Overview
HPE Aruba Networking’s SASE platform is a product of acquisition and integration rather than a single, from-scratch build. The SD-WAN engine, EdgeConnect, was built by Silver Peak Systems (founded 2004, first SD-WAN product shipped 2015) and joined HPE’s Aruba business in a $925 million acquisition completed September 2020. The security half of the platform, HPE Aruba Networking SSE, was previously an independent company called Axis Security before its own acquisition and rebrand. And the parent company itself, Hewlett Packard Enterprise, completed an enormous, contested acquisition of its own in July 2025 - a $14 billion purchase of Juniper Networks, cleared only after a Department of Justice antitrust lawsuit and settlement that required HPE to divest its Instant On WLAN business and licence Juniper’s Mist AIOps source code to competitors. That acquisition is directly relevant here: Juniper’s own SASE-relevant products now sit under the same parent company as EdgeConnect, which is an important fact for any buyer thinking that choosing between different vendor logos automatically means diversifying their supplier base. On its own merits, EdgeConnect’s SD-WAN engine has real, sustained, independent recognition - a consistent Leader in Gartner’s Magic Quadrant for WAN Edge Infrastructure in every report up to its discontinuation after 2022 - and the platform’s architecture supports a distinctive dual path: tight, single-vendor integration with HPE’s own SSE, or a confirmed, named best-of-breed approach integrating with third-party security vendors (Zscaler, Cheque Point, Forcepoint, Netskope, Palo Alto Networks and others) via automated, orchestrated IPsec tunnels. HPE’s own compliance programme is broad and well-documented at the corporate level (global ISO 27001 certification across 90+ sites in 40 countries, SOC 1/SOC 2 attestation), and HPE Aruba Networking Central was, per HPE’s own claim, one of the first networking vendors to achieve FedRAMP High authorization for an entire cloud networking platform (achieved January 2022).
Direct comparison
Put Hewlett Packard Enterprise Company (parent, NYSE: HPE), operating this platform under the HPE Aruba Networking business unit; the converged SASE platform is branded HPE Aruba Networking Unified SASE, combining HPE Aruba Networking EdgeConnect SD-WAN (formerly Silver Peak) and HPE Aruba Networking SSE (formerly Axis Security) beside any provider.
Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.
No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.
Find which providers match your exact needs
Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.
Open the RFP BuilderAgent-accessible research
Ask the Hewlett Packard Enterprise Company (parent, NYSE: HPE), operating this platform under the HPE Aruba Networking business unit; the converged SASE platform is branded HPE Aruba Networking Unified SASE, combining HPE Aruba Networking EdgeConnect SD-WAN (formerly Silver Peak) and HPE Aruba Networking SSE (formerly Axis Security) research record
Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.
Record summary
- Current products
- 7
- Capabilities
- 67
- Coverage records
- 12
- Service models
- 34
- Compliance records
- 13
- Integration records
- 24
- Sector records
- 10
- Evaluation records
- 49
- Public sources
- 37
Products and delivery
7 records| Product | Category | Relationship | Delivery model | Target buyer |
|---|---|---|---|---|
| Cloud Intelligence | SaaS path optimisation | Native | Embedded, cloud-delivered path database | Network administrators |
| EdgeConnect Orchestrator | SD-WAN control plane | Native | Centralised orchestration, integrates with ClearPass API | Network administrators |
| First-Packet iQ | Local internet breakout / intelligent traffic steering | Native | Embedded in EdgeConnect appliances | Branch network administrators |
| HPE Aruba Networking Central | Cloud-native network management and orchestration | Native | Cloud-delivered, AWS/Azure-hosted clusters | NetOps/SecOps admins |
| HPE Aruba Networking ClearPass | Network access control / Zero Trust segmentation | Native | On-premises or cloud-managed | Security administrators, IoT-heavy environments |
| HPE Aruba Networking EdgeConnect SD-WAN | SD-WAN | Native | Physical/virtual appliance, cloud edge (AWS, Azure, Google Cloud, Megaport Virtual Edge) | All buyers |
| HPE Aruba Networking SSE | Security Service Edge (ZTNA, SWG, CASB, DEM) | Native | Cloud-delivered, 500+ global edge locations | All buyers |
Capability evidence
67 recordsAi Automation14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| AI assistant/copilot | Requires Confirmation | Unresolved | Current | The specific mechanism/product name behind the 'AI-native console' claim wasn't itemised |
| AI data protection controls | Requires Confirmation | Unresolved | Current | Not confirmed |
| Anomaly detection | Requires Confirmation | Unresolved | Current | Scope specific to DDoS defence; broader anomaly detection across other threat types not itemised |
| Automated policy recommendation | Unknown | Unresolved | Current | Not confirmed |
| Automated remediation | Requires Confirmation | Unresolved | Current | Scope limited to DDoS threshold adjustment specifically; broader automated remediation (e.g. policy rollback, quarantine actions) not confirmed |
| Capacity/path optimisation | Requires Confirmation | Unresolved | Current | Sourced via a third-party marketplace/comparison page rather than a primary HPE datasheet in this pass for the specific mechanism names |
| Configuration generation | Unknown | Unresolved | Current | Not confirmed |
| Digital experience diagnostics | Requires Confirmation | Unresolved | Current | Technical depth beyond the named capability itself not detailed |
| Generative AI application controls | Requires Confirmation | Unresolved | Current | A general claim exists but lacks the technical specificity found for the strongest equivalent claims among other vendors profiled in this series |
| Natural-language querying | Unknown | Unresolved | Current | Not confirmed |
| Report summarisation | Unknown | Unresolved | Current | Not confirmed |
| Root-cause analysis | Supported | Unresolved | Current | The specific underlying mechanism (e.g. named AI/ML diagnostic tooling) behind the 90% figure wasn't itemised beyond the outcome itself |
| Threat detection/classification | Requires Confirmation | Unresolved | Current | Depth of the ML/detection methodology beyond the confirmed DDoS mechanism not disclosed |
| User/entity behaviour analytics | Requires Confirmation | Unresolved | Current | Not confirmed |
Architecture15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| 5G/LTE support | Supported | High | Current | Native, explicitly named as a supported underlay alongside MPLS and internet (see Supported WAN underlays row above) |
| Application identification | Requires Confirmation | Medium High | Current | Native, implied via the confirmed Business Intent Overlays mechanism, which requires application awareness to apply business-intent-based routing policy |
| Branch LAN/WLAN integration | Requires Confirmation | High | Current | Native, and genuinely a structural strength given HPE Aruba Networking's broader campus-networking heritage - the parent HPE Aruba Networking business unit's product page explicitly lists Wi-Fi access points/controllers and campus/branch/data-centre architecture alongside SASE/SD-WAN as part of one product family |
| Brownfield migration support | Requires Confirmation | Medium High | Current | Native, implied via the confirmed WAN-cost-reduction and MPLS-dependency-reduction framing found consistently across multiple sources, plus the confirmed multi-underlay coexistence architecture (MPLS alongside internet/5G) |
| Dynamic path selection | Requires Confirmation | High | Current | Native, confirmed by name - 'Real-time path selection and WAN optimization ensure consistent application delivery' per a named reseller's technical deep-dive |
| Edge form factors | Requires Confirmation | High | Current | Native - physical appliances confirmed at a specific model level (e.g. the EC-10106 gateway, described as 'ideally suited for small branch and remote office environments'), plus virtual appliance deployment |
| Forward error correction / packet duplication | Requires Confirmation | Low Medium | Current | Not confirmed as a distinct named capability in sources reviewed for the current EdgeConnect product specifically, though this was a core original Silver Peak WAN-optimisation technology historically |
| High availability | Requires Confirmation | Medium High | Current | Native, implied via the confirmed dynamic path selection and multi-underlay (MPLS/internet/5G) architecture, providing automatic failover across diverse transport types |
| LEO satellite support | Unknown | Low | Current | Unknown - not found in sources reviewed |
| Local internet breakout | Supported | High | Current | Native, and genuinely well-evidenced via a specifically-named product - First-Packet iQ, described as designed to 'eliminate wasted bandwidth and performance bottlenecks, by enabling intelligent traffic steering' |
| QoS and traffic engineering | Requires Confirmation | Medium High | Current | Native, implied via the confirmed Business Intent Overlays and dynamic path-selection mechanisms |
| Segmentation / VRF capability | Requires Confirmation | High | Current | Native, confirmed with specific technical detail - role-based segmentation is named directly, and ClearPass provides fine-grained, identity-based segmentation specifically for agentless IoT devices at the network edge |
| Supported WAN underlays | Requires Confirmation | High | Current | Native, confirmed - Business Intent Overlays explicitly combine 'multiple links, such as MPLS, internet, and 5G' |
| Virtual/cloud edge support | Requires Confirmation | High | Current | Native, confirmed across three named hyperscalers plus a named cloud-interconnect platform (Table 3) |
| Zero-touch provisioning | Requires Confirmation | High | Current | Native, confirmed by name - 'Zero-touch provisioning and centralized orchestration accelerate deployment and simplify operations' per a named reseller's technical analysis, corroborated by a second reseller's overview describing the same unified, single-vendor SASE deployment simplicity |
Core Capabilities15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application-aware routing | Supported | High | Current | None identified |
| CASB - API | Requires Confirmation | Low | Current | Not confirmed as distinct from inline CASB |
| CASB - inline | Supported | High | Current | None identified |
| Cloud firewall / cloud network security | Requires Confirmation | High | Current | None identified |
| DNS security | Requires Confirmation | Low | Current | Not confirmed |
| Data loss prevention | Supported | Medium High | Current | None identified |
| Digital experience monitoring | Requires Confirmation | High | Current | None identified |
| Firewall as a Service | Supported | High | Current | None identified |
| Multi-cloud networking | Requires Confirmation | High | Current | None identified |
| SD-WAN | Supported | High | Current | None identified |
| SaaS security posture | Requires Confirmation | Low | Current | Not confirmed |
| Secure web gateway | Supported | High | Current | None identified |
| Threat intelligence | Requires Confirmation | Low Medium | Current | General threat-protection language exists (IDS/IPS, adaptive DDoS) but a named, dedicated threat-research organisation wasn't itemised |
| WAN optimisation | Supported | High | Current | None identified |
| ZTNA | Supported | High | Current | None identified |
Remote Access9 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Clientless access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Contractors/third parties | Requires Confirmation | Unresolved | Current | None identified |
| Managed laptops | Supported | Unresolved | Current | None identified |
| Mobile devices | Requires Confirmation | Unresolved | Current | Not confirmed by a named mobile-specific case study |
