What’s New
This page provides brief descriptions of new features in the recent Orchestrator release.
Orchestrator 9.7.0
The following features and updates are included in Orchestrator 9.7.0.
NOTE: Orchestrator 9.7.0 is an Early Access release.
New Orchestrator Interface
The new web interface offers a simplified design for a faster, more responsive experience. The layout will remain familiar to users, with improvements throughout Orchestrator. This video series provides an overview of updates, new features, and improved workflows.
See this video series.
SASE Copilot
Orchestrator 9.7.0 introduces SASE Copilot, offering AI-assisted search and contextual help within Orchestrator. It helps users understand their SD-WAN and SASE environment, interpret system state, and access relevant documentation.
Use Case: Network operations teams need fast answers without digging through multiple tools or manuals. With SASE Copilot, operators ask natural-language questions to check network health, review security posture, visualize connectivity paths, or troubleshoot issues like tunnel failures. The interface provides guided answers from product documentation and APIs, helping users complete tasks quickly and confidently.
See SASE Copilot.
HPE SSE Connector Integration
HPE SSE Connector enables Zero Trust Network Access (ZTNA) users to securely reach private applications through the SD-WAN fabric without deploying or managing dedicated connectors in data centers or cloud environments. This release simplifies adoption by orchestrating connector lifecycle management and providing flow visibility for troubleshooting.
Use Case: A retailer grants contractors limited access to in-store systems without exposing the full network. Running the HPE SSE ZTNA Connector directly on the EdgeConnect appliance enables secure, application-level access without extra hardware or hypervisors. Identity and device checks enforce access to only required applications while protecting the rest of the network.
See HPE SSE.
Alarm Correlation
The Alarm Correlation feature groups multiple alarms with the same root cause into a single correlated alarm, reducing noise from related alarms triggered by a single event. Orchestrator automatically performs Alarm Correlation using predefined logic.
Use Case: When a service provider experiences a circuit failure at a branch site, dozens of related tunnel alarms may trigger simultaneously. Intelligent alarm correlation analyzes the relationships to identify the root cause. Operations teams receive a single, actionable notification, allowing focus on resolution instead of alarm noise.
See Intelligent Alarm Correlation.
Automatic WAN Bandwidth Detection
Automatic WAN Bandwidth Detection allows operators to measure upstream and downstream bandwidth across WAN interfaces directly from Orchestrator, improving bandwidth accuracy and reducing administrative overhead.
Use Case: Network capacity planners can evaluate the utilization at the appliance level from three perspectives: the total WAN-side bandwidth (sum of interfaces), appliance system bandwidth settings, and appliance bandwidth-based license. Network planners can evaluate appliance utilization on a time-of-day or business-hours basis and can determine how often the utilization exceeds a user-defined threshold.
See Interfaces Tab.
Unified Fabric Enhancements
The Unified Fabric enhancements strengthen segmentation, simplify configuration, and remove common deployment workarounds.
-
Zone mapping for Unified Fabric traffic
-
Default role mapping for Unified Fabric traffic
-
Overlay Tunnel Orchestrator (OTO) WAN type for label configuration
Use Case: A distributed retailer brings new stores online and needs them secured from day one. Using SD Branch or Microbranch gateways, new locations automatically join the SD-WAN fabric, reuse WAN labels, and inherit security zones and identity-based policies. Traffic segmentation and routing policies apply immediately, minimizing deployment risk.
See HPE Aruba Networking Central and Interface Labels.
EdgeConnect Orchestrator Integration with HPE GreenLake
The EdgeConnect management platform (SD-WAN Orchestrator-as-a-Service, or Cloud Orchestrator) can be added as a service to a workspace in HPE GreenLake. This allows organizations to manage multiple networking services without changing platforms, creating a unified, secure management experience. It also lets users access HPE services, such as HPE Networking Central, Compute, and others, through a single entry point. Integration allows management of EdgeConnect device inventory, subscriptions, and users via GreenLake, including RBAC support.
Configuration does not happen in Orchestrator. If not done, first create a workspace in HPE GreenLake. To learn more, log in to HPE GreenLake and search for “SD WAN Orchestrator”.
Enhanced Security Log Viewer
With the Security Log Viewer feature, EdgeConnect administrators can view security event data directly within Orchestrator for selected appliances. The Security Log Viewer provides real-time and stored security logs across supported log types, including Firewall, Stateful WAN Drops, Firewall Protection Profiles, and IDS/IPS. EdgeConnect administrators, along with SOC and NOC teams, can filter events by log type, appliance, time range, severity, protocol, event, application, and multiple log attributes. This enables precise analysis to determine whether traffic was allowed, blocked, dropped, or inspected by EdgeConnect security controls.
