All Buyer Guides
Foundational ITHigh Complexity

Buyer's Guide: Cloud Networking & SD-WAN

Evaluate Cisco, Fortinet, Palo Alto, HPE Aruba, Versa, Cato, and Arista VeloCloud against your real branch, cloud, and remote-work footprint — treating the SD-WAN choice as the SASE decision it has become, not a throughput spec sheet.

15 min read 7 vendors evaluated Typical deal: $200K – $3M+ Updated June 2026
Section 1

Executive Summary

The SD-WAN decision is really a SASE decision: choose whether networking and security become one policy — or stay two problems you operate forever.

Cisco, Fortinet, Palo Alto Prisma SD-WAN, and cloud-native pure-plays like Cato anchor a market where SD-WAN has largely dissolved into SASE — and where ownership has churned hard, with the original leader, VeloCloud, passing from VMware to Broadcom to Arista. The question is no longer how to steer traffic across links; it's whether networking and security converge into one cloud-delivered policy, or stay two products you integrate and operate separately.

This guide provides a vendor-neutral evaluation framework for 7 leading platforms, weighing SASE convergence, points-of-presence reach, and operating model so you can choose for your real branch, cloud, and remote-work footprint rather than a throughput spec sheet.


Section 2

Why Cloud Networking & SD-WAN Matters for Enterprise Strategy

WAN decisions are sticky and operationally heavy, so they should turn on the operating model as much as the technology: whether security and networking share one policy and console, how the vendor's global points of presence map to where your users and clouds actually sit, and whether your team can run it without a specialist for every change.

🎯
Strategic Impact
SD-WAN broke the old model of backhauling every branch to a data-center firewall, but the moment traffic breaks out locally to the internet and cloud, it has to be inspected somewhere — which pulls secure web gateway, CASB, firewall-as-a-service, and ZTNA into the same architecture. That is why the network decision and the security decision have merged into SASE. The real strategic question is no longer how to steer packets across links; it is whether your branch, remote, and cloud traffic is governed by one converged policy or by two stacks you integrate and operate forever — and which vendor’s points of presence sit close enough to your users and clouds to enforce that policy without a latency tax.

The market is consolidating networking and security into single-vendor SASE, while a best-of-breed camp argues the strongest firewall and the strongest SD-WAN rarely come from the same company. Decide where you sit on that trade-off — integration simplicity versus depth at each layer — before you shortlist.


Section 3

Architecture & Sourcing Decision

Nobody builds their own SD-WAN, so this is not a build-vs-buy question — it is an architecture-and-sourcing one. The decisions that actually shape the next five years are whether you converge networking and security on a single-vendor SASE platform or run best-of-breed SSE and SD-WAN from different vendors; whether enforcement lives in a cloud-native provider’s points of presence or in appliances at the branch; and how you sequence the rollout against MPLS contracts you can’t exit overnight. Frame the choice around your operating model and where your users and clouds actually sit, not a throughput spec.

Your Situation Recommended Path Rationale
Lean network & security team wanting one policy and console Single-vendor SASE One policy model, one data pipeline, and fewer integration seams cut day-2 toil and human error — the decisive advantage when you don’t have separate teams to babysit two stacks. Verify the seam between SD-WAN and SSE is genuinely unified, not two acquired consoles.
Deep existing firewall / SSE investment you won’t rip out Best-of-breed SSE + SD-WAN The strongest firewall and the strongest SD-WAN rarely come from one vendor. If your security stack is already a standard, keep it and pick an SD-WAN that integrates cleanly — integration quality between the layers matters more than a shared logo.
Remote-work / VPN pain is the burning problem, branches can wait SSE-first, SD-WAN later Buy SSE and let ZTNA retire the VPN now; converge SD-WAN when MPLS contracts lapse. Lets the security team move on its own budget and timeline without re-architecting the whole WAN up front.
Many internet-breakout branches, latency-sensitive SaaS & voice Cloud-native SASE on a private backbone When inspection happens in a nearby PoP on a managed backbone rather than on a branch box, you get more deterministic paths to SaaS and cloud. Validate real latency from your actual site geography — the PoP is the enforcement point, and there is usually no local-breakout fallback.
Data-residency or sovereignty mandates (public sector, regulated) In-country PoPs or sovereign / on-prem SASE Pure shared-cloud backbones can conflict with in-country egress and residency rules. Confirm a suitable PoP exists per region, or choose a stack that runs the security plane on-prem or in a sovereign cloud.
⚠️
Common Pitfall
The most common SD-WAN mistake is buying on peak appliance throughput and meeting the real costs in operations — per-site licensing, the broadband and cellular underlay that is a separate spend from the license, circuit commitments you carry through hybrid coexistence, and the specialized skills every policy change demands. Advertised throughput also collapses once full security inspection (TLS decrypt, IPS, DLP, CASB) is switched on, which is the state you will actually run in. Model the three-year operating load and the security half of SASE, not the hardware and bandwidth lines.