| Privileged access | Unknown | Unresolved | Current | Not confirmed |
| Remote browser isolation | Requires Confirmation | Unresolved | Current | Unknown |
| Remote browser isolation | Requires Confirmation | Low | Current | Not confirmed |
| Unmanaged/BYOD devices | Requires Confirmation | Unresolved | Current | None identified |
| VDI environments | Unknown | Unresolved | Current | Not confirmed |
Reporting Analytics14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Compliance reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Custom reports | Unknown | Unresolved | Current | Not confirmed |
| DLP events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Executive dashboard | Requires Confirmation | Unresolved | Current | Not confirmed |
| Network health | Requires Confirmation | Unresolved | Current | Not confirmed |
| Raw log access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Remote-user experience | Requires Confirmation | Unresolved | Current | Not confirmed |
| SLA reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Scheduled reports | Unknown | Unresolved | Current | Not confirmed |
| Security events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Site and circuit performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Threat reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| User experience | Requires Confirmation | Unresolved | Current | okta.com/integrations/hpe-aruba-networking-sse-formerly-axis/ |
Geographic coverage
12 records| Geography | Delivery type | Relationship | Confidence | Qualification |
|---|---|---|---|---|
| Africa coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Asia-Pacific coverage | Partially Evidenced Via HPE'S Own Marketplace Positioning - 'HPE Aruba Delivers Support Across Hybrid WAN Architectures' Including 'Europe, The Middle East, Africa, And Asia-Pacific Countries' Generally, Without Country-Level Specificity | Owned | Low Medium | Partially evidenced via HPE's own marketplace positioning - 'HPE Aruba delivers support across hybrid WAN architectures' including 'Europe, the Middle East, Africa, and Asia-Pacific Countries' generally, without country-level specificity | Direct | General regional presence claimed, not itemised by specific country | No formal regional PoP map found beyond the general regional-presence claim | Low-Medium | A general, credible regional-presence claim exists, though it doesn't substitute for a specific, itemised country-by-country coverage map. |
| Carrier interconnects | Confirmed At A Specific Level Via Megaport Virtual Edge Integration For Cloud-To-Cloud Connectivity | Partner | Medium High | Confirmed at a specific level via Megaport Virtual Edge integration for cloud-to-cloud connectivity | Partner (Megaport) | Wherever Megaport has points of presence | Specific carrier/exchange list beyond Megaport not itemised | Medium-High | A specific, named carrier-interconnect partner - more concrete evidence than a generic 'carrier interconnects available' claim. |
| China coverage | Unknown - No China-Specific Data-Centre Or Licensed-PoP Detail Found In Sources Reviewed | Unknown | Low | Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Data residency choices | Not Independently Confirmed As A Distinct, Named Data-Residency Architecture For The SASE/SSE Platform Specifically In Sources Reviewed, Though Central'S Confirmed Multi-Region Cloud Hosting (AWS Or Azure, 'In Select Regions') Implies Some Deployment-Region Choice | Owned | Medium | Not independently confirmed as a distinct, named data-residency architecture for the SASE/SSE platform specifically in sources reviewed, though Central's confirmed multi-region cloud hosting (AWS or Azure, 'in select regions') implies some deployment-region choice | Direct | Customers can choose AWS or Azure for Central cluster hosting, per confirmed documentation | Specific region-selection detail for the SSE platform specifically not itemised | Medium | Confirmed at the Central (network-management) platform level specifically; SSE-platform-specific data-residency detail is a genuine, specific gap worth closing directly. |
| Latin America coverage | Unknown - No Specific Evidence Found In This Pass | Unknown | Low | Unknown - no specific evidence found in this pass | Unknown | Not specified | No named data centres or customer evidence found for this region specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Middle East coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Private backbone | Not Confirmed As An Owned Private Backbone; The SSE Platform'S Architecture Is Explicitly Described As A 'Multi-Cloud Backbone (AWS, Azure, GCP)' Rather Than Owned Infrastructure | Unknown | High | Not confirmed as an owned private backbone; the SSE platform's architecture is explicitly described as a 'multi-cloud backbone (AWS, Azure, GCP)' rather than owned infrastructure | Hyperscaler-hosted, per the confirmed description | Wherever AWS, Azure and GCP have regions | Distinct from an owned, purpose-built private backbone | High | A specific, clear architectural finding - this platform runs on hyperscaler infrastructure rather than an owned private backbone, a genuine, worth-noting distinction from vendors with confirmed owned-backbone architectures. |
| Public cloud on-ramps | Native, Confirmed Across Three Named Hyperscalers (AWS, Azure, Google Cloud) | Owned | High | Native, confirmed across three named hyperscalers (AWS, Azure, Google Cloud) | Direct | Wherever those hyperscalers have regions | None identified | High | Well-evidenced with specific named platforms. |
| SD-WAN gateways / cloud gateways | Delivered Via EdgeConnect'S Confirmed Cloud Edge Deployment Across AWS, Azure And Google Cloud, Plus Megaport Virtual Edge For Cloud Interconnection | Owned | Medium High | Delivered via EdgeConnect's confirmed cloud edge deployment across AWS, Azure and Google Cloud, plus Megaport Virtual Edge for cloud interconnection | Direct | Wherever those hyperscalers and Megaport have points of presence | Specific gateway count not itemised | Medium-High | Confirmed with genuine hyperscaler-level specificity. |
| Security PoPs / service edges | Confirmed At A Specific Level - 'Over 500 Global Edge Locations' For The SSE Platform, Per Okta'S Own Independently-Hosted Integration Description | Owned | High | Confirmed at a specific level - 'over 500 global edge locations' for the SSE platform, per Okta's own independently-hosted integration description | Direct | Global, 500+ locations (specific country-by-country breakdown not itemised) | Regional breakdown by country/continent not itemised in this pass | High | A specific, concrete, independently-corroborated coverage figure - genuinely stronger evidence than the 'not found' finding common for this row across several other vendors profiled. |
| Sovereign/regional service options | Confirmed At A Specific Level For US Federal - HPE Aruba Networking Central Holds FedRAMP Authorization, Described Directly By HPE As Making It The First Networking Vendor To Achieve Full-Platform FedRAMP Authorization | Owned | High | Confirmed at a specific level for US federal - HPE Aruba Networking Central holds FedRAMP Authorization, described directly by HPE as making it the first networking vendor to achieve full-platform FedRAMP authorization | Direct | United States (federal) | SSE-platform-specific federal authorization not independently confirmed as distinct from the Central authorization | High for Central specifically; Medium for the SSE/SASE platform overall | A genuinely strong, specific, primary-sourced claim for the network-management platform; buyers should confirm directly whether the SSE/security layer carries an equivalent, current authorization. |
Service models
34 recordsOther
SupportedYes | HPE Aruba Networking SSE ZTNA client | Client → SSE | Cloud console | Managed-device remote/hybrid workforce | Not fully detailed | N/A | Confirmed present (Table 5).
Other
Requires ConfirmationNot confirmed as a distinct named service in sources reviewed | Not confirmed | - | - | Buyers wanting partner-led implementation | Not fully detailed | Not found in a Tier 1-2 source in this pass | Evidence gap, though HPE's large reseller/partner ecosystem (evidenced by multiple reseller-hosted case studies and technical content found throughout this research pass) implies real partner-delivered deployment is common in practise.
Other
Requires ConfirmationNative, implied via confirmed BYOD/third-party support, though the exact clientless-vs-agent mechanism wasn't independently itemised | Unknown mechanism specifically | Browser or lightweight agent → SSE | Cloud console | BYOD, contractors, third parties | Not fully detailed | N/A | See Table 5 - real, confirmed support for this use case, with the specific technical mechanism a genuine, worth-flagging gap.
Other
Requires ConfirmationNative, via the confirmed centralised EdgeConnect Orchestrator control plane and zero-touch provisioning architecture | N/A | N/A | Included | Customer-managed via Orchestrator | N/A | Real, confirmed capability via the centralised orchestration architecture, though a distinct, named configuration-management service (as opposed to the platform's own console) wasn't separately itemised.
Other
SupportedNative, via Business Intent Overlays enabling centralised, business-intent-based policy assignment across the WAN, and - for buyers using HPE's own SSE - a unified policy framework across networking and security | N/A | N/A | Included | Customer-managed via Orchestrator/cloud console | N/A | A genuine, confirmed unification point for buyers on the HPE-native SSE path specifically; buyers on the best-of-breed path (Table 6) should expect policy to be managed across two separate consoles rather than one fully unified interface.
Other
Requires ConfirmationNot confirmed as a distinct, named HPE-delivered managed-service product in sources reviewed | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up on whether HPE offers a formal managed-SASE product, given the company's broader managed-services and GreenLake consumption-model business elsewhere in its portfolio.
Other
Requires ConfirmationNot confirmed as a distinct, named MSP/co-management platform in sources reviewed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap, consistent with the Table 9 Multi-tenancy finding.
Other
UnknownUnknown - not found in sources reviewed | Presumably EdgeConnect Orchestrator | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
Requires ConfirmationNot confirmed as a distinct, named HPE-operated NOC service for this platform specifically in sources reviewed | Not confirmed | Not itemised | Not confirmed | Customer configures policy; operational model not detailed | Not itemised with specific figures | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up, particularly given HPE's much broader enterprise support infrastructure across its wider portfolio.
Other
Requires ConfirmationNot confirmed as a distinct named IR service with a specific SLA in sources reviewed | Not confirmed | N/A | Not confirmed | N/A | Not itemised with a specific figure | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationNot confirmed as a distinct, named MSP/multi-tenant capability for this platform specifically in sources reviewed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - no equivalent to some competitors' explicit multi-tenant/MSP-platform claims was found for this specific product line.
Other
Requires ConfirmationNot confirmed as a distinct, named, customer-facing MDR product in sources reviewed | Not confirmed | Not itemised by location | Not confirmed | N/A | Not itemised with a specific figure | Not found as a customer-facing product in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationNative, confirmed across three named hyperscalers | EdgeConnect cloud edge (AWS, Azure, Google Cloud); Megaport Virtual Edge for cloud-to-cloud | Cloud workload → SSE or third-party security stack | EdgeConnect Orchestrator | Multi-cloud/hybrid enterprises | Not fully detailed | Not itemised in detail | Genuinely well-evidenced with specific named platforms (Table 3, 4).