Use Case: When users report application access or connectivity issues, the operations team must determine whether EdgeConnect security controls are affecting traffic. By using the Security Log Viewer feature in Orchestrator, NOC and SOC teams can review security events across selected appliances, correlate relevant log entries with flow details using the flow ID, and identify whether application traffic was allowed, blocked, dropped, or inspected by EdgeConnect security controls.
See Security Log Viewer.
DHCP Manager
Orchestrator 9.7.0 introduces a centralized DHCP Manager that enhances configuration, monitoring, and operation of DHCP services across appliances. It supports distributed DHCP architectures, improves visibility, and reduces the effort of managing DHCP scopes, leases, reservations, and failover. It expands DHCP configuration capabilities, including flexibility for DHCP server, relay, IPv6 static, and Router Advertisement (RA) configurations. These capabilities simplify IP address management across complex edge deployments.
See DHCP Manager.
Advanced Network Access Control (Phase 2)
Phase 2 builds on existing EdgeConnect RADIUS authentication to improve reliability, stronger security, and broader deployment flexibility for RADIUS authentication on LAN ports. This release introduces the following enhancements:
-
Authentication survivability - When the authentication server is unreachable, already-authenticated MAC clients retain network access, preventing disruption during upstream outages.
-
Faster failure visibility - NAC failures now surface more quickly on the Network Access Control (NAC) tab, and failed client entries are retained longer for improved troubleshooting.
-
Brute-force protection - MAC addresses are automatically blocked after repeated authentication failures, and the Message-Authenticator attribute is now included in MAC Auth requests to harden RADIUS exchanges.
-
FQDN support for auth servers - Authentication server definitions now accept FQDN hostnames in addition to IPv4/IPv6 addresses, simplifying configuration in dynamic environments.
See Network Access Control (NAC).
Segment and VRF Pruning Integration
Orchestrator 9.7.0 adds support for segment/VRF pruning, allowing unused segments/VRFs to be excluded from Subnet Sharing announcements. If an EdgeConnect appliance is not using a particular segment/VRF, routes for that segment/VRF will not be present in the routing table. This reduces unnecessary control‑plane state and improves scalability in multi‑segment environments.
Enhanced Trust Store Management
Users can enable a single, orchestrated trust store for all Orchestrator and EdgeConnect functions dependent on CA certificates, including IPSec, TLS client connections, and SSL Proxy.
See Trust Store.
Bulk Configuration Restore
Users can simultaneously restore multiple EdgeConnect appliances to a previous configuration.
See Restore a Backup to an Appliance.
Common Criteria
The HPE Networking EdgeConnect SD-WAN Orchestrator platform achieved Common Criteria certification, ensuring compliance with international security standards for protected communications, role-based management, and secure administrative access. To maintain compliance, administrators must configure the system according to the Common Criteria User Guidance.
Remote IKE Identifier Configuration
Using Service Orchestration to automate tunnel configuration, users can now configure a Remote IKE identifier that is retrievable via REST APIs.
Enhanced IP SLA Visibility
Orchestrator 9.7.0 adds an IP SLA Summary view and dedicated IP SLA tabs, centralizing insight into SLA probe status, health, and performance. These views simplify monitoring and troubleshooting of path quality and SLA compliance across EdgeConnect appliances.
See IP SLA Summary.
Loopback Orchestration Populates BGP and OSPF Router IDs
The Router ID field in BGP Information and OSPF dialogs now includes a drop-down list to select from configured IPs in any segment, saving time and reducing errors. The field no longer defaults to “0.0.0.0” and instead starts blank.
Multi-Segment Multicast Support
Orchestrator supports IP multicast routing (PIM) across multiple VRF segments (up to eight), extending capability beyond the default VRF. Administrators can enable or disable multicast, configure PIM interfaces, rendezvous points, IGMP interfaces, and static multicast routes per segment.
See Multicast and Multicast Template.
Power Supply Health Reporting
Orchestrator can monitor and report power, voltage, and electrical current consumed by each EdgeConnect gateway. This visibility supports cost projection and sustainability initiatives. Information is available via Orchestrator and ECOS CLIs, and also REST APIs.
See Appliance Power Consumption.
Centralized Neighbor and ARP Visibility
Orchestrator provides a centralized view of neighbor and ARP tables for EdgeConnect appliances, improving network visibility and simplifying troubleshooting of Layer 2 and Layer 3 connectivity.
See ARP Tab.
Suricata 7.0 IDS/IPS Upgrade
The Suricata engine has been upgraded to version 7.0, providing critical security and performance updates.
See Intrusion Detection/Prevention System and Signature Profiles.
Other Updates
Ask AI Chatbot on the SD-WAN Documentation Website
The EdgeConnect SD-WAN documentation site now includes an Ask AI Chatbot that provides AI-powered assistance to answer technical questions instantly. It covers release notes, videos, Knowledgebase articles, API documentation, and curated content from validated solutions guides.