Cloud Connect

SD-Branch integration with cloud-based security and networking services

Cloud Connect enables secure connectivity between HPE Aruba Networking gateways and cloud-based services. It allows branch gateways to establish encrypted connections not only to cloud security platforms, but also to cloud networking infrastructure hosted in public cloud environments.

Cloud Connect supports integration with:

  • Cloud security providers, such as Zscaler, Aruba SSE, Prisma Access, etc., where traffic is steered to the cloud for security inspection and policy enforcement. In addition to these integrations, Cloud Connect also supports custom-defined cloud security endpoints, allowing integration with other vendors. Customers can onboard any provider by specifying the required endpoints, enabling Cloud Connect to establish IPsec tunnels and route traffic toward third-party security platforms that are not natively predefined. Cloud Connect also supports geolocation-aware endpoint selection for these integrations, where IPsec tunnels are established to the closest available cloud node based on the originating gateway location, optimizing latency and path efficiency.

  • Cloud networking platforms, such as Microsoft Azure Virtual Network Gateway (VGW) and Amazon Web Services Transit Gateway (TGW), where Cloud Connect provides private connectivity between branch or VPNC sites and cloud-hosted applications.

This dual capability allows customers to use Cloud Connect either for secure internet access via cloud-delivered security services or for private connectivity into public cloud environments, depending on their architecture.

Cloud Connect uses the SD‑Branch Orchestrator to automate configuration and lifecycle management of these connections. Branch Gateways establish IPsec tunnels to the selected cloud endpoints, and routing is dynamically exchanged to ensure optimal path selection between branch locations and cloud destinations.

This approach simplifies large-scale deployments by:

  • automating tunnel creation and maintenance

  • enabling consistent connectivity across multiple cloud providers

  • providing centralized control of branch-to-cloud traffic flows

Cloud Connect is designed to operate as part of the SD-Branch architecture, extending secure and optimized connectivity from branch sites to both security services and cloud-hosted resources without requiring manual tunnel configuration or complex routing setup.

For information about configuring Cloud Connect, see the following topics: