VeloCloud is the SD-WAN a large share of prospects are already running — a Gartner SD-WAN Magic Quadrant Leader for six consecutive years under VMware, and now under new ownership again. Arista Networks closed its acquisition of the VeloCloud SD-WAN business from Broadcom on June 30, 2025 (announced July 1, 2025) for $300M cash — a figure now disclosed via Arista's SEC 10-Q for FY2025 Q2 — in an asset-plus-talent carve-out bringing roughly half of VeloCloud's ~1,000 employees, primarily core engineering, into Arista's networking portfolio, with VeloCloud co-founder Sanjay Uppal leading the combined Software-Defined Edge business and former Cisco Meraki/VMware executive Todd Nightingale joining Arista as President & COO. The deal is Broadcom's latest step back from VMware's SASE ambitions: the bundled "VeloCloud SASE secured by Symantec" single-vendor offering reached End-of-Sale / End-of-Life on June 30, 2026 — a full year after the acquisition closed, and a separate, later event from the acquisition itself.
Pillar scope: SD-WAN and AIOps only. VeloCloud has no native SSE and no ZTNA in the sense the Codex uses the term — continuous device posture, identity-brokered per-application access. It offers a stateful L7 firewall and segment-based policy at the edge, not a zero-trust access broker. SASE completion depends on a third-party SSE partner; Arista's own current "Best-of-Breed SASE Partners" page documents Zscaler, Netskope, Palo Alto Prisma Access, and Forcepoint integrations (plus a separate Microsoft SSE deployment guide) — corrected 2026-07-22: Cato Networks was previously and incorrectly listed here; no Arista/Cato integration guide or partnership exists, and Cato is positioned as a competing single-pass SASE architecture, not a VeloCloud partner.
Primary fit: Not a SASE platform, and should not be pitched as a peer to Big Six or Emerging vendors. VeloCloud is the incumbent SD-WAN layer a prospect already owns — the conversation is a build-vs-consolidate decision: keep VeloCloud and add a best-of-breed SSE partner, or retire it in favor of a single-vendor SASE platform that converges SD-WAN and SSE under one policy plane.
$300M cash (SEC 10-Q)
(under VMware, historical)
(Broadcom-era offer, discontinued 2026-06-30)
Zscaler · Netskope · Palo Alto · Forcepoint
Three Owners in Nine Years
VeloCloud Networks was one of the original SD-WAN pioneers, patenting Dynamic Multipath Optimization (DMPO) — real-time, per-packet path steering based on continuously measured loss, latency, and jitter. VMware acquired VeloCloud in 2017 and built it into VMware SD-WAN, later bundling it with Symantec's Security Service Edge stack under Broadcom (which acquired VMware for $61B in 2023) as an attempt at single-vendor "VeloCloud SASE." That bundle never reached platform parity with Big Six SASE vendors, and Broadcom — whose core focus is infrastructure software and semiconductors, not SASE — divested the SD-WAN business. Arista Networks closed the acquisition on June 30, 2025, for $300M cash (disclosed via Arista's SEC 10-Q for FY2025 Q2), in an asset-plus-talent carve-out: Arista receives the IP and roughly half of VeloCloud's ~1,000 employees (primarily engineering), while most sales and marketing roles stayed with Broadcom. The Broadcom-era Symantec-bundled SASE offering reached End-of-Sale/End-of-Life under Arista on June 30, 2026 — one year after the acquisition itself closed.
Arista's stated strategy is to extend its campus and data-center networking portfolio into the WAN and branch — pairing VeloCloud SD-WAN with Arista's CloudVision management plane and positioning VeloCloud as the networking half of a best-of-breed SASE stack, not a single-vendor platform. For security, Arista explicitly partners rather than builds: VeloCloud Edge appliances tunnel to a customer's SSE vendor of choice (Zscaler, Netskope, Palo Alto Prisma Access, or Cato Networks SSE), with some orchestration automation (the Zscaler/Arista Business Development Guide v2.0, Jan 2026, documents automated simultaneous branch and security service provisioning from the VeloCloud Orchestrator) but no shared policy engine across vendors.
