Contact Us (02) 9388 1741
Defeat Lateral Threats

Defeat Lateral Threats

Enforcing Zero Trust directly in the fabric at wire speed: MSS microsegmentation, AGNI identity, and NDR threat hunting running on EOS switches already in production.

Talk to a Specialist

Lateral threat movement, where an attacker that has compromised one system crosses the network to reach additional systems, succeeds when the network lacks sufficient segmentation to prevent that crossing. Traditional segmentation approaches rely on firewall rules between subnets or VLANs, but enforcing fine-grained policies at the workload level requires creating and maintaining large numbers of firewall rules that grow exponentially as the number of protected systems increases. The enforcement point, a centralised firewall, also becomes a bottleneck for east-west traffic that must traverse it. Endpoint agents can extend identity-aware enforcement to individual devices, but they cannot be installed on unmanaged devices: IoT sensors, building management systems, medical equipment, and OT devices that represent a significant portion of devices on most enterprise networks and cannot be enrolled in an agent deployment. An attacker who has compromised one unmanaged device on a flat segment can reach all other devices on that segment without encountering any enforcement.

Arista's zero trust fabric integrates Multi-domain Segmentation Services (MSS), AGNI (Guardian for Network Identity), and Network Detection and Response (NDR) into the EOS and CloudVision platform to enforce identity-aware segmentation at the switch ASIC, at wire speed, at every port, covering every device connected to the network regardless of whether it can run an endpoint agent. MSS runs as part of EOS on each switch and enforces segmentation policies at the forwarding plane rather than through an out-of-path appliance, meaning enforcement latency is wire-speed and there is no central bottleneck. AGNI provides identity context for network-connected devices without requiring agents, profiling devices through network behaviour and supplying that identity context to MSS policy enforcement. NDR detects lateral movement attempts by monitoring east-west traffic for anomalous patterns, providing the detection layer that operates alongside the prevention layer of MSS. The 7260X3 with UFT Mode 3 supports 104,000 IPv4 host routes, providing the route table scale for large deployments with fine-grained per-host segmentation policies.

Wire-Speed Enforcement at the ASIC

MSS policy enforcement occurs at the switch forwarding ASIC rather than through a separate security appliance in the network path. This means enforcement does not add forwarding latency compared to a non-enforcement path, and there is no dedicated appliance whose throughput capacity limits the policy enforcement scale. When a segmentation policy blocks a specific east-west flow, the block occurs at the ingress switch port before the packet reaches any other device on the network; the blocked traffic is never forwarded to an out-of-path enforcement point for inspection before being dropped. The distributed nature of ASIC-level enforcement also means that the enforcement capacity scales linearly with the number of switches in the fabric rather than with the throughput of a centralised enforcement appliance.

Agentless Device Identity with AGNI

AGNI (Guardian for Network Identity) establishes and maintains identity context for network-connected devices without requiring endpoint agents or modifications to the devices themselves, a requirement for IoT, OT, medical, and building management systems that cannot run software agents. AGNI profiles device identity through observed network behaviour, MAC OUI manufacturer data, DHCP fingerprinting, and traffic pattern analysis, and continuously updates the identity assessment as device behaviour changes over time. That identity context is supplied to MSS to drive segmentation policy enforcement, so a device whose behaviour deviates from its expected profile (for instance, a printer that begins making SSH connections) receives updated identity classification that immediately affects which network segments it is allowed to access. Agentless coverage is the capability that allows a zero trust posture to extend to 100% of network-connected devices rather than only managed corporate assets.

NDR for East-West Lateral Movement Detection

Network Detection and Response (NDR) monitors east-west traffic patterns across the fabric for behaviours that indicate lateral movement attempts: port scanning between internal hosts, credential brute-forcing across segments, data staging on internal file shares, or command-and-control communications that match known threat actor patterns. NDR operates from the network rather than from endpoints, meaning it detects movement activity between all devices on the fabric regardless of whether those devices have endpoint security agents installed. Detections from NDR feed back into CloudVision and can trigger automated responses through MSS, restricting a compromised device's network access without waiting for manual intervention while the investigation proceeds. The combination of MSS prevention and NDR detection means that attacks stopped at the prevention layer are logged, and attacks that reach an advanced stage despite prevention generate detections that trigger incident response.

No Proprietary Overlay Required

Arista's MSS segmentation runs on standard EOS infrastructure using existing switch ASICs: no proprietary overlay protocol, no separate fabric hardware, and no custom endpoint adapters required on protected hosts. For enterprise networks that have already deployed Arista switching for performance and availability reasons, enabling MSS segmentation is an EOS and CloudVision software enablement on existing hardware rather than a separate hardware procurement and deployment project. Process isolation in EOS ensures that the MSS policy enforcement process operates independently from routing, spanning tree, and other forwarding processes; an issue in one process does not affect the others. Live patching allows EOS processes to be updated without a reboot, keeping the enforcement software current without creating maintenance windows that temporarily remove enforcement coverage.

Technical Specifications

Full specifications for Defeat Lateral Threats

Detailed specifications are coming soon — see the datasheet in the Documentation tab for full details in the meantime.

Documentation

Download product documentation and resources

Product Datasheet

Defeat Lateral Threats Datasheet

Your browser doesn't support inline PDF preview. Download the datasheet instead.

Call a Specialist
Today!

Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.

Monday - Friday: 9:00 AM - 6:00 PM AEST
Sydney, Australia

Speak to an Expert

We're here to help with any questions

Call us now
(02) 9388 1741