SASE CODEX
VENDOR DEEP DIVE VELOCLOUD 2026

VeloCloud — Incumbent SD-WAN, Now Under Arista

Pure-Play SD-WAN · No Native SSE · Comparison-Anchor Vendor · SASE Codex Working Document

Bottom Line Up Front

VeloCloud is the SD-WAN a large share of prospects are already running — a Gartner SD-WAN Magic Quadrant Leader for six consecutive years under VMware, and now under new ownership again. Arista Networks closed its acquisition of the VeloCloud SD-WAN business from Broadcom on June 30, 2025 (announced July 1, 2025) for $300M cash — a figure now disclosed via Arista's SEC 10-Q for FY2025 Q2 — in an asset-plus-talent carve-out bringing roughly half of VeloCloud's ~1,000 employees, primarily core engineering, into Arista's networking portfolio, with VeloCloud co-founder Sanjay Uppal leading the combined Software-Defined Edge business and former Cisco Meraki/VMware executive Todd Nightingale joining Arista as President & COO. The deal is Broadcom's latest step back from VMware's SASE ambitions: the bundled "VeloCloud SASE secured by Symantec" single-vendor offering reached End-of-Sale / End-of-Life on June 30, 2026 — a full year after the acquisition closed, and a separate, later event from the acquisition itself.

Pillar scope: SD-WAN and AIOps only. VeloCloud has no native SSE and no ZTNA in the sense the Codex uses the term — continuous device posture, identity-brokered per-application access. It offers a stateful L7 firewall and segment-based policy at the edge, not a zero-trust access broker. SASE completion depends on a third-party SSE partner; Arista's own current "Best-of-Breed SASE Partners" page documents Zscaler, Netskope, Palo Alto Prisma Access, and Forcepoint integrations (plus a separate Microsoft SSE deployment guide) — corrected 2026-07-22: Cato Networks was previously and incorrectly listed here; no Arista/Cato integration guide or partnership exists, and Cato is positioned as a competing single-pass SASE architecture, not a VeloCloud partner.

Primary fit: Not a SASE platform, and should not be pitched as a peer to Big Six or Emerging vendors. VeloCloud is the incumbent SD-WAN layer a prospect already owns — the conversation is a build-vs-consolidate decision: keep VeloCloud and add a best-of-breed SSE partner, or retire it in favor of a single-vendor SASE platform that converges SD-WAN and SSE under one policy plane.

2025-06-30
ARISTA / BROADCOM DEAL CLOSED
$300M cash (SEC 10-Q)
6 Years
GARTNER SD-WAN MQ LEADER
(under VMware, historical)
EOL
SYMANTEC-BUNDLED SASE
(Broadcom-era offer, discontinued 2026-06-30)
4
SSE PARTNER OPTIONS
Zscaler · Netskope · Palo Alto · Forcepoint
🏗
Architecture: Pure-Play SD-WAN, Multi-Vendor SASE by Partnership
Mature DMPO steering and self-healing AIOps — no native security stack

Three Owners in Nine Years


VeloCloud Networks was one of the original SD-WAN pioneers, patenting Dynamic Multipath Optimization (DMPO) — real-time, per-packet path steering based on continuously measured loss, latency, and jitter. VMware acquired VeloCloud in 2017 and built it into VMware SD-WAN, later bundling it with Symantec's Security Service Edge stack under Broadcom (which acquired VMware for $61B in 2023) as an attempt at single-vendor "VeloCloud SASE." That bundle never reached platform parity with Big Six SASE vendors, and Broadcom — whose core focus is infrastructure software and semiconductors, not SASE — divested the SD-WAN business. Arista Networks closed the acquisition on June 30, 2025, for $300M cash (disclosed via Arista's SEC 10-Q for FY2025 Q2), in an asset-plus-talent carve-out: Arista receives the IP and roughly half of VeloCloud's ~1,000 employees (primarily engineering), while most sales and marketing roles stayed with Broadcom. The Broadcom-era Symantec-bundled SASE offering reached End-of-Sale/End-of-Life under Arista on June 30, 2026 — one year after the acquisition itself closed.

