Arista Networks pushed further into the security market with group segmentation and a zero-trust framework.

The COVID-19 pandemic, and resulting shift to remote work, has made zero-trust security increasingly necessary as employees access corporate networks and data from their homes. This type of security framework assigns rules and policies to users, devices, workloads — essentially anything attempting to connect to the network — and then only allows necessary actions and connections. It uses identity verification and behavior analytics to ensure that only authenticated users and connected things can access applications and data.

But it’s also become a bit of a buzzword, “and anyone associated with security seems to work zero trust into their messaging,” said Allan Bolding, product line manager at Arista Networks. Arista’s zero trust architecture is based on the National Institute of Standards and Technology’s framework, and it combines group-based segmentation, situational awareness and visibility for all network resources, and AI-driven network detection and response, he added.

“That last pillar of zero trust, which is about continual device monitoring and response, is very important to us, and for that we rely on Awake,” Bolding said.

Last year, Arista acquired Awake Security, and has since been integrating Awake’ network detection and response technology into its networking portfolio. In December it released a new threat hunting and incident response service that uses this technology.

The group segmentation service, however, is new, it marks a more pronounced move into the security market for Arista, which Bolding says is essential as security and networking move closer together.

Arista Group Segmentation

“Arista hasn’t really been a security company, and that all started changing last year with some of the features that we’re developing, but also the acquisition of Awake Security,” he said. “So we are coming out with an extensive security offering, and we feel that we have most of the key things we need to be a solid security company at this point.”

The vendor’s new group segmentation service, which it calls MSS-Group, is the latest capability in its Macro-Segmentation Service (MSS) portfolio. The portfolio already includes MSS Firewall that integrates with firewall vendors like Palo Alto Networks and Fortinet, CloudEOS that integrates with hyperscale cloud providers, and MSS Host for the data center, which integrates with VMware to extend that company’s NSX micro-segmentation policies to bare-metal workloads.

The new group segmentation capabilities focus on IoT devices for controlling authorized network communication between groups. Forescout is its first integration partner and others, including Aruba, are on the roadmap.

Available on EOS-based switches, MSS-Group implements security policy enforcement based on logical groups rather than traditional approaches based on interfaces, subnets, or physical ports. It also uses Arista’s CloudVision management plane platform.

Additionally, through its partnership with Forescout, and organizations can use Forescout eyeSegment to automatically apply real-time context to associate each connected device with its relevant security segmentation group, design and monitor group-based policies, and communicate the appropriate segmentation policies to CloudVision. CloudVision is then responsible for the dynamic orchestration of the required policy to the Arista switches for enforcement.

Why Multi-Domain Segmentation Matters

Arista’s approach to segmentation aims to makes network security administration easier across companies’ various domains such as data center, cloud, and edge, explained Jeff Raymond, Arista’s VP for EOS product management and services. “With multi-domain segmentation, we’re hoping to bring a common set of tools that can be applied in various use cases rather than having the siloed architectural approaches to security,” he explained. “It’s intended to simplify network security.”

This unified approach to segmentation will make on going management simpler, said Zeus Kerravala, principal analyst at ZK Research. “This announcement does push them further down the security road, which makes sense as network and security are on a collision course. This is a strong enough solution that Arista could now lead with security.”