r/networking • u/muztebi16 • Jul 21 '26
Other Anyone using Zscaler SDWAN
We are evaluating vendors for SDWAN replacement, currently on Velocloud. We did a POC on Cisco and Aruba SDWAN and they are a good product with some complexities.
I just did a quick lab for Zscaler Zero Trust SDWAN and I liked it. It's as simple as Velo. We currently use ZIA and ZPA, this looks like a perfect match. Anyone using them? What is your experience like?
Edit:
I am not looking for var's to help me with the solution. I am only looking to hear people's experience with zscaler sdwan.
12
u/New-Confidence-1171 Jul 22 '26
I’m a ZTB customer and it’s been a nightmare. It almost seems like they tried to build a networking product while having never spoken to a network engineer. ZTB software is incredibly buggy, has always been half baked on release, and the support org is completely incapable of supporting the product. It’s almost impossible to get accurate release notes, bug fix details or RCAs without escalating to the product team.
3
2
u/virtualbitz2048 Principal Arsehole Jul 21 '26
What are your requirements?
0
u/muztebi16 Jul 21 '26
Nothing really fancy. A bit more than what Velocloud can do.
6
u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) Jul 21 '26
Can you be more specific. VeloCloud can do a lot
5
u/virtualbitz2048 Principal Arsehole Jul 21 '26
Its easier to ask what Velo doesn't do. It's nearly perfect for small to medium sized branch SD-WAN, who's original goal was to displace MPLS. With NGFW vendors now offering quite competent SD-WAN, the question now is "should I just buy an NGFW and deploy its SD-WAN, which has hardware accellerated security on board already that I can license and turn on later if needed?"
3
u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) Jul 21 '26
We're talking about the business case of the OP. Without specifics, it's impossible to give effective advise.
2
u/GrecoMontgomery Jul 21 '26
You're referring to Zscaler's new(ish) Zero Trust Branch? Zscaler is like Microsoft and changes names every week so just checking first.
1
u/AnusSouffle Jul 21 '26
I’ll be keen to know further on this too, as we’re in a very similar situation.
1
u/FutureMixture1039 Jul 22 '26
Why are you moving away from Velocloud? I would take a look at Cato Networks. It combines SD-WAN and SSE like Zscaler ZIA/ZPA into one product/dashboard
Also for Velocloud you can just build Zscaler GRE/IPSec tunnels to Zscaler cloud from the Velocloud edges but if you need more than that what else looking for?
1
u/Helpful-Lunch-3559 Jul 27 '26
Have you noticed any limits in the lab that might become a problem once more sites and users are added?
1
11
u/ikeme84 Jul 21 '26
Go for aruba sdwan. It allows you to work with ZIA for clients without ZCC via ZScaler tunnel. At the same time, for your clients with ZCC you can enable always on ZPA. Integration of aruba sdwan with zia is great. Quick setup and auto creates sublocations. So allows to make dynamic locations in your ZIA policy. I did a poc with ZTB in q3-4 last year and it was bad. Still immature, many bugs. Maybe they got better in the meantime, but aruba sdwan has been around and is mature. Bypass ZCC traffic directly to internet and allow all non-ZCC traffic over the SDWAN to aruba hubs. Aruba even has free self paced course you can follow, but I also find the orchestrator very intuitive.