Arista's stated strategy is to extend its campus and data-center networking portfolio into the WAN and branch — pairing VeloCloud SD-WAN with Arista's CloudVision management plane and positioning VeloCloud as the networking half of a best-of-breed SASE stack, not a single-vendor platform. For security, Arista explicitly partners rather than builds: VeloCloud Edge appliances tunnel to a customer's SSE vendor of choice (Zscaler, Netskope, Palo Alto Prisma Access, or Cato Networks SSE), with some orchestration automation (the Zscaler/Arista Business Development Guide v2.0, Jan 2026, documents automated simultaneous branch and security service provisioning from the VeloCloud Orchestrator) but no shared policy engine across vendors.

STRUCTURAL STRENGTHS
  • DMPO — mature, patented per-packet path steering; one of the original reference implementations in SD-WAN
  • Edge Network Intelligence (ENI) — genuine AIOps self-healing and fault isolation across LAN/WAN/wireless
  • Broad SSE partner ecosystem — customer chooses Zscaler, Netskope, Palo Alto, or Cato rather than being locked to one
  • Zero-touch provisioning designed for non-IT branch deployment
  • Arista's campus/data-center networking scale and CloudVision integration for customers already on Arista LAN/WAN gear
STRUCTURAL LIMITATIONS
  • No native SSE or ZTNA — genuinely not a SASE platform; every security function requires a third-party integration
  • No private backbone — internet-overlay Gateways, not SLA-backed fiber like Cato
  • Symantec-bundled SASE now EOL — any customer sold on that story needs a new security plan
  • Ownership transition risk — third owner in nine years; verify current support SLAs, roadmap commitments, and partner-integration continuity directly with Arista
  • Gartner's standalone SD-WAN MQ has been superseded by the Single-Vendor SASE MQ. The current SV-SASE MQ roster — Leaders: Palo Alto, Fortinet, Cato, Netskope; Visionaries: Cloudflare, Zscaler; Challengers: Cisco, Versa; Niche Players: Check Point, HPE, SonicWall — does not include Arista/VeloCloud, consistent with its lack of native SSE/ZTNA. No Gartner source explicitly confirms VeloCloud was evaluated and excluded, so this remains a watch item — now with a named current roster rather than a vague "verify directly" note
🌐
Pillar 1 — SD-WAN
DMPO path steering · multi-link bonding · zero-touch provisioning

SD-WAN Analysis


VeloCloud's core architecture has three components: the VeloCloud Orchestrator (cloud or on-prem central management — configuration, provisioning, monitoring, fault management), VeloCloud Gateways (cloud-hosted multi-path optimization and VPN termination points deployed in and near major cloud regions), and VeloCloud Edge appliances (physical, virtual, or cloud-hosted — current lineup spans the 510, 6x0, 7x0, 3xx0, 4100, and 5100 series). DMPO plus Deep Application Recognition (DAR) continuously measure per-link loss, latency, and jitter and steer traffic per application in real time, with active/active multi-link bonding across broadband, LTE, MPLS, and fiber.

What's Genuinely Strong

DMPO is mature and well-proven — it predates most Big Six SASE SD-WAN products and was one of the reasons VMware VeloCloud held Gartner SD-WAN MQ Leader status for six consecutive years. Zero-touch provisioning is a long-standing VeloCloud strength: Edge appliances ship pre-configured so non-IT branch staff can plug in power and WAN cables and the device auto-registers to the Orchestrator. Cloud on-ramp is solid — Gateways sit in or near major cloud regions (AWS, Azure, GCP), with virtual Edge instances available in cloud marketplaces.

What's Structurally Missing

VeloCloud has no private, SLA-backed backbone between Gateways — it is an internet-overlay architecture, architecturally similar to Palo Alto Prisma SD-WAN or Fortinet Secure SD-WAN, not Cato's owned fiber backbone. And critically: SD-WAN + SSE convergence, scored as its own SD-WAN criterion in the Codex, is VeloCloud's weakest score. There is no shared policy plane between VeloCloud and any SSE partner — each partner integration is a separate console with cross-vendor orchestration at the provisioning layer, not a unified policy engine.

Strengths

Mature, patented DMPO path steering with real-time per-link measurement. Strong zero-touch provisioning heritage. Solid cloud on-ramp via Gateways positioned in major cloud regions. Broad hardware lineup covering small branch to data-center-class throughput. Native 5G confirmed 2026-07-11 as a settled single-SKU capability (Edge 710-5G only) across the full current lineup — Arista's own datasheets confirm the 510/610-LTE variants ship LTE-only modems and the 520/540/620/640/680/710-W/720/740/840/2000/3400/3800/3810/4100/5100 models list "Integrated 5G/LTE: No."