- DMPO — mature, patented per-packet path steering; one of the original reference implementations in SD-WAN
- Edge Network Intelligence (ENI) — genuine AIOps self-healing and fault isolation across LAN/WAN/wireless
- Broad SSE partner ecosystem — customer chooses Zscaler, Netskope, Palo Alto, or Cato rather than being locked to one
- Zero-touch provisioning designed for non-IT branch deployment
- Arista's campus/data-center networking scale and CloudVision integration for customers already on Arista LAN/WAN gear
- No native SSE or ZTNA — genuinely not a SASE platform; every security function requires a third-party integration
- No private backbone — internet-overlay Gateways, not SLA-backed fiber like Cato
- Symantec-bundled SASE now EOL — any customer sold on that story needs a new security plan
- Ownership transition risk — third owner in nine years; verify current support SLAs, roadmap commitments, and partner-integration continuity directly with Arista
- Gartner's standalone SD-WAN MQ has been superseded by the Single-Vendor SASE MQ. The current SV-SASE MQ roster — Leaders: Palo Alto, Fortinet, Cato, Netskope; Visionaries: Cloudflare, Zscaler; Challengers: Cisco, Versa; Niche Players: Check Point, HPE, SonicWall — does not include Arista/VeloCloud, consistent with its lack of native SSE/ZTNA. No Gartner source explicitly confirms VeloCloud was evaluated and excluded, so this remains a watch item — now with a named current roster rather than a vague "verify directly" note
SD-WAN Analysis
VeloCloud's core architecture has three components: the VeloCloud Orchestrator (cloud or on-prem central management — configuration, provisioning, monitoring, fault management), VeloCloud Gateways (cloud-hosted multi-path optimization and VPN termination points deployed in and near major cloud regions), and VeloCloud Edge appliances (physical, virtual, or cloud-hosted — current lineup spans the 510, 6x0, 7x0, 3xx0, 4100, and 5100 series). DMPO plus Deep Application Recognition (DAR) continuously measure per-link loss, latency, and jitter and steer traffic per application in real time, with active/active multi-link bonding across broadband, LTE, MPLS, and fiber.
DMPO is mature and well-proven — it predates most Big Six SASE SD-WAN products and was one of the reasons VMware VeloCloud held Gartner SD-WAN MQ Leader status for six consecutive years. Zero-touch provisioning is a long-standing VeloCloud strength: Edge appliances ship pre-configured so non-IT branch staff can plug in power and WAN cables and the device auto-registers to the Orchestrator. Cloud on-ramp is solid — Gateways sit in or near major cloud regions (AWS, Azure, GCP), with virtual Edge instances available in cloud marketplaces.
VeloCloud has no private, SLA-backed backbone between Gateways — it is an internet-overlay architecture, architecturally similar to Palo Alto Prisma SD-WAN or Fortinet Secure SD-WAN, not Cato's owned fiber backbone. And critically: SD-WAN + SSE convergence, scored as its own SD-WAN criterion in the Codex, is VeloCloud's weakest score. There is no shared policy plane between VeloCloud and any SSE partner — each partner integration is a separate console with cross-vendor orchestration at the provisioning layer, not a unified policy engine.
▲ Strengths
Mature, patented DMPO path steering with real-time per-link measurement. Strong zero-touch provisioning heritage. Solid cloud on-ramp via Gateways positioned in major cloud regions. Broad hardware lineup covering small branch to data-center-class throughput. Native 5G confirmed 2026-07-11 as a settled single-SKU capability (Edge 710-5G only) across the full current lineup — Arista's own datasheets confirm the 510/610-LTE variants ship LTE-only modems and the 520/540/620/640/680/710-W/720/740/840/2000/3400/3800/3810/4100/5100 models list "Integrated 5G/LTE: No."
