Contact Us (02) 9388 1741
Reduce Firewall Spend

Reduce Firewall Spend

How Arista MSS delivers zero-trust microsegmentation using the EOS fabric already in place, without adding proprietary appliances or a forklift upgrade.

Talk to a Specialist

Centralised east-west firewalls (dedicated security appliances positioned to inspect and enforce policy on internal traffic) impose two costs beyond their purchase and maintenance price: throughput bottlenecks as east-west traffic volumes grow, and operational overhead from the firewall change management process. Each policy change requires a ticket, a review cycle, a change window, and a deployment, a process that takes hours to days for a single rule update and becomes a recurring cost at scale. As workloads move and network segments change, the firewall rule base grows in complexity, and the operational cost of maintaining accurate rules grows with it. The throughput limitation of a centralised appliance also forces capacity upgrades when east-west traffic volumes exceed the appliance's forwarding rate, a hardware procurement cycle that interrupts operations regardless of whether the security policy has changed.

Arista's Multi-domain Segmentation Services (MSS) moves the enforcement point from a centralised firewall to the forwarding ASIC of every EOS switch in the fabric, running on the existing switch hardware without requiring new appliance purchases. MSS policies are defined in CloudVision using identity-aware microperimeters: a workload's allowed communications are defined by its identity classification rather than its IP address or VLAN, which means policies remain accurate as workloads move or are reclassified without requiring firewall rule updates. Policy changes defined in CloudVision propagate across all MSS-enabled switches in seconds. The change management latency drops from hours to near-instant. For branch and edge deployments, Arista's Edge Threat Management integrates UTM (Unified Threat Management) capabilities at the network edge, providing the north-south filtering that complements MSS east-west microsegmentation. The combined architecture aligns with the CISA Zero Trust Maturity Model's requirements for distributed enforcement, identity-aware access, and continuous verification.

Distributed Enforcement on Existing Hardware

MSS enforcement runs in EOS on each Arista switch as a software feature, using the switch ASIC for wire-speed packet filtering, the same ASIC that handles all other forwarding decisions. This means MSS microsegmentation is enabled on existing deployed Arista switches through EOS and CloudVision software activation, rather than requiring a parallel hardware deployment of east-west firewall appliances. For organisations with an existing Arista fabric, enabling MSS does not require additional capital investment in security hardware. The cost model shifts from appliance procurement to subscription software. The distributed enforcement model also eliminates the single point of failure associated with centralised firewalls: there is no individual appliance whose failure removes policy enforcement from a network segment.

Identity-Aware Microperimeters

MSS policies define which identities can communicate with which other identities: workload labels, device classifications from AGNI, user identity from directory services, and application classifications. Because policies are written in terms of identity rather than IP address, a workload whose IP address changes (due to migration, DHCP renewal, or VM movement) remains covered by the correct policy without a firewall rule update. For dynamic environments where workloads are frequently created, moved, and retired (containerised applications, virtualised infrastructure, cloud bursting), identity-aware policies eliminate the continuous policy maintenance burden that IP-based firewall rules impose in those environments. Policy violation events are visible in CloudVision with identity context, showing which workload attempted which communication and whether it was allowed or blocked.

Policy Changes Take Effect in Seconds

Policy changes defined in CloudVision are pushed to all MSS-enabled switches in the fabric within seconds of being committed: no change window, no firewall deployment, and no per-device CLI change required. For incident response scenarios where a compromised host needs immediate isolation from network access, the ability to enforce a quarantine policy across the entire fabric in seconds rather than through a multi-step firewall change process reduces the dwell time during which the compromised host can reach additional targets. For routine policy operations (adding a new application to an approved communication set, restricting a workload during a maintenance period), the speed of policy application reduces the operational drag associated with security policy updates in the normal course of network operations.

CISA Zero Trust Maturity Alignment

The CISA Zero Trust Maturity Model specifies distributed enforcement, continuous verification, and identity-centric access control as the capabilities that define advanced zero trust maturity. Arista MSS addresses the network pillar of the maturity model by providing per-workload microsegmentation enforced at the forwarding plane, with policies continuously reconciled against current workload identity rather than assumed to be correct from the time of last manual update. For organisations pursuing compliance with US Federal zero trust requirements or using the CISA model as a security framework, MSS provides a documented technical control for the network segmentation and microsegmentation requirements. Edge Threat Management at the perimeter and NG Firewall for application-layer visibility complete the stack from the microsegmented internal fabric to the externally facing network boundary.

Technical Specifications

Full specifications for Reduce Firewall Spend

Detailed specifications are coming soon — see the datasheet in the Documentation tab for full details in the meantime.

Documentation

Download product documentation and resources

Product Datasheet

Reduce Firewall Spend Datasheet

Your browser doesn't support inline PDF preview. Download the datasheet instead.

Call a Specialist
Today!

Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.

Monday - Friday: 9:00 AM - 6:00 PM AEST
Sydney, Australia

Speak to an Expert

We're here to help with any questions

Call us now
(02) 9388 1741