Brand: HPE | Category: Network Security
SKU: HPE-S1A80AAE | Part #: S1A80AAE | MPN: S1A80AAE
Contact for Pricing — Request a Quote
HPE Aruba Networking Security Service Edge (SSE) is a cloud-delivered security platform launched in Q1 2025 that converges Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), and Cloud Access Security Broker (CASB) capabilities into a single unified policy engine. Built as an integral extension of the Aruba EdgeConnect SD-WAN fabric, SSE enforces identity-aware, least-privilege access for both roaming users and fixed branch locations without requiring traffic backhauling to legacy on-premises security stacks. The platform leverages a globally distributed network of cloud Points of Presence (PoPs) to deliver low-latency inspection and enforcement close to where users and applications reside, whether in public cloud, SaaS, or private data centers.
The architecture centers on the Aruba Central cloud management plane, enabling unified visibility and policy orchestration across the entire hybrid WAN and security stack from a single pane of glass. Continuous adaptive trust evaluation dynamically adjusts access rights based on real-time device posture, user behavior analytics, and contextual risk scoring—eliminating the implicit trust inherent in traditional VPN-centric designs. Deep integration with HPE GreenLake allows organizations to consume SSE capacity as a cloud service with flexible subscription tiers scaled to active user counts and branch seat volumes.
Aruba SSE differentiates itself through native integration with the broader Aruba networking portfolio, including Aruba ClearPass Policy Manager for rich NAC-driven context and Aruba EdgeConnect Ultra for WAN underlay optimization. SSL/TLS inspection, DNS security, remote browser isolation (RBI), and digital experience monitoring (DEM) are available as composable service modules, allowing enterprises to incrementally adopt SSE capabilities aligned to their security maturity roadmap. The platform is designed to satisfy NIST SP 800-207 zero-trust architecture principles and aligns with the SASE framework defined by Gartner.
| Manufacturer | HPE |
| Brand | Aruba Networking |
| Product Line | HPE Aruba Networking SSE |
| Launch Generation | 2025-Q1 |
| Deployment Model | Cloud-delivered SaaS / HPE GreenLake subscription service |
| Core Security Functions | ZTNA (Zero Trust Network Access), SWG (Secure Web Gateway), CASB (Cloud Access Security Broker) |
| Additional Security Modules | Remote Browser Isolation (RBI), DNS Security, Digital Experience Monitoring (DEM), SSL/TLS Inspection |
| Zero Trust Framework Alignment | NIST SP 800-207 Zero Trust Architecture; SASE (Gartner framework) |
| Policy Enforcement Architecture | Identity-aware, continuous adaptive trust with real-time device posture and behavioral risk scoring |
| Global PoP Infrastructure | Globally distributed cloud Points of Presence for low-latency traffic inspection and enforcement |
| Management Plane | Aruba Central (single-pane-of-glass cloud management with unified policy orchestration) |
| SD-WAN Integration | Native integration with Aruba EdgeConnect SD-WAN and EdgeConnect Ultra for unified SASE architecture |
| Identity & Access Integration | Aruba ClearPass Policy Manager, SAML 2.0, OIDC, SCIM; supports major IdPs (Azure AD, Okta, Ping) |
| Endpoint Support | Windows, macOS, iOS, Android, Linux (agent-based); agentless browser-based access for unmanaged devices |
| Traffic Inspection | Full SSL/TLS decryption and inspection; HTTP/HTTPS, DNS, and cloud application traffic analysis |
| CASB Capabilities | Sanctioned and unsanctioned app visibility, shadow IT discovery, DLP policy enforcement, API-mode CASB for M365 and Google Workspace |
| SWG Capabilities | URL filtering, malware detection, threat intelligence feeds, application control, bandwidth management |
| ZTNA Access Model | Application-level micro-segmentation; supports client-initiated and service-initiated ZTNA models |
| Scalability | Subscription-based scaling by active user count and branch seat volume; elastic cloud capacity on demand |
| Regulatory & Compliance Support | Supports GDPR, HIPAA, PCI-DSS, and ISO 27001 audit logging and data residency controls |
| Logging & Analytics | Centralized cloud SIEM integration via syslog and API; built-in user and entity behavior analytics (UEBA) |
| API & Automation | RESTful API for policy automation, third-party SIEM/SOAR integration, and lifecycle management |
Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.