Watch Areas

No private backbone — internet overlay only. No native SSE — every security function is a separate vendor and console. Adaptive FEC via per-flow packet duplication on up to two best links, dynamically triggered by measured loss, is documented in Arista's VeloCloud SD-WAN Administration Guide — confirmed, though exact performance parity vs. Cato Socket or FortiGate SD-WAN FEC remains unconfirmed.

SD-WAN pillar comparison — all vendors

🤖
Pillar 2 — AI-Driven Operations
Edge Network Intelligence — self-healing fault detection, not security AIOps

AIOps Analysis


Edge Network Intelligence (ENI) is VeloCloud's genuine AIOps differentiator: an ML-driven analytics and self-healing layer that performs fault detection, isolation, and remediation across wired LAN, wireless, WAN, network services, security services, and application layers, then classifies faults to a specific domain — client LAN, WAN, data center, or cloud — and takes or recommends corrective action. ENI predates most Big Six DEM tooling (VMware launched it in 2020) and is explicitly vendor-agnostic for endpoint and IoT visibility. Arista's 2024 VeloRAIN initiative extends this toward AI-workload-aware traffic engineering for distributed inference traffic.

Network Ops, Not Security Ops

The important distinction for a SASE conversation: ENI is network-operations AIOps, not security AIOps. It has no user-behavioral risk scoring (UEBA), no GenAI natural-language policy authoring, and no MITRE ATT&CK-mapped incident correlation — those are security-domain AIOps capabilities that live on the SSE side of the stack, and VeloCloud doesn't have an SSE side. A VeloCloud customer evaluating Cortex XDR-style cross-product correlation or Cato Dynamic Prevention-style adaptive threat blocking will not find an equivalent inside VeloCloud itself; it would have to come from whichever SSE partner they pair with, if at all.

Strengths

ENI self-healing and automated fault-domain classification is a genuine, mature capability. Vendor-agnostic device/wireless telemetry. Real-time DMPO-driven path optimization with sub-second failover.

Watch Areas

No UEBA, no GenAI policy authoring, no native SOAR. AIOps scope is network health, not security posture — do not position ENI as a substitute for Cortex XDR, ZDX, or Cato XDR in a security-ops conversation.

AIOps pillar comparison — all vendors

SSE and ZTNA — Out of Scope by Design


Not scored. VeloCloud is null on the ZTNA, SSE, and Sovereignty pillars in the Codex. It offers a stateful L7 firewall and segment-based policy at the Edge, but no continuous device posture, no identity-brokered per-application access, no cloud-delivered SWG/CASB/DLP, and no documented sovereignty or data-residency program of its own. Any of those requirements route to a partner.

Arista's documented SSE partner integrations for VeloCloud SD-WAN are Zscaler, Netskope, Palo Alto Prisma Access, and Cato Networks SSE. Each is a genuinely separate product with its own console, policy engine, and contract — VeloCloud's Orchestrator can automate branch and security service provisioning in tandem with a partner (per the Zscaler/Arista joint Business Development Guide v2.0, Jan 2026), but this is cross-vendor orchestration, not a converged policy plane. For a customer evaluating what to do about SASE, this is the crux of the decision: continue running VeloCloud and select or keep an SSE partner separately, or retire VeloCloud and adopt a platform where SD-WAN and SSE are one product.

SASE Completion & Replacement Paths


KEEP VELOCLOUD + ADD SSE PARTNER

Viable when the branch hardware refresh cycle isn't due, the network team is comfortable with DMPO, and the organization's SASE need is primarily an SSE gap (SWG/CASB/DLP/ZTNA) rather than SD-WAN dissatisfaction. Palo Alto Prisma Access is the closest to a managed pairing given Arista's documented integration; Zscaler or Netskope are viable if the buyer wants best-in-class SSE independent of the SD-WAN vendor. Two consoles, two contracts, two support paths — acceptable for organizations with the operational maturity to run a multi-vendor stack.

