Executive Summary
The SD-WAN decision is really a SASE decision: choose whether networking and security become one policy — or stay two problems you operate forever.
Cisco, Fortinet, Palo Alto Prisma SD-WAN, and cloud-native pure-plays like Cato anchor a market where SD-WAN has largely dissolved into SASE — and where ownership has churned hard, with the original leader, VeloCloud, passing from VMware to Broadcom to Arista. The question is no longer how to steer traffic across links; it's whether networking and security converge into one cloud-delivered policy, or stay two products you integrate and operate separately.
This guide provides a vendor-neutral evaluation framework for 7 leading platforms, weighing SASE convergence, points-of-presence reach, and operating model so you can choose for your real branch, cloud, and remote-work footprint rather than a throughput spec sheet.
Why Cloud Networking & SD-WAN Matters for Enterprise Strategy
WAN decisions are sticky and operationally heavy, so they should turn on the operating model as much as the technology: whether security and networking share one policy and console, how the vendor's global points of presence map to where your users and clouds actually sit, and whether your team can run it without a specialist for every change.
The market is consolidating networking and security into single-vendor SASE, while a best-of-breed camp argues the strongest firewall and the strongest SD-WAN rarely come from the same company. Decide where you sit on that trade-off — integration simplicity versus depth at each layer — before you shortlist.
Architecture & Sourcing Decision
Nobody builds their own SD-WAN, so this is not a build-vs-buy question — it is an architecture-and-sourcing one. The decisions that actually shape the next five years are whether you converge networking and security on a single-vendor SASE platform or run best-of-breed SSE and SD-WAN from different vendors; whether enforcement lives in a cloud-native provider’s points of presence or in appliances at the branch; and how you sequence the rollout against MPLS contracts you can’t exit overnight. Frame the choice around your operating model and where your users and clouds actually sit, not a throughput spec.
| Your Situation | Recommended Path | Rationale |
|---|---|---|
| Lean network & security team wanting one policy and console | Single-vendor SASE | One policy model, one data pipeline, and fewer integration seams cut day-2 toil and human error — the decisive advantage when you don’t have separate teams to babysit two stacks. Verify the seam between SD-WAN and SSE is genuinely unified, not two acquired consoles. |
| Deep existing firewall / SSE investment you won’t rip out | Best-of-breed SSE + SD-WAN | The strongest firewall and the strongest SD-WAN rarely come from one vendor. If your security stack is already a standard, keep it and pick an SD-WAN that integrates cleanly — integration quality between the layers matters more than a shared logo. |
| Remote-work / VPN pain is the burning problem, branches can wait | SSE-first, SD-WAN later | Buy SSE and let ZTNA retire the VPN now; converge SD-WAN when MPLS contracts lapse. Lets the security team move on its own budget and timeline without re-architecting the whole WAN up front. |
| Many internet-breakout branches, latency-sensitive SaaS & voice | Cloud-native SASE on a private backbone | When inspection happens in a nearby PoP on a managed backbone rather than on a branch box, you get more deterministic paths to SaaS and cloud. Validate real latency from your actual site geography — the PoP is the enforcement point, and there is usually no local-breakout fallback. |
| Data-residency or sovereignty mandates (public sector, regulated) | In-country PoPs or sovereign / on-prem SASE | Pure shared-cloud backbones can conflict with in-country egress and residency rules. Confirm a suitable PoP exists per region, or choose a stack that runs the security plane on-prem or in a sovereign cloud. |
Key Capabilities & Evaluation Criteria
Weight these domains against your own footprint and operating model. For most enterprises the security-convergence and points-of-presence questions now outrank the raw path-selection features that older SD-WAN RFPs over-index on — because the operational reality you live in is full inspection turned on, branches breaking out locally, and a remote workforce that never comes back to the office.