Other
SupportedYes, via EdgeConnect physical appliances | EdgeConnect physical appliance (specific models confirmed, e.g. EC-10106) | Appliance → SSE or third-party security stack via IPsec | EdgeConnect Orchestrator (networking); cloud console (security) | Branch offices | Low, given confirmed zero-touch provisioning | Multi-underlay coexistence confirmed (MPLS alongside internet/5G) | Well-evidenced via specific named hardware and confirmed zero-touch onboarding.
Other
Requires ConfirmationNative, implied via ClearPass's confirmed role-based, identity-driven segmentation capability (Table 4), which extends to network access control and administrative context more broadly per its confirmed 'role-based access control' framing | ClearPass / EdgeConnect Orchestrator | Not fully detailed for general administrative RBAC specifically, as distinct from network-access RBAC | Not itemised further | Not itemised | Not itemised | Reasonable inference from ClearPass's confirmed role-based framework, though this describes network-access control specifically rather than confirmed administrative-console RBAC.
Other
SupportedBusiness Intent Overlays enable centralised, business-intent-driven policy definition across the WAN; for buyers on the HPE-native SSE path specifically, policy extends into a single, unified framework across networking and security | EdgeConnect Orchestrator; cloud SSE console for buyers on the native path | Benefits from familiarity with the Business Intent Overlay model for advanced routing policy | Not itemised further | Positioned as simplified via the confirmed unified single-interface framework, for the native-SSE path specifically | None significant identified for the native-SSE path; buyers on the best-of-breed path should expect two separate policy surfaces (Table 6, 8) | A genuinely bifurcated finding worth being precise about: real simplification exists for buyers choosing the HPE-native SSE path specifically; buyers choosing the best-of-breed path get real flexibility but should expect two separate policy surfaces to manage.
Other
UnknownCloud-based SSE tenant setup; EdgeConnect appliance registration via Orchestrator | Cloud console (SSE); EdgeConnect Orchestrator (SD-WAN) | Not itemised in detail | Zero-touch provisioning confirmed for EdgeConnect specifically | Positioned as low-effort, reinforced by the confirmed zero-touch provisioning claim | None significant identified | Real, confirmed capability, though sourced via a reseller's technical analysis rather than a primary HPE datasheet in this pass.
Other
Requires ConfirmationSSE ZTNA client install, provisioned via confirmed identity integration (Okta specifically) | Cloud console + client | End-user self-install typical for this category | SSO-based provisioning confirmed via the Okta integration | Not itemised further | None significant identified | A named, independently-confirmed SSO integration (via Okta's own page, not just HPE's marketing) is genuinely credible, corroborated evidence.
Other
SupportedYes, and genuinely distinctive in offering a real architectural choice | Mix of EdgeConnect appliances and either HPE-native SSE or a confirmed, named third-party SSE vendor (e.g. Zscaler) | Mixed, with automated, orchestrated IPsec tunnels to the chosen security stack | EdgeConnect Orchestrator (networking) plus either the HPE SSE console or the third-party SSE vendor's own console | Most real-world enterprise estates, particularly those with an existing third-party SSE investment | Moderate - genuinely lower for buyers keeping their existing SSE vendor and only adopting EdgeConnect for SD-WAN specifically | Cushman & Wakefield's named case study (EdgeConnect plus Zscaler) evidences this exact best-of-breed pattern directly | This is genuinely one of the platform's clearest, most concrete differentiators - a real, named, working example (Cushman & Wakefield) of the best-of-breed path, not just a theoretical architectural option.
Other
Requires ConfirmationNot confirmed as a distinct, separately-priced Professional Services product for this platform specifically in sources reviewed, though HPE's large reseller/partner ecosystem (evidenced throughout this research pass by multiple reseller-hosted technical resources) implies real implementation-support capacity exists in practise | N/A | N/A | Not confirmed as a direct HPE offering with specific pricing | N/A | N/A | Real in practise via the confirmed reseller/partner channel, though a direct, named, HPE-priced Professional Services product specifically wasn't confirmed in this pass.
Other
Requires ConfirmationNot applicable in the same sense as an owned-backbone vendor, given the confirmed hyperscaler-hosted (not owned-backbone) SSE architecture (Table 7) | N/A | N/A | N/A | N/A | N/A | N/A | Structurally clear rather than uncertain, given the specifically-confirmed hyperscaler-hosted architecture.
Other
SupportedYes | EdgeConnect virtual appliance | VM → SSE or third-party security stack | EdgeConnect Orchestrator | Cloud/virtualised data centres | Low | Not itemised in detail | Confirmed as a supported form factor across multiple sources.
Other
UnknownUnknown - not found in sources reviewed | Not found | Not specified | Not confirmed | N/A | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationNot confirmed as a distinct named support tier with specific TAM detail in sources reviewed | Not confirmed with specific figures | Not specified | Not confirmed | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationNot confirmed with a specific figure in sources reviewed | Not confirmed | N/A | Not confirmed | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationNative, well-evidenced via named, quantified customer outcomes specifically - Henkel reports a 90% reduction in the time to diagnose and resolve network issues across 450 locations, attributed directly to the platform's confirmed consistent network experience and centralised visibility | EdgeConnect Orchestrator; cloud SSE console | Reduced specialist requirement implied by the specific, quantified outcome | Not itemised as a distinct, named AI-diagnostics feature | Genuinely well-evidenced as low-effort via a specific, named, quantified customer outcome | None significant identified | One of the strongest, most specifically quantified pieces of evidence in this entire profile - a named customer's 90% reduction in issue-resolution time is genuinely compelling, concrete evidence.
Other
Requires ConfirmationZero-touch EdgeConnect appliance provisioning, confirmed by name via a named reseller's technical analysis, reinforced by named customer evidence (Henkel's 450-location deployment, Table 18) demonstrating real onboarding at scale | EdgeConnect Orchestrator (remote) | Low specialist requirement per the confirmed zero-touch mechanism and named customer evidence | Zero-touch provisioning confirmed | Genuinely well-evidenced as low-effort, reinforced by a specific, large-scale (450-location) named customer example | None significant identified | Well-evidenced via both a specific technical mechanism (zero-touch provisioning) and a real, named, large-scale customer example - genuinely solid, concrete evidence.
Other
Requires ConfirmationNot confirmed as a distinct, named HPE-operated SOC service for this platform specifically in sources reviewed | Not confirmed | Not itemised | Not confirmed | Not confirmed | Not itemised with specific figures | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationCloud-delivered updates for the SSE platform are managed centrally; EdgeConnect appliance firmware is managed via the confirmed centralised Orchestrator control plane | EdgeConnect Orchestrator | Low, given the confirmed centralised orchestration architecture | Centralised via Orchestrator | Low | None significant identified | Real, credible capability via the confirmed centralised orchestration architecture.
Other
UnknownUnknown - not found in sources reviewed for EdgeConnect appliance RMA/replacement terms specifically, though HPE's much broader hardware-support infrastructure across its wider server/networking portfolio implies real capability exists | Not found | Not found | Not confirmed for this specific product line | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass at this level of detail | Evidence gap for this specific product line - worth a direct follow-up, though HPE's much larger hardware business overall makes some form of RMA/support programme plausible.
Other
Requires ConfirmationNot confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
UnknownUnknown - not found in sources reviewed | Presumably Orchestrator/console/API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
SupportedYes | HPE Aruba Networking SSE | Via the confirmed 500+-edge-location, multi-cloud backbone | Centralised, cloud console | All customers - core delivery model for the SSE layer | Low-Moderate | N/A - default | Genuinely well-evidenced with specific coverage figures (Table 7).
Other
SupportedYes | EdgeConnect physical appliance | Appliance → SSE or third-party security stack | EdgeConnect Orchestrator | Distributed branch estates | Low, given confirmed zero-touch provisioning | See Table 4 findings | Well evidenced via multiple named customer case studies at real scale (Table 18).
Compliance and assurance
13 records| Framework | Scope | Support | Review date | Qualification |
|---|---|---|---|---|
| DORA relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth flagging for financial-services sector suitability assessment (Table 14), particularly given the named First Bank customer reference elsewhere in this profile. |
| Data residency | Central platform specifically confirmed; SSE platform architecture not detailed to the same depth | Requires Confirmation | Not stated | Partial - Central's cloud clusters confirm a specific, named regional choice (AWS or Azure, 'in select regions'); SASE/SSE-platform-specific data-residency architecture beyond this wasn't independently detailed | Central platform specifically confirmed; SSE platform architecture not detailed to the same depth | AWS or Azure regional hosting choice (Central) | Customer-selectable region, within AWS/Azure availability, for Central specifically | Medium for Central specifically; Low for the SSE platform | Real, confirmed regional-choice flexibility for the Central platform; SSE-platform-specific data-residency detail is a genuine, specific gap worth closing directly. |
| Encryption/key management | Platform | Requires Confirmation | Not stated | Not independently confirmed with specific technical detail (e.g. FIPS validation) in sources reviewed | Platform | Not confirmed at this technical depth | None identified | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | Evidence gap - a common RFP question Netify should source directly from HPE's own security whitepaper or technical documentation. |
| FedRAMP | US federal government, confirmed for the Central network-management platform specifically | Requires Confirmation | Not stated | Authorized, specifically and confirmed for HPE Aruba Networking Central, achieved January 2022, described directly by HPE as making it the first networking vendor to undergo FedRAMP authorization for its entire cloud networking platform. FedRAMP-specific authorization status for the SSE/security platform specifically was not independently confirmed as distinct from the Central authorization in this research pass | US federal government, confirmed for the Central network-management platform specifically | FedRAMP Authorized (Central) | US federal | 22 Jul 2026 | A genuinely strong, specific, primary-sourced, dated claim for the Central platform specifically - a real differentiator worth quoting directly. Buyers should confirm separately whether the SSE/security layer carries an equivalent, current, distinct FedRAMP authorization before assuming full-platform federal readiness. |
| GDPR | N/A | Unknown | Not stated | Not separately itemised as a distinct compliance line item in sources reviewed | N/A | Not confirmed | EU/UK relevant | Not found in a Tier 1-2 source in this pass | Not found | Worth a direct follow-up; HPE's established global, EU-inclusive operations make broader GDPR compliance infrastructure likely, even without SASE-specific documentation surfaced in this pass. |
| HIPAA | N/A | Requires Confirmation | Not stated | Not confirmed as a formal attestation in sources reviewed | N/A | Not confirmed | US healthcare-relevant | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | A specific gap worth a direct follow-up, particularly given confirmed named healthcare-sector customers (Universal Health Services, Hato Hone St John) elsewhere in this profile. |
| ISO 27001 | HPE corporate-wide (per HPE's own Digital Trust Centre materials); Central cloud clusters specifically also confirmed ISO 27001:2022 certified | Unknown | Not stated | Certified, at the parent-company level, with a specific, quantified scope | HPE corporate-wide (per HPE's own Digital Trust Centre materials); Central cloud clusters specifically also confirmed ISO 27001:2022 certified | ISO 27001, covering more than 90 sites in 40 countries per HPE's own claim; ISO 27001:2022 specifically confirmed for Central's cloud data centres | None identified | 22 Jul 2026 | Genuinely well-evidenced with a specific, quantified scope (90+ sites, 40 countries) - stronger, more concrete evidence than a generic certification claim. |
| Logging/auditability | Platform | Requires Confirmation | Not stated | Not independently confirmed as a distinct, named logging/audit architecture (comparable to a confirmed SIEM-export integration) in sources reviewed | Platform | Not confirmed | None identified | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | A specific evidence gap - see Table 12's Syslog/SIEM-integration rows for the related integration-level gap. |
| NHS DSPT relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - a direct follow-up question for UK healthcare-sector suitability assessment. |
| NIS2 relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap. |
| PCI DSS | Central cloud clusters (AWS/Azure-hosted) | Requires Confirmation | Not stated | Confirmed specifically for Central's cloud data centres | Central cloud clusters (AWS/Azure-hosted) | PCI, per Central's confirmed cloud-architecture documentation | None identified | 22 Jul 2026 | Confirmed specifically for the Central platform's cloud infrastructure; PCI-DSS status for the SSE/SASE platform specifically wasn't separately itemised. |
| SOC 2 | HPE corporate support centres; Central cloud clusters specifically | Requires Confirmation | Not stated | Certified, confirmed at two levels - SOC 1 and SOC 2 attestation for HPE customer support centres generally, and SSAE 18 SOC 2 specifically confirmed for Central's cloud data centres | HPE corporate support centres; Central cloud clusters specifically | SOC 1, SOC 2, SSAE 18 SOC 2 | None identified | 22 Jul 2026 | Well-evidenced across two independent primary sources describing consistent, specific certifications. |
| UK public sector frameworks | UK | Unknown | Not stated | Unknown - not found in sources reviewed | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth a direct follow-up given HPE's substantial, long-standing UK public-sector presence more broadly. |
Integrations
24 recordsAWS
Cloud · Native
Cloud | Native, confirmed for both EdgeConnect cloud edge deployment and the SSE platform's multi-cloud backbone | Bidirectional | Not specified | Confirmed across two separate platform components (SD-WAN cloud edge, SSE backbone) | High | Confirmed with genuine depth across both halves of the platform.