REPLACE WITH SINGLE-VENDOR SASE

The right call when the customer wants one console, one policy plane, and one vendor accountable for the outcome — or when the SD-WAN hardware refresh is already due, making the marginal cost of switching SD-WAN vendors low. Palo Alto (Prisma SD-WAN + Prisma Access under SCM) preserves a richer SD-WAN feature set with a stitched-but-unified management plane. Cato (single-pass SASE Cloud) goes further — SD-WAN, SSE, and ZTNA converge natively with a private backbone VeloCloud never had.

Persona Fit Summary


PersonaVeloCloud-as-is FitPrimary ReasonWatch
Lean IT
SMB–Mid-market
CONSOLIDATEA lean team benefits most from one console and one vendor. Cato's native single-pass convergence and ZTP simplicity is a stronger fit than operating VeloCloud plus a separate SSE console.If the VeloCloud hardware is recently refreshed and budget-constrained, a partner-SSE bridge (e.g. Cato SSE alongside VeloCloud) can defer full consolidation.
Global Security Ops
Large Enterprise
BRIDGE OR REPLACELarge security ops teams already running Palo Alto NGFW estate can pair VeloCloud with Prisma Access as a bridge, but most will get a cleaner outcome migrating SD-WAN to Prisma SD-WAN under SCM for one policy plane across firewall, SD-WAN, and SSE.Verify current Arista/Palo Alto integration depth before committing to a long-term bridge architecture.
Data-First / Regulated
Finance · Healthcare · Legal
NOT SUFFICIENT AS-ISVeloCloud has no native DLP, sovereignty program, or compliance certifications of its own. Regulated buyers need a Big Six SSE partner (Netskope for DLP depth, Palo Alto for certifications breadth) at minimum, or full migration to a single-vendor platform for a clean compliance story.A partner-pairing architecture means compliance is only as strong as the weakest-documented link — audit both vendors' certifications, not just the SSE partner's.
Platform / Network Architect
500–5,000 employees
EVALUATE BOTH PATHSArchitects already standardized on Arista for campus/data-center networking have a real reason to keep VeloCloud and add an SSE partner for CloudVision continuity. Architects planning a genuine SASE consolidation (MPLS exit + security convergence in one project) should default to evaluating Cato or Palo Alto as the replacement.Don't let existing Arista LAN/data-center investment drive the SASE decision by inertia — the SSE gap is the same regardless of switch vendor.

Changelog


DateVersionChange
2026-07-22v1.5VeloCloud's absence from the Gartner Single-Vendor SASE MQ formally accepted as permanently unresolvable via public sources, not an active pending item — Gartner does not publish exclusion rationale, so no public search will ever confirm an evaluated exclusion versus simple non-submission. Decision made per user request; framing unchanged (standing caveat, not a closed fact).
2026-07-22v1.4Codex-wide accuracy review pass: corrected the documented SSE partner list — Cato Networks does not appear on Arista's current "Best-of-Breed SASE Partners" page and was replaced with Forcepoint (which, along with Zscaler/Netskope/Palo Alto Prisma Access/Microsoft SSE, is actually documented). This error also existed in scores.json's sdwan.sse_convergence note and CLAUDE.md — now fixed everywhere. aiops.genai_policy raised 1→2: Arista's "AI Insights" (via Autonomous Virtual Assist) explains existing policy in natural language, though it does not author policy.
2026-07-11v1.3Resolved native-5G watch item — confirmed single-SKU (Edge 710-5G only) across the full current lineup via Arista datasheets. Strengthened Gartner SV-SASE MQ note with current named roster (VeloCloud absent, not confirmed excluded).
2026-06-30v1.0Initial working document created under v2.4 Codex structure. VeloCloud added as a legacy_incumbent comparison-anchor vendor to support incumbent-displacement analysis. Covers the Arista/Broadcom acquisition close (2026-06-30), End-of-Sale/End-of-Life status of Broadcom's Symantec-bundled VeloCloud SASE, and the multi-vendor SSE partner model (Zscaler, Netskope, Palo Alto, Cato). Scored on SD-WAN and AIOps pillars; ZTNA, SSE, and Sovereignty null by design.
2026-07-10v1.2Codex review pass: CORRECTED acquisition close date (was misstated as 2026-06-30; actual close 2025-06-30, $300M cash disclosed via Arista SEC 10-Q) — this error also existed in CLAUDE.md and scores.json, now fixed everywhere. Resolved FEC/packet-duplication and native-5G (Edge 710-5G) watch items from "unverified" to "confirmed" with appropriate scope caveats.