▼ Watch Areas
No private backbone — internet overlay only. No native SSE — every security function is a separate vendor and console. Adaptive FEC via per-flow packet duplication on up to two best links, dynamically triggered by measured loss, is documented in Arista's VeloCloud SD-WAN Administration Guide — confirmed, though exact performance parity vs. Cato Socket or FortiGate SD-WAN FEC remains unconfirmed.
AIOps Analysis
Edge Network Intelligence (ENI) is VeloCloud's genuine AIOps differentiator: an ML-driven analytics and self-healing layer that performs fault detection, isolation, and remediation across wired LAN, wireless, WAN, network services, security services, and application layers, then classifies faults to a specific domain — client LAN, WAN, data center, or cloud — and takes or recommends corrective action. ENI predates most Big Six DEM tooling (VMware launched it in 2020) and is explicitly vendor-agnostic for endpoint and IoT visibility. Arista's 2024 VeloRAIN initiative extends this toward AI-workload-aware traffic engineering for distributed inference traffic.
The important distinction for a SASE conversation: ENI is network-operations AIOps, not security AIOps. It has no user-behavioral risk scoring (UEBA), no GenAI natural-language policy authoring, and no MITRE ATT&CK-mapped incident correlation — those are security-domain AIOps capabilities that live on the SSE side of the stack, and VeloCloud doesn't have an SSE side. A VeloCloud customer evaluating Cortex XDR-style cross-product correlation or Cato Dynamic Prevention-style adaptive threat blocking will not find an equivalent inside VeloCloud itself; it would have to come from whichever SSE partner they pair with, if at all.
▲ Strengths
ENI self-healing and automated fault-domain classification is a genuine, mature capability. Vendor-agnostic device/wireless telemetry. Real-time DMPO-driven path optimization with sub-second failover.
▼ Watch Areas
No UEBA, no GenAI policy authoring, no native SOAR. AIOps scope is network health, not security posture — do not position ENI as a substitute for Cortex XDR, ZDX, or Cato XDR in a security-ops conversation.
SSE and ZTNA — Out of Scope by Design
Arista's documented SSE partner integrations for VeloCloud SD-WAN are Zscaler, Netskope, Palo Alto Prisma Access, and Cato Networks SSE. Each is a genuinely separate product with its own console, policy engine, and contract — VeloCloud's Orchestrator can automate branch and security service provisioning in tandem with a partner (per the Zscaler/Arista joint Business Development Guide v2.0, Jan 2026), but this is cross-vendor orchestration, not a converged policy plane. For a customer evaluating what to do about SASE, this is the crux of the decision: continue running VeloCloud and select or keep an SSE partner separately, or retire VeloCloud and adopt a platform where SD-WAN and SSE are one product.
SASE Completion & Replacement Paths
Viable when the branch hardware refresh cycle isn't due, the network team is comfortable with DMPO, and the organization's SASE need is primarily an SSE gap (SWG/CASB/DLP/ZTNA) rather than SD-WAN dissatisfaction. Palo Alto Prisma Access is the closest to a managed pairing given Arista's documented integration; Zscaler or Netskope are viable if the buyer wants best-in-class SSE independent of the SD-WAN vendor. Two consoles, two contracts, two support paths — acceptable for organizations with the operational maturity to run a multi-vendor stack.
The right call when the customer wants one console, one policy plane, and one vendor accountable for the outcome — or when the SD-WAN hardware refresh is already due, making the marginal cost of switching SD-WAN vendors low. Palo Alto (Prisma SD-WAN + Prisma Access under SCM) preserves a richer SD-WAN feature set with a stitched-but-unified management plane. Cato (single-pass SASE Cloud) goes further — SD-WAN, SSE, and ZTNA converge natively with a private backbone VeloCloud never had.