Section 4

Key Capabilities & Evaluation Criteria

Weight these domains against your own footprint and operating model. For most enterprises the security-convergence and points-of-presence questions now outrank the raw path-selection features that older SD-WAN RFPs over-index on — because the operational reality you live in is full inspection turned on, branches breaking out locally, and a remote workforce that never comes back to the office.

Capability Domain Weight What to Evaluate
SASE / Security Convergence 25% Native SWG, CASB, FWaaS, and DLP in the same fabric as SD-WAN; a single policy model and data pipeline across network and security; whether SD-WAN and SSE are genuinely unified or two acquired consoles; and how far advertised throughput drops with TLS decryption, IPS, and DLP all enabled
Path Selection & WAN Performance 20% Application-aware steering and per-packet/per-session path selection across MPLS, broadband, and LTE/5G; sub-second failover and forward error correction for voice and video; loss/latency/jitter remediation (WAN optimization heritage); and granular segmentation for IoT, guest, and regulated traffic
Points of Presence & Backbone 20% PoP density near your actual sites and clouds, and whether enforcement rides a private backbone or the public internet; cloud and SaaS on-ramps and in-country egress for residency; PoP failover behavior (there is usually no local-breakout fallback); and real measured latency from your geography, not the marketing map
Zero Trust & Remote Access 15% ZTNA that can actually retire the VPN (clientless and agent-based, per-app least privilege, identity and device-posture context); consistent policy for branch, remote, and unmanaged devices; and secure access to private apps across multicloud without backhauling
Operations, Automation & AIOps 10% Zero-touch provisioning at branch scale, true single-pane administration, and full API/IaC (Terraform) coverage for security policy, not just GUI; digital-experience monitoring (DEM/DEX) and AIOps for root-cause; and brownfield coexistence tooling and unified visibility during hybrid MPLS run
Commercials & Operating Model 10% Per-site vs. per-user vs. consumption fit for your estate; module bundling (which SSE features are extra); deployment flexibility (cloud-native, appliance, virtual, or sovereign/air-gapped); managed-service vs. DIY support depth; and renewal and unwind terms for each layer
💡
Evaluation Tip
Run the proof-of-concept in the state you will actually operate in, not the demo state. Turn on TLS decryption, IPS, DLP, and CASB at the same time, route a representative branch through the nearest PoP, and measure real throughput and end-to-end latency to your priority SaaS and clouds from your worst-connected site — then pull a plug and time the failover. The vendor whose numbers hold up with full inspection enabled, not the one with the best spec sheet at zero inspection, leads your shortlist.

Section 5

Vendor Landscape

The market sorts into three camps that most shortlists end up comparing across, not within. Security-led incumbents (Fortinet, Palo Alto) start from a firewall and converge SD-WAN into it, betting that security depth wins. Networking incumbents (Cisco, HPE Aruba, and now Arista with VeloCloud) start from routing and the installed base, offering breadth and choice but stitching the security half together. And cloud-native SASE (Cato, with Versa as the flexible-deployment variant) builds networking and security as one service on its own backbone. A recurring trap: “single-vendor” rarely means “single-pane” — most large platforms were assembled by acquisition, so the seam between SD-WAN and SSE is exactly where integration gaps show.