Active Directory
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Cheque Point
SSE / Best-Of-Breed Security Partner · Partner
SSE / best-of-breed security partner | Native, confirmed as a named automated-integration partner | Bidirectional, via automated, orchestrated IPsec tunnels | Not specified | Named specifically in the confirmed security-partner integration list | Medium-High | Same evidence quality as the Palo Alto Networks row above.
CrowdStrike
EDR · Unknown
EDR | Not independently confirmed as a direct product integration specifically for this platform in sources reviewed; CrowdStrike appears in the research primarily in the context of a broader Zscaler-Okta-CrowdStrike three-way alliance, not a confirmed direct HPE Aruba Networking-CrowdStrike integration | Unknown | Not specified | Not detailed as a direct integration | zscaler.com/partners/okta-and-crowdstrike (describes the Zscaler-Okta-CrowdStrike alliance, not a direct HPE integration) | Low | Worth being precise: the CrowdStrike connection found in this research runs through the confirmed Zscaler partnership rather than being a direct HPE Aruba Networking-CrowdStrike integration - do not conflate the two.
Google Cloud
Cloud · Native
Cloud | Native, confirmed for both EdgeConnect cloud edge deployment and the SSE platform's multi-cloud backbone | Bidirectional | Not specified | Same confirmed dual-component evidence as AWS/Azure above | High | Same evidence quality as the AWS/Azure rows above.
Google Workspace
Identity/Productivity · Unknown
Identity/productivity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Infoblox
Secure DNS · Partner
Secure DNS | Native, confirmed as a named automated-integration partner specifically for secure DNS | Bidirectional, via automated, orchestrated IPsec tunnels | Not specified | Named specifically as a secure-DNS example in the confirmed integration architecture description | Medium-High | A specific, named DNS-security partner integration - a genuine, concrete example rather than a generic 'DNS security available' claim.
Intune
MDM/UEM · Unknown
MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Jamf
MDM/UEM · Unknown
MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft 365
Productivity/SaaS · Unknown
Productivity/SaaS | Not separately confirmed as a distinct named integration in sources reviewed, though the confirmed Cloud Intelligence (SaaS path-optimisation) capability would architecturally support this class of application | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low-Medium | Reasonable architectural inference; not independently confirmed by name.
Microsoft Azure
Cloud · Native
Cloud | Native, confirmed for both EdgeConnect cloud edge deployment and the SSE platform's multi-cloud backbone | Bidirectional | Not specified | Same confirmed dual-component evidence as AWS above | High | Same evidence quality as the AWS row above.
Microsoft Defender
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Entra ID
Identity · Partner
Identity | Not separately itemised from general identity-partner claims in sources reviewed (Okta is the specifically documented IdP) | Unknown | Not specified | Not detailed | Not found as a distinct integration in this pass | Low | Do not assume Entra ID parity with the confirmed Okta integration without direct confirmation.
Microsoft Sentinel
SIEM · Unknown
SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Netskope
SSE / Best-Of-Breed Security Partner · Partner
SSE / best-of-breed security partner | Native, confirmed as a named automated-integration partner | Bidirectional, via automated, orchestrated IPsec tunnels | Not specified | Named specifically in the confirmed security-partner integration list | Medium-High | Same evidence quality as the Palo Alto Networks/Cheque Point rows above.
Okta
Identity · Native
Identity | Native, confirmed via Okta's own integration catalogue - describing SSO/identity integration for the HPE Aruba Networking SSE platform directly | Bidirectional (auth) | Not specified | Listed in Okta's own catalogue with a dated (October 2024) integration description | High | Independently confirmed by the identity provider itself, not just HPE's own marketing - genuinely solid, corroborated evidence.
Palo Alto Networks
SSE / Best-Of-Breed Security Partner · Partner
SSE / best-of-breed security partner | Native, confirmed as a named automated-integration partner alongside several other named SASE/security vendors | Bidirectional, via automated, orchestrated IPsec tunnels, per the confirmed integration architecture | Not specified | Named specifically in the confirmed security-partner integration list | Medium-High | Confirmed as a named partner within a broader, credible integration list, though with less individual technical depth than the specifically-documented Zscaler relationship.
REST API
Platform API · Api
Platform API | Implied via the confirmed automated, orchestrated integration architecture connecting EdgeConnect to multiple named third-party security platforms, and via ClearPass's confirmed API-based integration with the SD-WAN Orchestrator | Bidirectional | Not specified | The ClearPass-Orchestrator API integration is specifically confirmed with technical detail (propagating user/device/role/posture policy information) | Medium-High | Reasonable, well-supported inference from the confirmed multi-partner integration architecture and the specifically-detailed ClearPass API mechanism.
SCIM/SAML/OIDC
Identity Federation · Unknown
Identity federation | SAML/SSO implied via the confirmed Okta integration | Bidirectional (auth) | Not specified | Not detailed by specific protocol name beyond the general SSO framing | Medium | Reasonable inference from the confirmed Okta SSO integration; specific protocol names weren't spelled out.
ServiceNow
ITSM · Unknown
ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Splunk
SIEM · Unknown
SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Syslog
Log Export · Unknown
Log export | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Terraform
Infrastructure-As-Code · Unknown
Infrastructure-as-code | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Zscaler
SSE (Best-Of-Breed Security Partner) · Native
SSE (best-of-breed security partner) | Native, deeply and specifically confirmed - a dedicated HPE-Zscaler joint solution brief exists, describing 'best-of-breed zero trust and SASE frameworks' via 'an automated and scalable solution', reinforced by a named customer deployment (Cushman & Wakefield) and independent corroboration from Zscaler's own marketplace listing noting 'strong integrations' with HPE Aruba EdgeConnect specifically | Bidirectional, via automated, orchestrated IPsec tunnels | Not specified | Genuinely the best-documented single security-partner integration for this platform, evidenced from three independent angles: a joint HPE-Zscaler document, a named customer case, and Zscaler's own independent listing | High | Genuinely one of the best-evidenced integrations across this entire profile series - three independent angles of confirmation (joint solution brief, named customer, independent third-party corroboration) is a materially stronger evidentiary picture than most integration rows achieve.
Sector evidence
10 recordsEducation
UnknownGood fit, evidenced | Consistent network experience and centralised management relevant to distributed campus/student environments | Not assessed for sector-specific frameworks | A named reference describing a centrally-managed, high-performance network delivering 'a home-from-home experience for Oxford students'; Edmonton Public Library's digital-space modernisation is a related, if not strictly higher-education, public-education-adjacent reference | UK (Oxford) and Canada (Edmonton) - genuine international sector evidence | Both references are qualitative rather than quantified with a specific metric | Two independently named, international, credible references - real sector evidence, though without the specific quantified metrics found for some other sectors in this profile (e.g. Manufacturing's 99%+ uptime, Government's FedRAMP date).
- Named evidence
- A named reference describing a centrally-managed, high-performance network delivering 'a home-from-home experience for Oxford students'; Edmonton Public Library's digital-space modernisation is a related, if not strictly higher-education, public-education-adjacent reference
- Case study strength
- Strong
Energy/utilities
Not SupportedUnknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Financial services
Requires ConfirmationConditional - one named customer reference exists, but no PCI-DSS or DORA-specific certification was confirmed for the SASE/SSE platform specifically | SD-WAN cost-reduction and application-performance capabilities plausibly relevant | PCI confirmed for Central's cloud infrastructure specifically (Table 13); DORA not confirmed | First Bank (SASE-based SD-WAN, cost reduction, application performance, cloud-smart technology strategy) | N/A | Compliance evidence is narrower than the named customer evidence would suggest is needed for full sector confidence | A real, named financial-services customer exists, though Netify should be precise that platform-wide PCI/DORA-specific certification for the SASE/SSE components specifically wasn't independently confirmed.
