Chapter 2
Aruba SD-Branch Solution
The Aruba SD Branch solution offers the best-in-class wireless and wired infrastructure and management
orchestration features with the SD-WAN capabilities. The SD Branch solution extends the SD-WAN concept to
all elements in the branch to deliver a full stack solution that addresses the business challenges of distributed
enterprises. Coupled with Aruba Central, the solution provides a cloud-hosted environment for simplified
operations and improved agility.
Why SD-WAN?
A traditional branch setup supports client connectivity requirements across different geographical locations for
various types of business operations. The sites in remote geographical locations serve as branch offices, while
the headquarters or main office serves as a data center that hosts network resources to store, manage, and
distribute data. The main office also hosts a centralized Virtual Private Network(VPN) management system to
aggregate traffic from the remote branch sites. A Wide Area Network (WAN) —with Multiprotocol Label
Switching (MPLS), T1, T3, Broadband, or Cellular links—is used for connecting multiple local area networks to a
central corporate network or data centers separated by distance.
Due to an increase in the number of client devices at the remote sites and the new bandwidth requirements,
branch office networks are expected rapidly scale to provide uninterrupted user experience. A traditional
branch infrastructure with multiple appliances, different operating systems, and management tools only adds
to the cost, involves a maintenance overhead, and demands skilled IT personnel.
The Aruba SD-WANsolution simplifies your branch deployments with a single management interface for
administering, managing, and monitoring your branch networks. It also provides a unified policy enforcement
framework with operational ease.
Key Features and Benefits
The SD-WANsolution comes with the following key capabilities:
nZero Touch Provisioning of devices—Ability to self-provision without operator's intervention.
nCentralized overlay management and control—A single cloud-based network management interface for
managing and monitoring SDBranch devices. Aruba Central, the cloud based network management system,
supports unified management of SDbranch devices with ZTP and hierarchical configuration.
nIPsec based Automatic VPN Tunnels—Support for high-performance and automatic IPsec VPN for secure
overlay networking.
nUnified security policy for wired, wireless, and WAN—Support for a common security policy framework
based on user roles for WAN, WLAN, and LAN users.
nDynamic path selection—Support for dynamically steering traffic or a service request to the best available
path. For example, you can configure a policy to dynamically route the real-time voice and video traffic on
the link with the lowest latency and jitter, and the bulk file traffic on the link with the maximum bandwidth.
nDeep Packet Inspection and Web Content Classification—Support for monitoring and analyzing application
usage by clients.
nVisibility, analytics, and troubleshooting—Dashboards for monitoring branch health, device performance,
and client connectivity metrics. Alerts, reports, and audit trails for monitoring and troubleshooting network
performance issues.
nPolicy-based Routing—In addition to the traditional destination-based routing, the SD Branch devices
support routing client traffic based on user role or type of application, For example, traffic generated from
Aruba SD-WAN Solution | User Guide Aruba SD-Branch Solution | 20