a tightly integrated ecosystem of hardware and software — not unlike Aruba.

Several of these vendors also have a headstart on Aruba, particularly when it comes to SD-WAN and security. Cisco and Fortinet are two of the leading SD-WAN vendors and among the top performers in the firewall and security markets.

Cisco and Fortinet also offer a single vendor SASE architecture, something Aruba, at least for now, does not.

“What we want to be is the edge company that people can partner with to manage all their network and security concerns,” Hughes said, adding that when it comes to security, providing customers choice is paramount. “Large enterprises really value the flexibility of not being locked down. They want the freedom to be able to choose.”