- Named evidence
- First Bank (SASE-based SD-WAN, cost reduction, application performance, cloud-smart technology strategy)
- Case study strength
- Strong
Government/public sector
UnknownStrong fit, evidenced | FedRAMP authorization for HPE Aruba Networking Central specifically | FedRAMP Authorized (Central, January 2022, described as first-of-its-kind full-platform authorization) | None found as a named individual agency case study in this pass, though the confirmed FedRAMP authorization is itself a strong sector proof point | US federal specifically confirmed | SSE-platform-specific federal authorization status not independently confirmed as distinct from Central | A genuinely strong, well-evidenced, primary-sourced compliance foundation for this sector, tempered by the specific, worth-flagging caveat that SSE-platform federal authorization wasn't separately confirmed.
- Named evidence
- None found as a named individual agency case study in this pass, though the confirmed FedRAMP authorization is itself a strong sector proof point
- Case study strength
- None
Healthcare/NHS
Requires ConfirmationGood fit, evidenced, though without a formal HIPAA attestation confirmed | SD-WAN reliability and DEM plausibly relevant to telehealth/clinical-application performance specifically | HIPAA not confirmed as a formal attestation | Universal Health Services (telehealth, assured network performance and reliability); Hato Hone St John (New Zealand ambulance/healthcare service, digital transformation of healthcare operations); USANA Health Sciences (global efficiency, application performance and savings from Unified SASE, per a named reseller case study) | Named customers in both US and New Zealand markets | No formal HIPAA attestation confirmed despite the named healthcare customer evidence | Two independently named healthcare-sector customers give real, credible sector evidence, though Netify should not assume formal HIPAA compliance without direct confirmation, given this wasn't found in this research pass.
- Named evidence
- Universal Health Services (telehealth, assured network performance and reliability); Hato Hone St John (New Zealand ambulance/healthcare service, digital transformation of healthcare operations); USANA Health Sciences (global efficiency, application performance and savings from Unified SASE, per a named reseller case study)
- Case study strength
- Strong
Hospitality
UnknownGood fit, evidenced | Consistent network experience and branch/site connectivity relevant to distributed hospitality operations | Not assessed | A named hotel reference: 'Network excellence enables hotel to streamline operational efficiency and drive service innovation' | N/A | Anonymised (described as 'a hotel' without further naming detail in the source reviewed) | A real, if not fully named, hospitality-sector reference - worth a direct follow-up to identify the specific hotel/hotel group if a fully named case study is needed.
- Named evidence
- A named hotel reference: 'Network excellence enables hotel to streamline operational efficiency and drive service innovation'
- Case study strength
- Strong
Manufacturing
UnknownGood fit, evidenced | SD-WAN reliability directly relevant to distributed manufacturing operations | Not assessed for sector-specific frameworks | IMMI (99%+ uptime ratio reported across all branches using EdgeConnect as a turn-key, out-of-the-box solution) | N/A | Single case study, though genuinely specific and quantified | A specific, quantified (99%+ uptime), named manufacturing customer reference - genuinely credible, concrete sector evidence.
- Named evidence
- IMMI (99%+ uptime ratio reported across all branches using EdgeConnect as a turn-key, out-of-the-box solution)
- Case study strength
- Strong
Professional services
UnknownGood fit, evidenced, and genuinely the platform's best-documented individual case study | The confirmed best-of-breed SD-WAN-plus-third-party-SSE architecture (Table 6) directly relevant to this sector's typical existing security-vendor investments | Not assessed for sector-specific frameworks | Cushman & Wakefield (global commercial real estate services firm) - 'boost global network performance and security with Aruba EdgeConnect SD-WAN edge platform and Zscaler cloud-delivered SASE' | Global deployment implied by the confirmed 'global network performance' framing | Single case study, though it directly demonstrates the platform's most architecturally distinctive capability | Genuinely the most strategically important case study in this entire profile - a real, named, global professional-services customer using the exact best-of-breed (EdgeConnect plus Zscaler) architecture that is this platform's clearest differentiator.
- Named evidence
- Cushman & Wakefield (global commercial real estate services firm) - 'boost global network performance and security with Aruba EdgeConnect SD-WAN edge platform and Zscaler cloud-delivered SASE'
- Case study strength
- Strong
Retail
Not SupportedUnknown - not assessed, no case study found specifically labelled retail in this pass | SD-WAN/branch capability plausibly relevant | Not assessed | None found specifically labelled retail | N/A | No case study found | Evidence gap.
- Named evidence
- None found specifically labelled retail
- Case study strength
- None
Transport/logistics
Not SupportedUnknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Case studies
3 records- Customer
- Named - IMMI
- Sector and geography
- Manufacturing · Not specified
- Estate
- Not quantified; All branches (specific count not itemised)
- Outcome
- 99%+ uptime ratio reported across all branches
Named - IMMI | Manufacturing | Not specified | Not quantified | All branches (specific count not itemised) | Needed a reliable, turn-key SD-WAN solution deployable out-of-the-box across all branch locations | Aruba EdgeConnect (described specifically as an 'out of the box turn-key solution') | Turn-key branch deployment across all IMMI branches | Not itemised | 99%+ uptime ratio reported across all branches | High - named customer, a specific, quantified, credible uptime metric (99%+), directly referenced on HPE's own customer-story index | A specific, quantified, genuinely credible reliability metric for a real, named manufacturing customer - strong, concrete evidence for buyers prioritising uptime/reliability specifically.
- Customer
- Named - Cushman & Wakefield
- Sector and geography
- Professional services / commercial real estate · Global
- Estate
- Not quantified; Not quantified
- Outcome
- Described as boosting 'global network performance and security', per HPE's own customer-story index
Named - Cushman & Wakefield | Professional services / commercial real estate | Global | Not quantified | Not quantified | Needed to boost global network performance and security across a distributed, international professional-services estate | Aruba EdgeConnect SD-WAN edge platform, paired with Zscaler cloud-delivered SASE (a genuine, named best-of-breed architecture) | Best-of-breed: EdgeConnect for SD-WAN, third-party (Zscaler) for cloud-delivered security | Zscaler (explicitly named and confirmed) | Described as boosting 'global network performance and security', per HPE's own customer-story index | High for demonstrating the architectural pattern (named customer, named specific technology pairing); Medium for outcome specificity (no numeric metric given in the source reviewed) | The single most strategically important case study in this profile - a real, named, global customer using the exact best-of-breed pairing (EdgeConnect plus Zscaler) that is this platform's clearest architectural differentiator, independently reinforced by Zscaler's own corroborating materials elsewhere in this profile.
- Customer
- Named - Henkel
- Sector and geography
- Manufacturing/consumer goods · Global (450 locations)
- Estate
- Not quantified; 450 locations
- Outcome
- Established a consistent network experience across 450 locations; reduced the time to diagnose and resolve network issues by 90%
Named - Henkel | Manufacturing/consumer goods | Global (450 locations) | Not quantified | 450 locations | Needed a consistent network experience across a very large, distributed global estate, with efficient issue diagnosis and resolution | HPE Aruba Networking unified SASE | Distributed branch/site deployment across 450 global locations | Not itemised | Established a consistent network experience across 450 locations; reduced the time to diagnose and resolve network issues by 90% | High - named customer, specific and large-scale figures (450 locations, 90% reduction), directly quoted on HPE's own primary product page | One of the strongest, most specifically quantified case studies found across this profile series - a precise, credible, named-customer efficiency metric (90% reduction) at genuine, large-scale (450 locations).
Netify evaluation record
49 recordsSummary
MPLS to SD-WAN migration | Evidenced consistently via the confirmed multi-underlay (MPLS alongside internet/5G) coexistence architecture, and reinforced by Bethesda's named case reference specifically describing 'six-figure cost savings versus MPLS' | Existing MPLS circuits coexist during transition per the confirmed multi-transport architecture | IT team, with reseller/partner support available per the confirmed channel ecosystem | HPE reseller/partner network | Not quantified with a specific timeline in this pass | Coexistence-period complexity if not carefully sequenced | The confirmed multi-underlay Business Intent Overlay architecture is explicitly designed to support gradual migration rather than a forced cutover | Well-evidenced via both the underlying multi-transport architecture and a specific, named, quantified customer outcome - genuinely credible evidence for this exact scenario.
Summary
Limitation | The FedRAMP authorization confirmed in this research pass applies specifically to HPE Aruba Networking Central; no independent confirmation was found that the SSE/security layer specifically carries an equivalent, current, distinct FedRAMP authorization | Federal buyers evaluating the full SASE/SSE platform (not just Central network management) cannot currently verify SSE-specific FedRAMP status from public sources | Affects US federal/regulated buyers most specifically | Table 7, 13 findings | Medium-High (confident about what was and wasn't found in this specific research pass) | A precise, specific, easy-to-miss distinction - worth confirming directly rather than assuming the well-evidenced Central authorization automatically extends to the SSE layer.
Federal buyers evaluating the full SASE/SSE platform (not just Central network management) cannot currently verify SSE-specific FedRAMP status from public sources
Summary
Compliance & Footprint | A broad, well-documented, primary-sourced corporate compliance programme - global ISO 27001 across 90+ sites in 40 countries, SOC 1/SOC 2 attestation, TISAX for automotive, CSA STAR for cloud platforms, and a specific, dated (January 2022) FedRAMP authorization for HPE Aruba Networking Central described directly as a first-of-its-kind, full-platform achievement. | The FedRAMP authorization confirmed in this research pass applies specifically to HPE Aruba Networking Central (the network-management platform); this profile did not find independent confirmation that the SSE platform specifically carries an equivalent, current FedRAMP authorization, which is worth confirming directly for any federal buyer evaluating the SASE/SSE components specifically.
Summary
Mid-market | Good fit | Named customer evidence (Cushman & Wakefield, First Bank, IMMI) spans real-world organisations of varying scale, evidencing genuine mid-to-large applicability | Benefits from, but doesn't strictly require, dedicated network-engineering staff given confirmed zero-touch onboarding | Not itemised | Table 17, 18 findings | Reasonably well evidenced across multiple named customer references at varying scale.
Summary
Who is this genuinely best suited for? (mandatory) | Large, distributed enterprises wanting a genuinely proven, independently-recognised SD-WAN engine (seven consecutive years as a Gartner Magic Quadrant Leader); organisations with an existing, separate SSE vendor relationship - particularly Zscaler, given the depth of that specific, multiply-corroborated integration - wanting best-of-breed pairing rather than a forced platform switch; and US federal/public-sector buyers needing a FedRAMP-authorized networking-management platform specifically. | Tables 1, 3, 6, 12, 13, 19 | High | Buyers matching this profile - especially those with an existing Zscaler investment - can proceed with genuine confidence, backed by real, named, multiply-corroborated evidence for exactly this use case.
