Cloudflare and Aruba join forces on SD-WAN-to-cloud security

Cloudflare has announced a collaboration with Aruba to integrate Aruba’s EdgeConnect SD-WAN platform with Cloudflare One. The goal is to let organizations using Aruba’s appliances send selected traffic through Cloudflare’s global anycast network for additional security services without replacing their existing WAN edge gear.

The integrated solution is aimed at two main traffic patterns. First, Internet-bound traffic from branch offices can be steered through Cloudflare’s Secure Web Gateway and Magic Firewall. Second, east/west traffic between branch locations can be inspected and filtered with Magic Firewall policies. In both cases, network administrators continue to manage inter-branch and Internet-bound traffic policies from the Aruba EdgeConnect Orchestrator.

How the integration works

The technical foundation is straightforward: EdgeConnect appliances at each branch or public cloud location establish Anycast GRE or IPSec tunnels to the nearest Cloudflare data center. Network administrators then use Aruba’s Business Intent Overlays feature in the Orchestrator to build policies that automatically identify application traffic and decide where to send it.

BLOG-984 Embedded Image - FXYM4U

Traffic can be directed over the tunnels to Cloudflare for policy enforcement, sent directly to other EdgeConnect appliances at other offices, routed through other service providers, or broken out locally to the Internet. For example, business applications may go through the Cloudflare tunnels while video streaming traffic breaks out directly to the Internet. The overlay matching determines which path each traffic profile takes.

Detailed setup guidance is available in the joint deployment guide. Cloudflare notes that future iterations of the integration are expected to let EdgeConnect devices self-configure using authorization credentials and the Magic WAN management API, rather than requiring manual tunnel configuration.

Cloudflare and Aruba partner to deliver a seamless global secure network from the branch to the cloud

Why SD-WAN matters here

SD-WAN is an evolution of the traditional WAN that reduces the reliance on expensive leased lines and MPLS links. Instead, it can combine private circuits with the public Internet to give administrators more flexibility in managing and scaling the network. Aruba’s EdgeConnect is a WAN edge platform available in both physical and virtual appliance form factors. It creates logical network overlays across the WAN, and the Aruba Orchestrator is used to configure and manage the whole deployment, including branch appliances.

Benefits for existing Aruba customers

The partnership is designed primarily for organizations that already have EdgeConnect SD-WAN deployments. Adding Cloudflare One to that topology means they can apply Zero Trust and network security policies without a rip-and-replace project.

Simplicity: Customers connect to Cloudflare’s edge using SD-WAN appliances they already own and know how to operate. The Cloudflare integration slots into an existing network topology that may already be sending traffic to a variety of destinations, services, and clouds.

Security and control: For traffic that is sent to Cloudflare, policies are managed from a single dashboard that provides policy management, logging, and analytics. Gateway supports DNS, Network, and HTTP(s) policy types. Remote browser isolation is available to protect end-user devices from malware and zero-day threats. Access Applications allow conditional Zero Trust policies for applications that are public, internal, or SaaS-based. Magic WAN and Magic Firewall offer cloud-based network firewall capabilities for both Internet-bound and inter-branch traffic.

Speed and performance: Instead of stitching branch offices together with leased lines or MPLS, each site can use a GRE or IPSec tunnel to reach Cloudflare’s network, which spans 250+ cities in 100+ countries and operates within 95% of the Internet-connected population. The Cloudflare network effectively becomes the WAN backbone for connected branches.