Persona Fit Summary
| Persona | VeloCloud-as-is Fit | Primary Reason | Watch |
|---|---|---|---|
| Lean IT SMB–Mid-market | CONSOLIDATE | A lean team benefits most from one console and one vendor. Cato's native single-pass convergence and ZTP simplicity is a stronger fit than operating VeloCloud plus a separate SSE console. | If the VeloCloud hardware is recently refreshed and budget-constrained, a partner-SSE bridge (e.g. Cato SSE alongside VeloCloud) can defer full consolidation. |
| Global Security Ops Large Enterprise | BRIDGE OR REPLACE | Large security ops teams already running Palo Alto NGFW estate can pair VeloCloud with Prisma Access as a bridge, but most will get a cleaner outcome migrating SD-WAN to Prisma SD-WAN under SCM for one policy plane across firewall, SD-WAN, and SSE. | Verify current Arista/Palo Alto integration depth before committing to a long-term bridge architecture. |
| Data-First / Regulated Finance · Healthcare · Legal | NOT SUFFICIENT AS-IS | VeloCloud has no native DLP, sovereignty program, or compliance certifications of its own. Regulated buyers need a Big Six SSE partner (Netskope for DLP depth, Palo Alto for certifications breadth) at minimum, or full migration to a single-vendor platform for a clean compliance story. | A partner-pairing architecture means compliance is only as strong as the weakest-documented link — audit both vendors' certifications, not just the SSE partner's. |
| Platform / Network Architect 500–5,000 employees | EVALUATE BOTH PATHS | Architects already standardized on Arista for campus/data-center networking have a real reason to keep VeloCloud and add an SSE partner for CloudVision continuity. Architects planning a genuine SASE consolidation (MPLS exit + security convergence in one project) should default to evaluating Cato or Palo Alto as the replacement. | Don't let existing Arista LAN/data-center investment drive the SASE decision by inertia — the SSE gap is the same regardless of switch vendor. |
Changelog
| Date | Version | Change |
|---|---|---|
| 2026-07-22 | v1.5 | VeloCloud's absence from the Gartner Single-Vendor SASE MQ formally accepted as permanently unresolvable via public sources, not an active pending item — Gartner does not publish exclusion rationale, so no public search will ever confirm an evaluated exclusion versus simple non-submission. Decision made per user request; framing unchanged (standing caveat, not a closed fact). |
| 2026-07-22 | v1.4 | Codex-wide accuracy review pass: corrected the documented SSE partner list — Cato Networks does not appear on Arista's current "Best-of-Breed SASE Partners" page and was replaced with Forcepoint (which, along with Zscaler/Netskope/Palo Alto Prisma Access/Microsoft SSE, is actually documented). This error also existed in scores.json's sdwan.sse_convergence note and CLAUDE.md — now fixed everywhere. aiops.genai_policy raised 1→2: Arista's "AI Insights" (via Autonomous Virtual Assist) explains existing policy in natural language, though it does not author policy. |
| 2026-07-11 | v1.3 | Resolved native-5G watch item — confirmed single-SKU (Edge 710-5G only) across the full current lineup via Arista datasheets. Strengthened Gartner SV-SASE MQ note with current named roster (VeloCloud absent, not confirmed excluded). |
| 2026-06-30 | v1.0 | Initial working document created under v2.4 Codex structure. VeloCloud added as a legacy_incumbent comparison-anchor vendor to support incumbent-displacement analysis. Covers the Arista/Broadcom acquisition close (2026-06-30), End-of-Sale/End-of-Life status of Broadcom's Symantec-bundled VeloCloud SASE, and the multi-vendor SSE partner model (Zscaler, Netskope, Palo Alto, Cato). Scored on SD-WAN and AIOps pillars; ZTNA, SSE, and Sovereignty null by design. |
| 2026-07-10 | v1.2 | Codex review pass: CORRECTED acquisition close date (was misstated as 2026-06-30; actual close 2025-06-30, $300M cash disclosed via Arista SEC 10-Q) — this error also existed in CLAUDE.md and scores.json, now fixed everywhere. Resolved FEC/packet-duplication and native-5G (Edge 710-5G) watch items from "unverified" to "confirmed" with appropriate scope caveats. |