Buyers matching this profile - especially those with an existing Zscaler investment - can proceed with genuine confidence, backed by real, named, multiply-corroborated evidence for exactly this use case.
Summary
Limitation | HPE completed a $14 billion acquisition of Juniper Networks in July 2025 - the company's largest-ever acquisition, cleared only after a contested DOJ antitrust lawsuit and settlement - meaning this platform now sits within a parent organisation that also owns a separate, competing SASE-relevant product line under the same corporate umbrella and is mid-way through a major post-merger integration | Buyers face genuine, current roadmap and organisational-stability uncertainty during a major, ongoing corporate integration, and should confirm HPE's specific plans for rationalising overlapping Aruba/Juniper networking portfolios directly | Affects all buyer sizes considering a long-term platform commitment, though large enterprises making multi-year infrastructure decisions are most exposed to roadmap risk specifically | Table 1, 19 findings | High (the acquisition and its scale/contentiousness are well-documented across multiple independent sources) | Netify should flag this proactively and specifically - it is the single most consequential organisational fact about this vendor as of this profile's research, and a buyer evaluating long-term platform stability should not discover it only after committing.
Buyers face genuine, current roadmap and organisational-stability uncertainty during a major, ongoing corporate integration, and should confirm HPE's specific plans for rationalising overlapping Aruba/Juniper networking portfolios directly
Summary
Remote-user-heavy organisation | Good fit | Confirmed BYOD, third-party, and contractor support via Okta's own independently-hosted integration description, alongside confirmed DEM capability for monitoring remote-user experience | None significant identified | Not assessed | Table 5, 10 findings | Real, credible capability across managed-device, BYOD, and third-party access scenarios, evidenced via an independent source (Okta) rather than only HPE's own marketing.
Summary
Strength | Specific, quantified, named customer outcomes at genuine scale - Henkel's 90% reduction in issue diagnosis/resolution time across 450 locations, and IMMI's 99%+ uptime ratio, are both concrete, credible, primary-sourced metrics | Buyers get real, checkable proof points for operational-efficiency and reliability claims specifically, not just generic marketing language | Best: any buyer wanting quantified evidence before committing. Less relevant: N/A - this benefits any evaluation | High | Genuinely among the strongest, most specifically quantified case-study evidence found across this profile series.
Buyers get real, checkable proof points for operational-efficiency and reliability claims specifically, not just generic marketing language
Summary
Deployment & Ops | Named, quantified customer outcomes are genuinely strong and specific - Henkel reports a 90% reduction in the time to diagnose and resolve network issues across 450 locations, and Bethesda reports six-figure cost savings versus MPLS with a 50% reduction in management and troubleshooting overhead. | The platform's dual heritage (EdgeConnect from Silver Peak, SSE from Axis Security) means a buyer evaluating console and policy unification should confirm current integration depth directly rather than assume a single, ground-up-built platform's level of architectural consistency.
Summary
Most credible differentiator | A genuine, real-world-proven, best-of-breed architecture - the ability to pair a genuinely mature, seven-time-Gartner-Leader SD-WAN engine with an existing, separate SSE vendor investment (most deeply evidenced with Zscaler, via a named customer and independent third-party corroboration) rather than forcing a full single-vendor platform switch. | Tables 6, 12, 18, 19 | High | This is the single sentence Netify's comparison engine could most confidently quote for this vendor specifically.
This is the single sentence Netify's comparison engine could most confidently quote for this vendor specifically.
Summary
What implementation challenges should buyers expect? (mandatory) | Expect genuinely low-friction deployment via confirmed zero-touch provisioning, reinforced by real, quantified named-customer evidence at scale (Henkel's 450 locations). Expect a real, specific choice at the outset between the HPE-native SSE path (genuinely unified single-console management) and the best-of-breed third-party path (real architectural flexibility, but two separate management consoles to operate day-to-day). Expect the commercial conversation to require a direct HPE or reseller-partner engagement from the start, given the complete absence of published pricing. | Tables 6, 8, 9, 16 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Summary
Scope & Boundaries | A confirmed, specific, named local-internet-breakout technology (First-Packet iQ) and real-time cloud-path intelligence for SaaS applications give the platform genuine, concrete technical depth beyond generic SD-WAN marketing claims. | The July 2025 Juniper acquisition, and HPE's required divestiture of its Instant On WLAN business as part of the DOJ settlement, both represent genuine, current organisational change - buyers evaluating long-term roadmap stability should factor in that this is a company mid-way through digesting its largest-ever acquisition.
Summary
Overall Netify Assessment | This platform's most credible, best-evidenced strengths - a genuinely proven, independently and repeatedly recognised SD-WAN engine, and a real, working, multiply-corroborated best-of-breed architecture (most deeply evidenced via Zscaler) - both flow directly from the platform's acquisition history (Silver Peak for SD-WAN, Axis Security for SSE) rather than from a single, ground-up build. That heritage is a genuine strength for buyers wanting proven technology and architectural flexibility, and it sits within a parent company (HPE) that just completed its own largest-ever, most contested acquisition ($14B, Juniper Networks, July 2025) - a genuinely current, well-documented, and material source of roadmap and organisational uncertainty that this profile cannot resolve from public sources alone. This profile is solid enough to support initial shortlist guidance for large-enterprise, best-of-breed-architecture, and US-federal buyers specifically, but the flagged Juniper-integration uncertainty and the SSE-specific FedRAMP/compliance gaps should be closed out directly with HPE before use in a high-stakes, long-term procurement decision. | Whole profile | Medium-High overall | Recommend direct HPE engagement to clarify the post-Juniper-acquisition roadmap and close the flagged SSE-specific compliance gaps before this profile supports a high-stakes procurement decision.
Recommend direct HPE engagement to clarify the post-Juniper-acquisition roadmap and close the flagged SSE-specific compliance gaps before this profile supports a high-stakes procurement decision.
Summary
VPN to ZTNA migration | Not evidenced via a named case study specifically describing VPN retirement in favour of ZTNA in sources reviewed, though the confirmed ZTNA architecture (Table 3) implies this is a supported path | Existing VPN infrastructure | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | A genuine evidence gap - the underlying ZTNA capability is confirmed, but no named customer scenario specifically describes VPN retirement in this pass.
Summary
Procurement watch-out | Buyers choosing the best-of-breed architectural path (EdgeConnect plus a third-party SSE vendor) should expect to manage two separate policy/management consoles rather than one fully unified interface, a real, specific operational trade-off against the architectural flexibility that path offers | Lean IT teams specifically should weigh this trade-off carefully - real flexibility versus real added console-management overhead | Most relevant to lean IT teams choosing the best-of-breed path specifically | Table 6, 8, 9, 15 findings | Medium (based on the sources reviewed describing HPE-native SSE and third-party SSE as architecturally distinct paths with correspondingly distinct management surfaces) | A specific, worth-flagging operational nuance for lean-team buyers specifically - worth a direct question on current cross-console visibility/integration depth for whichever specific third-party SSE vendor a buyer is considering.
Lean IT teams specifically should weigh this trade-off carefully - real flexibility versus real added console-management overhead
Summary
Merger/acquisition integration | Not documented via a named M&A-specific customer scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap for a customer M&A scenario. (Separately, and notably, HPE itself has extensive, direct, current M&A integration experience of its own - Aruba 2015, Silver Peak 2020, Juniper 2025 - though this describes HPE's own corporate activity, not a customer integration scenario.)
Summary
Limitation | No pricing has been published for HPE Aruba Networking SSE in any source found in this research pass, including a dedicated third-party pricing aggregator that explicitly confirmed no pricing information exists | Buyers cannot self-serve any budget estimate at all, even a rough one, and must engage HPE or a reseller partner directly from the very first conversation | Affects all buyer sizes, though smaller buyers wanting to self-shortlist based on approximate cost are most affected | Table 16 findings | Medium (confident about the absence found in this specific research pass, though pricing information may exist that wasn't surfaced) | A genuinely notable commercial-opacity gap - consistent with the broader pattern across this vendor category, but worth setting buyer expectations around directly.
Buyers cannot self-serve any budget estimate at all, even a rough one, and must engage HPE or a reseller partner directly from the very first conversation
Summary
Lean IT team | Good fit, particularly for buyers on the HPE-native SSE path | Confirmed zero-touch provisioning, centralised Orchestrator management, and - for the native-SSE path specifically - a genuinely unified single policy framework all support a low-operational-burden story | Minimal training investment implied by confirmed zero-touch mechanisms | Not assessed | Table 8, 9, 15 findings | A genuinely credible fit for the native-SSE path specifically; buyers choosing the best-of-breed path (Table 6, 9) should factor in the added operational complexity of managing two separate consoles, which is a real, specific trade-off against the architectural flexibility that path offers.
Summary
Strength | Independently sustained SD-WAN leadership - seven consecutive years as a Gartner Magic Quadrant SD-WAN Leader as of 2024, tracing back to Silver Peak's original, long-standing SD-WAN business | Buyers get a genuinely mature, independently and repeatedly validated SD-WAN engine, not a newer or less-proven entrant to the category | Best: buyers prioritising proven SD-WAN maturity specifically. Less relevant: buyers with no particular weight on this specific analyst recognition | High | A specific, repeated, checkable claim - genuinely one of the strongest sustained-recognition claims found across this profile series for the SD-WAN category specifically.
Buyers get a genuinely mature, independently and repeatedly validated SD-WAN engine, not a newer or less-proven entrant to the category
Summary
Questions Netify still cannot verify | HPE's specific post-acquisition roadmap for rationalising the Aruba/EdgeConnect and Juniper networking portfolios; current FedRAMP status for the SSE/security layer specifically, as distinct from the confirmed Central authorization; PCI-DSS, HIPAA, GDPR, DORA and UK-framework status for the SASE/SSE platform specifically; any pricing figure; and named, formal support-tier SLA structure. | Synthesis of Tables 1, 7, 8, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct HPE or reseller-partner briefing) before this profile is considered fully closed out - the Juniper-integration roadmap question specifically should be treated as a priority item given the scale and currency of that acquisition.
This list should drive the next follow-up (a direct HPE or reseller-partner briefing) before this profile is considered fully closed out - the Juniper-integration roadmap question specifically should be treated as a priority item given the scale and currency of that acquisition.
