Link Search Menu Expand Document
calendar_month 23-May-24

Reference Architecture

This section describes the components and features of a remote worker design, with reference designs and bill-of-materials.

Table of contents

HPE Aruba Networks SSE is purchased per user for a given time period (1, 3, 5, or 7 years). All users in a workspace must have the same license level. Advanced Plus is the recommended license tier because it enables organizations to realize the full value of a Zero Trust remote access design including ZTNA, SWG, and CASB with all the advanced DLP features.

The table below outlines the features provided in each license tier.

Package / BundleFoundationFoundation Plus /
Foundation SWG
AdvancedAdvanced Plus
CommonXXXX
ManagementXXXX
PortalXXXX
AgentXXXX
ConnectorsXXXX
Branch ConnectivityXXXX
Smart RoutingXXXX
Server Initiated FlowXXXX
IdentityXXXX
Log StreamingXXXX
Partner IntegrationsXXXX
AnalyticsXXXX
Device PostureXXXX
Custom Block PagesXXXX
Network RangesXXXX
SSHXXXX
RDPXXXX
VNCXXXX
WebXXXX
SWG XXX
Threat Intelligence Protection XXX
DLP XXX
Malware Protection XXX
CASB  XX
Experience  XX
Cloud Firewall  XX
Advanced DLP   X
Local Edge   X
Sandbox  Requires add-onX
Managed Connectors  Requires add-onRequires add-on

Identity Planning

Integrating with identity providers should be considered carefully when planning architecture. Consider which identity providers to be integrated and which protocols to use. Certain identity providers do not support the required protocols, and may not be compatible, such as on-premise Active Directory. Consider the groups and users included in policies and ensure that the policies are created. For third-party access, consider the identity sources to use, which may differ from your corporate identity store.

Connector Planning

There is no cost for the connectors, though operators should plan for the compute and connectivity requirements of the connector. Best practice is to deploy at least two connectors in each zone for redundancy.

For setting up a connector, select one of the following options:

  • Deploy a connector on your own server. Click here to read and verify the server requirements.
  • Deploy a virtual machine template. Follow the deployment instructions here.
  • Deploy in AWS. Follow the AWS deployment instructions here.

A managed connector offering will be available soon.


Back to top

© Copyright 2024 Hewlett Packard Enterprise Development LP. The information contained herein is subject to change without notice. The only warranties for Hewlett Packard Enterprise products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Hewlett Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein. Aruba Networks and the Aruba logo are registered trademarks of Aruba Networks, Inc. Third-party trademarks mentioned are the property of their respective owners. To view the end-user software agreement, go to Aruba EULA.