Ownership has churned hard in this category, and it matters: VeloCloud, the original SD-WAN leader, passed from VMware to Broadcom and is now an Arista Networks business — but the security half stayed behind with Broadcom’s Symantec, so Arista holds mature SD-WAN without a native SASE security stack. HPE folded in Silver Peak (EdgeConnect) and Axis Security, then absorbed Juniper, inheriting a second SD-WAN line. Read each vendor’s roadmap with its M&A history in hand.

Cisco (Catalyst SD-WAN & Meraki) Leader — Breadth & Choice

Strengths: Two distinct, mature SD-WAN lines: engineer-grade Catalyst SD-WAN (the former Viptela, now on IOS XE with Catalyst SD-WAN Manager) for deep routing, policy, and segmentation, and cloud-managed Meraki MX for branch simplicity. Cisco Secure Access (Umbrella lineage) supplies the SSE half, and ThousandEyes plus Splunk give an assurance and observability stack few rivals match end to end. Considerations: The portfolio’s breadth is also its tax: two separate SD-WAN stacks plus several security SKUs (Secure Access, Umbrella, Secure Connect) create licensing confusion and migration friction, and Catalyst SD-WAN and Secure Access still run on different consoles rather than one converged pane.

Best for: Large Cisco-standardized enterprises that want either deep IT-controlled WAN engineering (Catalyst) or cloud-managed branch simplicity (Meraki), with best-in-class network assurance
Fortinet Secure SD-WAN Leader — Converged on ASIC

Strengths: SD-WAN is delivered natively inside the FortiGate firewall on Fortinet’s own custom ASICs (SPUs), so security and path selection run on one box under one policy engine, hardware-accelerating IPsec and SSL inspection instead of paying the CPU tax that hobbles software-only SD-WAN. A single OS (FortiOS) spans branch, data center, and the cloud-delivered FortiSASE. Considerations: The deepest value is realized inside the Fortinet ecosystem (FortiGate hardware, FortiOS, FortiManager), which means real lock-in and an appliance-centric model that fits hardware-agnostic or best-of-breed buyers less well.

Best for: Security-led, branch-heavy organizations that want firewall and SD-WAN converged on one performant box and a single-vendor SASE path, and are comfortable standardizing on Fortinet hardware
Palo Alto Prisma SD-WAN Leader — Security-Led

Strengths: An app-defined, autonomous SD-WAN fabric (from the CloudGenix acquisition, using ION edge devices) that learns application behavior and self-heals, paired with best-in-class threat prevention inherited from Palo Alto’s NGFW lineage. As part of Prisma SASE it shares the Prisma Access SSE stack and ADEM for autonomous digital-experience monitoring. Considerations: Premium pricing and licensing overhead; the full value generally assumes committing to the broader Palo Alto ecosystem rather than a mixed best-of-breed estate, and SD-WAN and SSE are stitched through Strata Cloud Manager rather than born as one product.

Best for: Security-first enterprises — often existing Palo Alto NGFW or Prisma Access customers — wanting consolidated single-vendor SASE and willing to pay for top-tier integrated security
HPE Aruba EdgeConnect Strong — WAN-Optimized

Strengths: EdgeConnect (the former Silver Peak) brings mature, proven WAN optimization and high-quality path conditioning for loss-prone links, now inside HPE’s broad edge-to-cloud portfolio, with EdgeConnect SSE (from the Axis Security acquisition) supplying the security half of a single-vendor SASE story. Considerations: The converged SASE offering is still maturing relative to the pure-play leaders, and the closed Juniper acquisition adds a second SD-WAN line (Session Smart Router) alongside EdgeConnect — near-term roadmap overlap that buyers should get clarity on before committing.