Summary
SSE deployment to remote users | Client-based ZTNA rollout to remote/mobile users, provisioned via confirmed SSO integration (Okta specifically) | IdP integration (Okta confirmed) a documented prerequisite for SSO-based provisioning | End-user self-install typical for this category | Not itemised | Not quantified with a specific duration | Not itemised | Not detailed | The IdP integration evidence (via Okta's own page) is genuinely current and independently confirmed, though a named, scaled remote-user deployment case study (comparable to some competitors' equivalent evidence) wasn't found in this pass specifically.
Summary
Support/service reality | No confirmed, named, formally published support-tier SLA structure, NOC/SOC service, or direct-from-HPE Professional Services pricing was found in this research pass - real implementation support clearly exists in practise via HPE's large reseller/partner ecosystem, but wasn't formalised into a named, priced HPE-direct service in the sources reviewed. | Table 8, 16 | Low-Medium | Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.
Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.
Summary
Commercial reality | No pricing exists for the SSE platform in any source found in this research pass, including a dedicated third-party aggregator that explicitly confirmed the absence - a genuinely opaque commercial picture consistent with the standard pattern across this vendor category. | Table 16 | Medium (confident about the absence found in this specific research pass) | Route any budget conversation to a direct HPE or reseller-partner quote from the very first interaction - Netify currently has no benchmark figure of any kind to offer a buyer for this vendor's SSE platform specifically.
Route any budget conversation to a direct HPE or reseller-partner quote from the very first interaction - Netify currently has no benchmark figure of any kind to offer a buyer for this vendor's SSE platform specifically.
Summary
Biggest operational advantage | Specific, quantified, named customer outcomes at genuine scale - Henkel's 90% reduction in network issue diagnosis/resolution time across 450 locations is among the most concretely evidenced operational-efficiency claims found across this entire profile series. | Table 9, 17, 18 | High | Directly quotable with the specific named-customer figure for credibility.
Directly quotable with the specific named-customer figure for credibility.
Summary
When would Netify recommend looking elsewhere? (mandatory) | When a buyer wants a platform built natively as one SASE product from a single, focused company rather than assembled through multiple acquisitions under a much larger parent mid-integration on its own $14B acquisition; when a buyer needs published, self-service pricing to shortlist without an extended sales engagement; or when a buyer needs SSE-platform-specific FedRAMP authorization confirmed rather than only the Central network-management platform's authorization. | Synthesis of Tables 1, 13, 16, 19 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Summary
Highly distributed branch estate | Strong fit, extensively evidenced | Henkel's 450-location deployment is a specific, quantified, named proof point directly matching this buyer profile, reinforced by confirmed zero-touch provisioning and specific small-branch hardware options | Zero-touch provisioning well-evidenced via confirmed mechanism and named customer scale | Site-based/per-appliance licensing implications not fully itemised | Table 4, 9, 14 findings | Genuinely one of the stronger, most specifically-evidenced suitability findings in this profile - a real, named, large-scale, quantified customer example combined with a concrete small-branch hardware option.
Summary
Cloud-first organisation | Strong fit, evidenced | Confirmed multi-cloud deployment across three named hyperscalers (AWS, Azure, Google Cloud) plus Megaport Virtual Edge for cloud interconnection, evidenced with genuine technical specificity | None significant identified | Not assessed | Table 3, 4, 7, 12 findings | Genuinely well-evidenced with specific, named hyperscaler and cloud-interconnect platform detail - stronger evidence than the generic 'multi-cloud support' claim found for some competitors.
Summary
Biggest operational concern | The ongoing, large-scale HPE-Juniper integration creates genuine, current, well-documented organisational and roadmap uncertainty - a buyer making a long-term platform commitment is effectively also betting on how smoothly a $14 billion, contested, DOJ-settlement-encumbered acquisition gets digested over the coming years. | Table 1, 19 | Medium-High | Netify should proactively flag this specific, current organisational risk to buyers during the shortlist conversation rather than let it surface as a surprise later.
Netify should proactively flag this specific, current organisational risk to buyers during the shortlist conversation rather than let it surface as a surprise later.
Summary
Where does it stand out? (mandatory) | A genuine, working, best-of-breed architecture supporting both HPE-native SSE and confirmed integration with multiple named third-party security vendors; independently sustained SD-WAN category leadership; a specific, dated, first-of-its-kind full-platform FedRAMP authorization for Central; and specific, quantified, named customer outcomes at genuine scale (Henkel's 90% efficiency gain across 450 locations, IMMI's 99%+ uptime). | Tables 6, 12, 13, 18, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, and - for the Zscaler integration and case-study evidence specifically - independently corroborated sources.
These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, and - for the Zscaler integration and case-study evidence specifically - independently corroborated sources.
Summary
Reporting reality | Strong specifically for network health, site/circuit performance, and digital experience monitoring - all reinforced by the specific, quantified Henkel outcome and the confirmed, named DEM capability; weaker or unconfirmed on security-event reporting, compliance reporting, and executive dashboards, none of which were confirmed as distinct, named products in this research pass. | Table 10 | Medium-High | Present the network-health and DEM strengths specifically rather than imply comprehensive security/compliance-reporting maturity across the board.
Present the network-health and DEM strengths specifically rather than imply comprehensive security/compliance-reporting maturity across the board.
Summary
AI reality | Real, specific, technically-detailed AI/ML investment exists for a narrowly-scoped but genuinely credible use case (adaptive DDoS defence, automatically adjusting thresholds in real time using machine learning), reinforced by a general 'AI-native console' claim; a distinctly-named AI assistant/copilot product for broader platform administration, comparable to some competitors' named equivalents, was not independently confirmed. | Table 11 | Medium | Represent the confirmed, specific DDoS-defence ML capability with genuine confidence, while being clear that a broader, named AI-copilot product for general administration wasn't independently confirmed in this pass.
Represent the confirmed, specific DDoS-defence ML capability with genuine confidence, while being clear that a broader, named AI-copilot product for general administration wasn't independently confirmed in this pass.
Summary
Multi-vendor SASE integration | Genuinely and distinctively well-suited to this exact scenario by design - the confirmed, named, automated integration architecture spans multiple third-party SSE vendors (Zscaler most deeply, alongside Cheque Point, Forcepoint, Netskope, Palo Alto Networks, Symantec, and Infoblox for secure DNS), with Cushman & Wakefield providing a real, named, working example of the pattern | Existing security/identity tools already in place (Zscaler specifically confirmed with the deepest evidence) | Not itemised | Confirmed automated orchestration architecture, joint solution documentation (Zscaler specifically) | Not quantified | N/A | N/A | Arguably one of the best-suited platforms across this entire profile series for this exact scenario - the combination of a broad, named partner list and a specific, real, working customer example (Cushman & Wakefield) makes this a genuinely credible, well-evidenced strength rather than a theoretical architectural claim.
Summary
Questions to ask before recommending it | 1) What is HPE's specific roadmap for rationalising or converging the Aruba/EdgeConnect and Juniper networking portfolios following the July 2025 acquisition? 2) Does the SSE/security layer specifically carry a current, equivalent FedRAMP authorization to the confirmed Central platform authorization? 3) For a buyer choosing the best-of-breed path with a specific named SSE vendor (e.g. Cheque Point, Netskope, Palo Alto Networks - vendors named alongside Zscaler but with less individually-documented depth), what does the actual cross-console operational experience look like day to day? 4) What is a realistic per-user or per-site cost estimate at our expected scale, given no public figure was found? | Synthesis of Tables 1, 6, 12, 13, 16 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering HPE Aruba Networking.
A direct, reusable question set for Netify's advisory conversations with buyers considering HPE Aruba Networking.
Summary
SME | Conditional fit | A specific, named small-branch hardware model (EC-10106) confirms product-line accessibility for smaller sites, though no SME-specific pricing tier or simplified product line was confirmed | Minimal internal skills needed given confirmed zero-touch provisioning | No confirmed entry-level pricing tier | The small-branch hardware option is a genuine, specific, positive signal, though without a confirmed SME-specific commercial packaging to match it.
Summary
Mature NetOps/SecOps team | Strong fit, especially for teams with an existing Zscaler investment | The exceptionally well-documented, three-angle-confirmed Zscaler integration (joint solution brief, named customer, independent third-party corroboration) makes this platform a genuinely credible SD-WAN pairing for teams already standardised on Zscaler for security specifically | Mature teams benefit from familiarity with the confirmed best-of-breed integration model | Not assessed | Genuinely one of this profile's clearest, most specifically-evidenced strengths for this exact buyer profile - a real, working, named example of the best-of-breed pattern this platform is built to support.
Summary
Global fit | Confirmed multi-cloud deployment across three named hyperscalers plus Megaport Virtual Edge, and named customer evidence spanning the US, UK, Canada, and global professional-services/manufacturing operations, together demonstrate real multinational capability - though a formal, published, country-by-country network-coverage map (comparable to some competitors' equivalent evidence) wasn't found for the SSE platform specifically beyond the confirmed 500+-edge-location figure. | Table 7, 14 | Medium-High for evidenced customer scale and the confirmed 500+ edge-location count; Low for a detailed, country-level coverage map specifically | Always verify buyer-specific country/region delivery capability directly with HPE rather than relying on the general customer-scale evidence or the headline edge-location count alone.
Always verify buyer-specific country/region delivery capability directly with HPE rather than relying on the general customer-scale evidence or the headline edge-location count alone.
Summary
Global branch rollout | Evidenced with genuine specificity via Henkel's confirmed 450-location deployment, achieving a specific, quantified 90% reduction in issue diagnosis/resolution time | Existing branch network/WAN infrastructure to integrate or replace | Not itemised at the full 450-location scale specifically beyond the outcome itself | Not itemised | Not quantified beyond the confirmed 90% efficiency figure | Not itemised | Not detailed | Genuinely one of the strongest, most specifically quantified global-rollout claims found across this profile series - a real, named, large-scale customer with a precise, credible efficiency metric.
Summary
Sector fit | Professional services (via the genuinely strategic Cushman & Wakefield best-of-breed case study), manufacturing (via IMMI's specific 99%+ uptime metric and Henkel's 90% efficiency gain), government/public sector (via the confirmed, dated FedRAMP authorization), healthcare, and education are all credibly evidenced with named or quantified references; retail, transport/logistics, and energy/utilities all lack case-study evidence in this research pass. | Table 14 | Medium-High for the evidenced sectors; Low for the others | The Cushman & Wakefield case specifically is worth highlighting for any buyer evaluating the best-of-breed architecture pattern, regardless of their own sector.
The Cushman & Wakefield case specifically is worth highlighting for any buyer evaluating the best-of-breed architecture pattern, regardless of their own sector.
