Switch-based zero-trust microsegmentation that enforces microperimeters directly in the EOS fabric, requiring no endpoint agents or proprietary protocols, managed through CloudVision.
Arista Multi-Domain Segmentation Services (MSS) enforces zero trust microperimeters directly in the EOS fabric at the switch ASIC, at wire speed without endpoint agents or proprietary overlay protocols. MSS binds endpoints, workloads, and network segments to microperimeter tags through CloudVision's NetDL pipeline, then enforces the resulting segmentation policy at every connected port across the fabric, covering managed devices and unmanaged assets IoT sensors, building automation systems, and operational technology that cannot run endpoint agents.
Policy enforcement is stateless and wire-speed: MSS acts at the ingress switch port before a packet reaches any other device on the network. There is no dedicated enforcement appliance in the forwarding path and no throughput ceiling other than the aggregate capacity of the switching fabric itself. Continuous traffic monitoring through CloudVision provides real-time visibility into policy violations, enabling security teams to investigate events without waiting for batch log collection from a separate monitoring system.
Integration with NAC systems, CMDBs, and virtualization platforms such as VMware vSphere allows MSS to consume identity and context from existing enterprise inventory systems, avoiding the need to rebuild device identity from scratch in a parallel database. When a device's authorization state changes in an upstream system due to a failed posture check, a changed role, or a detected infection the change flows into MSS tag assignment through CloudVision's NetDL pipeline and takes effect at the forwarding plane without requiring manual rule changes on individual switches.
MSS enforces segmentation policy at the switch forwarding ASIC rather than through an out-of-path appliance, meaning enforcement does not add forwarding latency, there is no dedicated appliance throughput ceiling, and blocked traffic is stopped at the ingress port before reaching any other device on the network.
Segmentation policy is enforced at every connected port regardless of whether the endpoint can run an agent IoT sensors, building automation systems, medical equipment, and OT assets are all covered at wire speed through the same EOS-based enforcement plane as managed devices.
Endpoint, workload, and network tags are bound and updated through CloudVision's NetDL pipeline, which integrates with NAC systems, CMDBs, and virtualization platforms to consume identity and context from existing enterprise inventory no separate policy database to maintain.
Continuous monitoring through CloudVision provides real-time visibility into policy violations and traffic flows, enabling security teams to investigate incidents as they occur rather than relying on periodic log exports from a separate monitoring system.
Full specifications for Arista Multi-Domain Segmentation (MSS)
Download product documentation and resources
Explore other configurations and models that might suit your needs.
Recommended#Arista-7130E
Recommended#Arista-EDGE-THREAT-MANAGEMENT-SOLUTIONS
Recommended#Arista-NG
Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.
We're here to help with any questions