Best for: Existing HPE, Aruba, and now Juniper networking shops that want one edge-to-cloud vendor and strong standalone SD-WAN, and can tolerate a still-converging SASE roadmap
Versa Networks Strong — Sovereign-Ready

Strengths: A single converged software stack (the Versa Operating System) runs SD-WAN, SSE, and SD-LAN, and the same VOS deploys on appliances, white-box, virtual machines, public cloud, or fully air-gapped infrastructure. Its run-it-yourself Sovereign SASE is genuinely differentiated for governments, regulated industries, and service providers that cannot use a shared public cloud. Considerations: That configurability makes VOS more operationally complex and less turnkey than a pure cloud-delivered service, typically assuming deeper in-house networking expertise or an MSP; as a still-private, IPO-pending company it also carries some financing and exit uncertainty.

Best for: Large enterprises, service providers, and government or sovereign buyers wanting one converged stack with maximum deployment control — on-prem, private, cloud, or air-gapped
Cato Networks Leader — Cloud-Native SASE

Strengths: A born-in-the-cloud, single-pass converged architecture on Cato’s own global private backbone of points of presence: networking and security converge inside the cloud rather than being stitched from acquisitions, giving one consistent policy, an SLA-backed optimized backbone, and the simplest managed operating model in the category. SD-WAN is delivered as part of the service via the Cato Socket edge. Considerations: As a cloud-only single-vendor pure-play you commit to Cato’s architecture and PoP footprint, with little appliance or on-prem customization and no self-hosted or air-gapped sovereign option — a real constraint for strict data-residency or heavy on-prem-inspection needs.

Best for: Mid-market and distributed enterprises wanting the simplest path to fully converged, fully managed, cloud-delivered SASE from one vendor, prioritizing operational simplicity over deployment flexibility
Arista VeloCloud Strong — Mature SD-WAN

Strengths: One of the most widely deployed, battle-tested SD-WAN technologies, with strong Dynamic Multipath Optimization and a large installed base, now under a financially strong, networking-focused owner in Arista and on a path toward integration with Arista’s EOS and CloudVision fabric for an end-to-end campus, data-center, and WAN story. Considerations: Fresh ownership change — the second in roughly eighteen months — and, critically, the SASE security stack did not come with the deal (it stayed with Broadcom’s Symantec), so how Arista adds modern SASE security to VeloCloud’s SD-WAN is an open, unproven roadmap. Existing customers should press for clarity.

Best for: Existing VeloCloud installed-base customers and Arista-aligned enterprises (especially data-center and campus shops extending to branch) that value mature SD-WAN and can wait for the converged-security direction to firm up
🔎
Market Insight
The center of gravity has shifted decisively from standalone SD-WAN to single-vendor SASE, and the buying committee now includes the CISO from day one. But the honest nuance is that “single-vendor” and “single-pane” are not the same thing: most of the large platforms were assembled through acquisition, and the integration seam between SD-WAN and the security stack is where the real differences live. Cloud-native architectures that converged the two from the start, and the AIOps and digital-experience layers that protect hybrid-workforce experience, are becoming the dividing lines — ahead of raw throughput, which buyers still over-weight.

Section 6

Pricing Models & Cost Structure

SD-WAN and SASE pricing is a stacked model, and the stack is the trap: an SD-WAN line (per-site or per-edge, often with branch-hardware capex plus subscription) sits under a security line (predominantly per-user for the SSE layer), with bandwidth or PoP-egress elements on top. The unit of measure, more than any headline rate, determines what you pay as you grow — and the largest cost, the broadband and cellular underlay itself, is usually a separate spend the license never shows. List prices are rarely published; every deal is negotiated on size, competition, and incumbency, so model against your own site count, user count, and retention of legacy circuits.