| Capability Domain | Weight | What to Evaluate |
|---|---|---|
| SASE / Security Convergence | 25% | Native SWG, CASB, FWaaS, and DLP in the same fabric as SD-WAN; a single policy model and data pipeline across network and security; whether SD-WAN and SSE are genuinely unified or two acquired consoles; and how far advertised throughput drops with TLS decryption, IPS, and DLP all enabled |
| Path Selection & WAN Performance | 20% | Application-aware steering and per-packet/per-session path selection across MPLS, broadband, and LTE/5G; sub-second failover and forward error correction for voice and video; loss/latency/jitter remediation (WAN optimization heritage); and granular segmentation for IoT, guest, and regulated traffic |
| Points of Presence & Backbone | 20% | PoP density near your actual sites and clouds, and whether enforcement rides a private backbone or the public internet; cloud and SaaS on-ramps and in-country egress for residency; PoP failover behavior (there is usually no local-breakout fallback); and real measured latency from your geography, not the marketing map |
| Zero Trust & Remote Access | 15% | ZTNA that can actually retire the VPN (clientless and agent-based, per-app least privilege, identity and device-posture context); consistent policy for branch, remote, and unmanaged devices; and secure access to private apps across multicloud without backhauling |
| Operations, Automation & AIOps | 10% | Zero-touch provisioning at branch scale, true single-pane administration, and full API/IaC (Terraform) coverage for security policy, not just GUI; digital-experience monitoring (DEM/DEX) and AIOps for root-cause; and brownfield coexistence tooling and unified visibility during hybrid MPLS run |
| Commercials & Operating Model | 10% | Per-site vs. per-user vs. consumption fit for your estate; module bundling (which SSE features are extra); deployment flexibility (cloud-native, appliance, virtual, or sovereign/air-gapped); managed-service vs. DIY support depth; and renewal and unwind terms for each layer |
Vendor Landscape
The market sorts into three camps that most shortlists end up comparing across, not within. Security-led incumbents (Fortinet, Palo Alto) start from a firewall and converge SD-WAN into it, betting that security depth wins. Networking incumbents (Cisco, HPE Aruba, and now Arista with VeloCloud) start from routing and the installed base, offering breadth and choice but stitching the security half together. And cloud-native SASE (Cato, with Versa as the flexible-deployment variant) builds networking and security as one service on its own backbone. A recurring trap: “single-vendor” rarely means “single-pane” — most large platforms were assembled by acquisition, so the seam between SD-WAN and SSE is exactly where integration gaps show.
Ownership has churned hard in this category, and it matters: VeloCloud, the original SD-WAN leader, passed from VMware to Broadcom and is now an Arista Networks business — but the security half stayed behind with Broadcom’s Symantec, so Arista holds mature SD-WAN without a native SASE security stack. HPE folded in Silver Peak (EdgeConnect) and Axis Security, then absorbed Juniper, inheriting a second SD-WAN line. Read each vendor’s roadmap with its M&A history in hand.
Strengths: Two distinct, mature SD-WAN lines: engineer-grade Catalyst SD-WAN (the former Viptela, now on IOS XE with Catalyst SD-WAN Manager) for deep routing, policy, and segmentation, and cloud-managed Meraki MX for branch simplicity. Cisco Secure Access (Umbrella lineage) supplies the SSE half, and ThousandEyes plus Splunk give an assurance and observability stack few rivals match end to end. Considerations: The portfolio’s breadth is also its tax: two separate SD-WAN stacks plus several security SKUs (Secure Access, Umbrella, Secure Connect) create licensing confusion and migration friction, and Catalyst SD-WAN and Secure Access still run on different consoles rather than one converged pane.
Strengths: SD-WAN is delivered natively inside the FortiGate firewall on Fortinet’s own custom ASICs (SPUs), so security and path selection run on one box under one policy engine, hardware-accelerating IPsec and SSL inspection instead of paying the CPU tax that hobbles software-only SD-WAN. A single OS (FortiOS) spans branch, data center, and the cloud-delivered FortiSASE. Considerations: The deepest value is realized inside the Fortinet ecosystem (FortiGate hardware, FortiOS, FortiManager), which means real lock-in and an appliance-centric model that fits hardware-agnostic or best-of-breed buyers less well.
Strengths: An app-defined, autonomous SD-WAN fabric (from the CloudGenix acquisition, using ION edge devices) that learns application behavior and self-heals, paired with best-in-class threat prevention inherited from Palo Alto’s NGFW lineage. As part of Prisma SASE it shares the Prisma Access SSE stack and ADEM for autonomous digital-experience monitoring. Considerations: Premium pricing and licensing overhead; the full value generally assumes committing to the broader Palo Alto ecosystem rather than a mixed best-of-breed estate, and SD-WAN and SSE are stitched through Strata Cloud Manager rather than born as one product.
Strengths: EdgeConnect (the former Silver Peak) brings mature, proven WAN optimization and high-quality path conditioning for loss-prone links, now inside HPE’s broad edge-to-cloud portfolio, with EdgeConnect SSE (from the Axis Security acquisition) supplying the security half of a single-vendor SASE story. Considerations: The converged SASE offering is still maturing relative to the pure-play leaders, and the closed Juniper acquisition adds a second SD-WAN line (Session Smart Router) alongside EdgeConnect — near-term roadmap overlap that buyers should get clarity on before committing.
Strengths: A single converged software stack (the Versa Operating System) runs SD-WAN, SSE, and SD-LAN, and the same VOS deploys on appliances, white-box, virtual machines, public cloud, or fully air-gapped infrastructure. Its run-it-yourself Sovereign SASE is genuinely differentiated for governments, regulated industries, and service providers that cannot use a shared public cloud. Considerations: That configurability makes VOS more operationally complex and less turnkey than a pure cloud-delivered service, typically assuming deeper in-house networking expertise or an MSP; as a still-private, IPO-pending company it also carries some financing and exit uncertainty.
