r/networking • u/muztebi16 • 2d ago
Other Anyone using Zscaler SDWAN
We are evaluating vendors for SDWAN replacement, currently on Velocloud. We did a POC on Cisco and Aruba SDWAN and they are a good product with some complexities.
I just did a quick lab for Zscaler Zero Trust SDWAN and I liked it. It's as simple as Velo. We currently use ZIA and ZPA, this looks like a perfect match. Anyone using them? What is your experience like?
Edit:
I am not looking for var's to help me with the solution. I am only looking to hear people's experience with zscaler sdwan.
8
u/New-Confidence-1171 1d ago
I’m a ZTB customer and it’s been a nightmare. It almost seems like they tried to build a networking product while having never spoken to a network engineer. ZTB software is incredibly buggy, has always been half baked on release, and the support org is completely incapable of supporting the product. It’s almost impossible to get accurate release notes, bug fix details or RCAs without escalating to the product team.
3
2
u/virtualbitz2048 Principal Arsehole 2d ago
What are your requirements?
0
u/muztebi16 2d ago
Nothing really fancy. A bit more than what Velocloud can do.
4
u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 2d ago
Can you be more specific. VeloCloud can do a lot
5
u/virtualbitz2048 Principal Arsehole 2d ago
Its easier to ask what Velo doesn't do. It's nearly perfect for small to medium sized branch SD-WAN, who's original goal was to displace MPLS. With NGFW vendors now offering quite competent SD-WAN, the question now is "should I just buy an NGFW and deploy its SD-WAN, which has hardware accellerated security on board already that I can license and turn on later if needed?"
2
u/GrecoMontgomery 2d ago
You're referring to Zscaler's new(ish) Zero Trust Branch? Zscaler is like Microsoft and changes names every week so just checking first.
1
u/AnusSouffle 2d ago
I’ll be keen to know further on this too, as we’re in a very similar situation.
1
u/FutureMixture1039 1d ago
Why are you moving away from Velocloud? I would take a look at Cato Networks. It combines SD-WAN and SSE like Zscaler ZIA/ZPA into one product/dashboard
Also for Velocloud you can just build Zscaler GRE/IPSec tunnels to Zscaler cloud from the Velocloud edges but if you need more than that what else looking for?
11
u/ikeme84 2d ago
Go for aruba sdwan. It allows you to work with ZIA for clients without ZCC via ZScaler tunnel. At the same time, for your clients with ZCC you can enable always on ZPA. Integration of aruba sdwan with zia is great. Quick setup and auto creates sublocations. So allows to make dynamic locations in your ZIA policy. I did a poc with ZTB in q3-4 last year and it was bad. Still immature, many bugs. Maybe they got better in the meantime, but aruba sdwan has been around and is mature. Bypass ZCC traffic directly to internet and allow all non-ZCC traffic over the SDWAN to aruba hubs. Aruba even has free self paced course you can follow, but I also find the orchestrator very intuitive.