| Brand | HPE |
| Category | Network Security |
| SKU | HPE-S1A80AAE |
| Part Number | S1A80AAE |
| Condition | New |
| Product Line | HPE Aruba Networking SSE |
| Launch Generation | 2025-Q1 |
| Deployment Model | Cloud-delivered SaaS / HPE GreenLake subscription service |
| Core Security Functions | ZTNA (Zero Trust Network Access), SWG (Secure Web Gateway), CASB (Cloud Access Security Broker) |
| Additional Security Modules | Remote Browser Isolation (RBI), DNS Security, Digital Experience Monitoring (DEM), SSL/TLS Inspection |
| Zero Trust Framework Alignment | NIST SP 800-207 Zero Trust Architecture; SASE (Gartner framework) |
| Policy Enforcement Architecture | Identity-aware, continuous adaptive trust with real-time device posture and behavioral risk scoring |
| Global PoP Infrastructure | Globally distributed cloud Points of Presence for low-latency traffic inspection and enforcement |
| Management Plane | Aruba Central (single-pane-of-glass cloud management with unified policy orchestration) |
| SD-WAN Integration | Native integration with Aruba EdgeConnect SD-WAN and EdgeConnect Ultra for unified SASE architecture |
| Identity & Access Integration | Aruba ClearPass Policy Manager, SAML 2.0, OIDC, SCIM; supports major IdPs (Azure AD, Okta, Ping) |
| Endpoint Support | Windows, macOS, iOS, Android, Linux (agent-based); agentless browser-based access for unmanaged devices |
| Traffic Inspection | Full SSL/TLS decryption and inspection; HTTP/HTTPS, DNS, and cloud application traffic analysis |
| CASB Capabilities | Sanctioned and unsanctioned app visibility, shadow IT discovery, DLP policy enforcement, API-mode CASB for M365 and Google Workspace |
| SWG Capabilities | URL filtering, malware detection, threat intelligence feeds, application control, bandwidth management |
| ZTNA Access Model | Application-level micro-segmentation; supports client-initiated and service-initiated ZTNA models |
| Scalability | Subscription-based scaling by active user count and branch seat volume; elastic cloud capacity on demand |
| Regulatory & Compliance Support | Supports GDPR, HIPAA, PCI-DSS, and ISO 27001 audit logging and data residency controls |
| Logging & Analytics | Centralized cloud SIEM integration via syslog and API; built-in user and entity behavior analytics (UEBA) |
| API & Automation | RESTful API for policy automation, third-party SIEM/SOAR integration, and lifecycle management |
The HPE Aruba Networking SSE / Security Service Edge Platform is enterprise networking hardware for data-center, campus, and branch deployments. Common roles include core/distribution switching, server uplinks, top-of-rack fabric, and edge connectivity in mixed Cisco/Juniper/Arista environments.
Key specifications for the HPE Aruba Networking SSE / Security Service Edge Platform: new condition; manufacturer HPE; brand Aruba Networking; product line HPE Aruba Networking SSE; launch generation 2025-Q1; deployment model Cloud-delivered SaaS / HPE GreenLake subscription service; core security functions ZTNA (Zero Trust Network Access), SWG (Secure Web Gateway), CASB (Cloud Access Security Broker). Manufacturer part number S1A80AAE. For the full datasheet with electrical, environmental, and compliance details, contact our pre-sales engineering team.
The HPE Aruba Networking SSE / Security Service Edge Platform interoperates with standard switching protocols (LACP, MLAG/VPC, 802.1Q, OSPF/BGP). For specific cross-vendor scenarios — Cisco-to-Arista MLAG peering, fabric integration with Cumulus/SONiC, or migration from legacy Catalyst — our network engineers map a compatibility plan as part of the RFQ.