Vendor Pricing Model Relative Tier Key Cost Drivers
Cisco (Catalyst / Meraki) Per-device + subscription tiers (DNA / Meraki licensing) Moderate–Premium Edge appliance class and count, license tier (Essentials vs. Advantage), separate Secure Access / Umbrella SSE seats, ThousandEyes and support
Fortinet Secure SD-WAN FortiGate appliance + FortiGuard subscription bundles; FortiSASE per-user Lower–Moderate FortiGate model per site, security-service bundle, FortiSASE user count, FortiManager/FortiAnalyzer, support level
Palo Alto Prisma SD-WAN Per-ION-edge subscription, part of Prisma SASE; SSE per-user Premium ION edge count and capacity, Prisma Access user tier, ADEM and advanced security modules, professional services
HPE Aruba EdgeConnect Per-edge subscription (EC-S/M/L tiers) + EdgeConnect SSE per-user Moderate EdgeConnect appliance tier and bandwidth, Boost WAN-optimization add-on, SSE seats, support and managed options
Versa Networks Flexible: per-site, per-user, or capacity; on-prem, cloud, or sovereign Moderate Deployment model (managed vs. self-hosted vs. sovereign), site and user counts, software tier, professional services depth
Cato Networks Subscription bundle: per-site (Socket) + per-user for the security stack Moderate Site/Socket count and bandwidth, ZTNA user count, optional security modules, the included global backbone
Arista VeloCloud Per-edge subscription (Standard/Enterprise/Premium editions) Moderate Edge count and throughput edition, gateway/orchestrator hosting, and third-party security if added (no native SSE in the deal)
3-Year TCO Formula
TCO = (SD-WAN subscription × 36 months) + Per-user SSE / security layer + Branch edge hardware + Underlay circuits (broadband / LTE / 5G) + MPLS overlap during coexistence + Professional services & migration + Internal FTE − Backhaul / MPLS savings − Avoided outage cost

Section 7

Implementation & Migration

Sequence a WAN transformation by risk and underlay reality, not by contract expiry dates. The hard part is rarely the technology — it is the shift from device-centric to policy-centric operations, the carrier lead times for new circuits, and the long stretch where SD-WAN runs in parallel with the MPLS you cannot exit yet. A national estate of a couple hundred sites is commonly a twelve-to-eighteen-month effort; plan the brownfield coexistence up front so you do not discover asymmetric paths and DNS surprises mid-rollout.

Phase 1
Assess & Baseline (Months 1–3)

Discover and segment applications, map each site’s underlay options (fiber, broadband, LTE/5G), and establish a performance baseline tied to business outcomes, not just uptime. Settle the architecture question — single-vendor SASE vs. best-of-breed — and run the POC with full security inspection enabled. Order new circuits early; carrier lead time is usually the critical path.

Phase 2
Pilot & Harden (Months 3–5)

Deploy a small set of representative sites — including a deliberately worst-connected one — to surface routing, DNS, and firewall-policy surprises while the blast radius is small. Stand up orchestration, zero-touch provisioning, identity integration, and the unified policy model, and codify branch configuration as templates and IaC before scaling.

Phase 3
Regional Waves & Coexistence (Months 5–12)

Migrate branches in regional waves, running hybrid MPLS and SD-WAN side by side with deliberate traffic-steering and fallback so a bad cutover is recoverable. Maintain unified visibility across both fabrics, and validate each site against the baseline before declaring it done.

Phase 4
Converge Security & Decommission (Months 12–18)

Layer and unify the SSE controls (SWG, CASB, FWaaS, and ZTNA to retire the VPN), tune TLS-decrypt exceptions and inspection performance, then decommission MPLS site by site as each validates. Settle into day-2 operations with DEM/DEX monitoring and a regular review of cost and policy drift.


Section 8

Selection Checklist & RFP Questions

Use this checklist during evaluation to ensure each shortlisted platform covers what actually decides an SD-WAN/SASE outcome — the operating reality, not the demo.


Section 9

Related Resources

Spotlight Listing

Interested in getting featured here?

Put your solution in front of the CIOs evaluating this category.

Learn how
Tags:SD-WANSASESSECisco Catalyst SD-WANFortinet Secure SD-WANPalo Alto Prisma SD-WANHPE Aruba EdgeConnectVersaCatoArista VeloCloudCloud Networking