Summary
Where does it fall behind competitors? (mandatory) | HPE's ongoing, large-scale ($14B) Juniper Networks integration creates genuine, current roadmap and organisational-stability uncertainty; SSE-platform-specific FedRAMP status wasn't independently confirmed as distinct from the well-evidenced Central authorization; no pricing was published for the SSE platform in any source found; and several common compliance certifications beyond the confirmed corporate-level ISO 27001/SOC 2 (PCI-DSS, HIPAA, GDPR, DORA) weren't separately confirmed for the SASE/SSE platform specifically. | Tables 1, 7, 13, 16, 19 | Medium-High | Named specifically and evidenced, not a generic hedge - the Juniper-integration uncertainty specifically should be raised proactively with any buyer making a long-term platform commitment.
Named specifically and evidenced, not a generic hedge - the Juniper-integration uncertainty specifically should be raised proactively with any buyer making a long-term platform commitment.
Summary
Global multinational | Good fit, evidenced | Cushman & Wakefield's confirmed 'global network performance' framing and Henkel's 450-location scale both demonstrate genuine multinational deployment capability | Needs Netify/buyer to verify specific-country coverage directly, given the partial Table 7 coverage-map gap | Custom enterprise pricing | Table 7, 14, 18 findings | Real, credible multinational evidence via two independently named large customers, though the underlying global infrastructure coverage map itself remains partially confirmed (Table 7).
Summary
Deployment reality | Genuinely well-evidenced as fast and low-friction, backed by confirmed zero-touch provisioning and multiple specific, named, quantified large-scale customer outcomes (Henkel, IMMI) - among the stronger deployment-evidence pictures found across this profile series. | Table 9, 17, 18 | High | Present this deployment-speed evidence with genuine confidence, backed by specific, named, quantified outcomes rather than generic marketing claims.
Present this deployment-speed evidence with genuine confidence, backed by specific, named, quantified outcomes rather than generic marketing claims.
Summary
Strength | A genuine, working, best-of-breed architecture - confirmed automated integration with multiple named third-party SSE vendors (Zscaler most deeply documented), evidenced by a real, named customer (Cushman & Wakefield) rather than just a theoretical capability claim | Buyers with an existing, separate SSE investment can pair it with EdgeConnect for SD-WAN specifically, rather than being forced into a full single-vendor platform switch | Best: buyers with an established third-party SSE vendor relationship, particularly Zscaler specifically. Less relevant: buyers wanting one fully unified, single-vendor platform from the outset | High | Genuinely one of this platform's clearest, most concretely evidenced differentiators - a real, working, multiply-corroborated example rather than an inferred capability.
Buyers with an existing, separate SSE investment can pair it with EdgeConnect for SD-WAN specifically, rather than being forced into a full single-vendor platform switch
Summary
Co-managed transition | Not confirmed as a distinct named service or evidenced via a case study in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap, consistent with the Table 6/9 finding that no formal co-managed/MSP delivery model was confirmed for this specific product line.
Summary
Commercials | No specific negative commercial signal was found in this research pass beyond the standard industry pattern of unpublished pricing. | No pricing has been published for HPE Aruba Networking SSE in any source found in this research pass, consistent with the pattern found across most vendors in this category - budget conversations should be routed to a direct quote from the outset.
Summary
When would Netify recommend it? (mandatory) | When a buyer wants a genuinely proven, independently-recognised SD-WAN engine specifically; when a buyer already has an established third-party SSE vendor (particularly Zscaler) and wants best-of-breed SD-WAN pairing rather than a full platform switch; or when a buyer is a US federal/public-sector entity needing FedRAMP-authorized network management specifically. | Synthesis of Tables 1, 6, 12, 13 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
Summary
Regulated organisation | Conditional fit, strongest for US federal specifically via Central | FedRAMP Authorization for Central specifically is confirmed, dated, and described as a first-of-its-kind full-platform achievement; broader compliance (ISO 27001, SOC 1/2) is confirmed at the parent-company level with a specific, quantified scope (90+ sites, 40 countries); PCI-DSS, HIPAA, GDPR, DORA and UK-framework status for the SASE/SSE platform specifically were not separately confirmed | Buyer must independently verify sector-specific compliance status directly with HPE for anything outside the confirmed Central/corporate scope | Not assessed | Table 13 findings | A genuinely strong overall compliance foundation at the corporate and Central-platform level, tempered by the specific, worth-flagging gap that SASE/SSE-platform-specific certifications beyond Central weren't separately confirmed - worth closing directly before a high-stakes regulated-sector recommendation.
Summary
Firewall consolidation | Evidenced via the confirmed embedded NGFW/IDS/IPS capability directly on the EdgeConnect appliance, explicitly marketed as enabling 'organizations to seamlessly consolidate their branch equipment by replacing branch firewalls and routers' | Existing branch firewall/router hardware retired | IT/network team | Not itemised | Not quantified with a specific timeline | Hardware/policy transition complexity during cutover (not specifically addressed in sources reviewed) | Not detailed | A specific, direct, primary-sourced claim about branch-hardware consolidation - genuinely credible, concrete evidence for this exact scenario.
Summary
Security & Analytics | The SSE platform confirms a specific, concrete global footprint - over 500 global edge locations across a multi-cloud backbone spanning AWS, Azure and Google Cloud - and a built-in NGFW with IDS/IPS and machine-learning-based adaptive DDoS defence sits directly on the SD-WAN appliance itself. | HPE now owns both this platform and Juniper Networks' separate, competing SASE-relevant product line following the July 2025 acquisition - buyers should ask directly how HPE plans to rationalise or converge these overlapping portfolios over time, since roadmap uncertainty during a major post-merger integration is a real, practical risk.
Summary
Large enterprise | Strong fit, extensively evidenced | Henkel's 450-location deployment, with a specific, quantified 90% reduction in issue diagnosis/resolution time, is genuinely strong, concrete evidence for this exact buyer profile | Requires internal or partner-supported operational ownership at scale | Custom enterprise pricing | Well evidenced via a specific, large-scale, quantified named customer outcome - genuinely strong evidence quality for this buyer profile.
Public evidence sources
37 records- 01HPE - Buy HPE Aruba Networking EdgeConnect product listing (hardware models, e.g. EC-10106 gateway) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 02HPE - EdgeConnect SD-WAN page (7-time Gartner Magic Quadrant Leader claim, Universal Health Services case reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 03HPE - HPE Aruba Networking Central for Government Data Sheet (FedRAMP authorized) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 04HPE - HPE Aruba Networking EdgeConnect SD-WAN product page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 05HPE - HPE Aruba Networking and Zscaler joint solution brief · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 06HPE - HPE Aruba Networking unified SASE product page (named customer references: Bethesda, Henkel, Hato Hone St John, First Bank) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 07HPE - HPE Digital Trust Centre: Accountability and Oversight (ISO 27001, SOC 1/2, TISAX, FedRAMP, CSA STAR) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 08HPE - What is FedRAMP? (HPE Aruba Networking Central, first networking vendor with full-platform FedRAMP authorization) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 09HPE - press release: HPE and Juniper Networks reach settlement with U.S. Department of Justice · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 10HPE Aruba Networking - Customer Stories index page (Cushman & Wakefield/Zscaler, IMMI, Edmonton Public Library, hotel and university references) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 11HPE Aruba Networking Documentation - Central Cloud Architecture (SSAE 18 SOC 2, PCI, FedRAMP, ISO 27001:2022 certified data centres) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 12HPE Investor Relations - HPE Closes Juniper Networks Acquisition (earnings call transcript) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 13HPE Networking - EdgeConnect product page (Megaport Virtual Edge deployment, AWS/Azure/Google Cloud deployment options) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 14Hewlett Packard Enterprise Co - SEC Form 10-Q, FY2025 (Note 8: Acquisitions and Dispositions, Juniper Networks merger terms) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 15Business Wire (via wire-distribution mirror) - Aruba Central Attains Formal Authorized Designation from FedRAMP · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 16Cabling Installation & Maintenance - HPE acquires SD-WAN specialist Silver Peak (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 17Gartner Peer Insights - HPE Aruba Networking Unified SASE with HPE EdgeConnect SD-WAN Reviews & Ratings · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 18GovCon Wire - HPE Closes Juniper Purchase (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 19Nasdaq (wire distribution of HPE's own release) - HPE Completes Acquisition of SD-WAN Leader Silver Peak · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 20Network World - Timeline of HPE's $14 billion Juniper acquisition (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 21Nomios Group - HPE completes acquisition of Juniper Networks (independent partner/reseller commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 22Okta - Integrate HPE Aruba Networking SSE (formerly Axis) with Okta (Okta's own integration catalogue page) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 23RCR Wireless News - HPE closes on $14 billion Juniper acquisition (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 24Advizex (HPE reseller) - HPE Aruba EdgeConnect: A Technical Deep Dive (7x Gartner Leader claim, Gartner Peer Insights rating) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 25CXO DX - HPE completes acquisition of Silver Peak (independent regional trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 26Cavell - The Ins and Outs of HPE-Aruba's Silver Peak Acquisition (independent industry analysis) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 27Consiliant Technologies (HPE reseller) - USANA HPE Aruba Networking SASE Case Study · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 28FinancialContent - The Networking Renaissance: A Deep Dive into Hewlett Packard Enterprise (independent financial analysis) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 29Futurum Group - HPE Acquires Silver Peak to Expand its SD-WAN Offering (independent analyst commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 30Futurum Group - HPE Closes Juniper Acquisition, Combining AI-Native Networking Portfolios (independent analyst commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 31G2 - HPE Aruba Networking SSE Pricing Overview (third-party review aggregator; no pricing plan found) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 32G2 - Top 10 HPE Aruba Networking SSE Alternatives & Competitors in 2026 (third-party review aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 33HPE Taiwan - HPE Aruba Networking EdgeConnect SD-WAN product catalogue page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 34Medium (independent technical blog) - HPE Aruba Networking Edge Connect SD-WAN (technical deep-dive, ClearPass/IoT detail) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 35Netify - HPE Aruba SD WAN & SASE Cybersecurity solutions marketplace page (named security-partner integration list, First-Packet iQ, Cloud Intelligence) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 36Netify - Zscaler: Zero Trust Exchange SASE Platform marketplace page (independent corroboration of the Zscaler/HPE Aruba EdgeConnect integration from Zscaler's side) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 37SecureWirelessWorks.com (HPE reseller) - HPE Aruba Networking EdgeConnect SD-WAN overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
Profile contract provider-public/1.0.0. Machine-readable record: JSON.