Strengths: A born-in-the-cloud, single-pass converged architecture on Cato’s own global private backbone of points of presence: networking and security converge inside the cloud rather than being stitched from acquisitions, giving one consistent policy, an SLA-backed optimized backbone, and the simplest managed operating model in the category. SD-WAN is delivered as part of the service via the Cato Socket edge. Considerations: As a cloud-only single-vendor pure-play you commit to Cato’s architecture and PoP footprint, with little appliance or on-prem customization and no self-hosted or air-gapped sovereign option — a real constraint for strict data-residency or heavy on-prem-inspection needs.
Strengths: One of the most widely deployed, battle-tested SD-WAN technologies, with strong Dynamic Multipath Optimization and a large installed base, now under a financially strong, networking-focused owner in Arista and on a path toward integration with Arista’s EOS and CloudVision fabric for an end-to-end campus, data-center, and WAN story. Considerations: Fresh ownership change — the second in roughly eighteen months — and, critically, the SASE security stack did not come with the deal (it stayed with Broadcom’s Symantec), so how Arista adds modern SASE security to VeloCloud’s SD-WAN is an open, unproven roadmap. Existing customers should press for clarity.
Pricing Models & Cost Structure
SD-WAN and SASE pricing is a stacked model, and the stack is the trap: an SD-WAN line (per-site or per-edge, often with branch-hardware capex plus subscription) sits under a security line (predominantly per-user for the SSE layer), with bandwidth or PoP-egress elements on top. The unit of measure, more than any headline rate, determines what you pay as you grow — and the largest cost, the broadband and cellular underlay itself, is usually a separate spend the license never shows. List prices are rarely published; every deal is negotiated on size, competition, and incumbency, so model against your own site count, user count, and retention of legacy circuits.
| Vendor | Pricing Model | Relative Tier | Key Cost Drivers |
|---|---|---|---|
| Cisco (Catalyst / Meraki) | Per-device + subscription tiers (DNA / Meraki licensing) | Moderate–Premium | Edge appliance class and count, license tier (Essentials vs. Advantage), separate Secure Access / Umbrella SSE seats, ThousandEyes and support |
| Fortinet Secure SD-WAN | FortiGate appliance + FortiGuard subscription bundles; FortiSASE per-user | Lower–Moderate | FortiGate model per site, security-service bundle, FortiSASE user count, FortiManager/FortiAnalyzer, support level |
| Palo Alto Prisma SD-WAN | Per-ION-edge subscription, part of Prisma SASE; SSE per-user | Premium | ION edge count and capacity, Prisma Access user tier, ADEM and advanced security modules, professional services |
| HPE Aruba EdgeConnect | Per-edge subscription (EC-S/M/L tiers) + EdgeConnect SSE per-user | Moderate | EdgeConnect appliance tier and bandwidth, Boost WAN-optimization add-on, SSE seats, support and managed options |
| Versa Networks | Flexible: per-site, per-user, or capacity; on-prem, cloud, or sovereign | Moderate | Deployment model (managed vs. self-hosted vs. sovereign), site and user counts, software tier, professional services depth |
| Cato Networks | Subscription bundle: per-site (Socket) + per-user for the security stack | Moderate | Site/Socket count and bandwidth, ZTNA user count, optional security modules, the included global backbone |
| Arista VeloCloud | Per-edge subscription (Standard/Enterprise/Premium editions) | Moderate | Edge count and throughput edition, gateway/orchestrator hosting, and third-party security if added (no native SSE in the deal) |
Implementation & Migration
Sequence a WAN transformation by risk and underlay reality, not by contract expiry dates. The hard part is rarely the technology — it is the shift from device-centric to policy-centric operations, the carrier lead times for new circuits, and the long stretch where SD-WAN runs in parallel with the MPLS you cannot exit yet. A national estate of a couple hundred sites is commonly a twelve-to-eighteen-month effort; plan the brownfield coexistence up front so you do not discover asymmetric paths and DNS surprises mid-rollout.
Discover and segment applications, map each site’s underlay options (fiber, broadband, LTE/5G), and establish a performance baseline tied to business outcomes, not just uptime. Settle the architecture question — single-vendor SASE vs. best-of-breed — and run the POC with full security inspection enabled. Order new circuits early; carrier lead time is usually the critical path.
Deploy a small set of representative sites — including a deliberately worst-connected one — to surface routing, DNS, and firewall-policy surprises while the blast radius is small. Stand up orchestration, zero-touch provisioning, identity integration, and the unified policy model, and codify branch configuration as templates and IaC before scaling.
Migrate branches in regional waves, running hybrid MPLS and SD-WAN side by side with deliberate traffic-steering and fallback so a bad cutover is recoverable. Maintain unified visibility across both fabrics, and validate each site against the baseline before declaring it done.
Layer and unify the SSE controls (SWG, CASB, FWaaS, and ZTNA to retire the VPN), tune TLS-decrypt exceptions and inspection performance, then decommission MPLS site by site as each validates. Settle into day-2 operations with DEM/DEX monitoring and a regular review of cost and policy drift.
Selection Checklist & RFP Questions
Use this checklist during evaluation to ensure each shortlisted platform covers what actually decides an SD-WAN/SASE outcome — the operating reality, not the demo.