Modernize Virtualization Stack with HPE Aruba Networking CX Switches
Marty Ma, Director of Product Management for HPE Aruba Networking’s CX switching strategy, presented on modernizing the virtualization stack with HPE Aruba Networking CX Switches. He introduced new products and recent integrations that unify HPE’s offerings. The CX switch portfolio, established in late 2016, now spans from 1 GBe to 400 GBe, all operating on a common software platform and managed by Aruba Central. This broad portfolio supports campus, branch, remote, access, aggregation, and core environments, as well as high-density data center deployments. A key innovation in late 2021 was the introduction of the first smart switch featuring a DPU (Data Processing Unit) from AMD Pensando, designed to bring services closer to the workload at the top of the rack. This was followed by the CX 10040, focused on 100 GBe server connectivity, both offering stateful Layer 4-7 services, East-West firewall inspection, and high-resolution telemetry.
Ma then linked this to the broader HPE GreenLake strategy, emphasizing the HPE Private Cloud Solution and HPE Private AI offerings, all orchestrated by HPE Morpheus software. He specifically highlighted Morpheus VM Essential, a next-generation virtualization management solution that unifies disparate hypervisor environments (like existing VMware ESXi clusters and KVM-based environments), all managed through a single pane of glass: HVM Manager. This aims to provide a more cost-effective alternative for customers concerned about rising hypervisor licensing costs. The overall HPE strategy positions them as a unique IT vendor capable of delivering a full hybrid cloud stack, with Morpheus for management and OpsRamp for comprehensive visibility across all environments.
The presentation underscored how the CX smart switching portfolio integrates with this virtualization strategy. Customers can leverage plugins to connect DPU-equipped switches into their hypervisor environments, enabling macro and micro-segmentation and advanced network services directly at the first-hop switch, even for bare-metal servers. This approach aims to simplify virtual networking across different hypervisors by offloading network policy enforcement to the hardware. The ongoing trend of increasing network speeds, driven by AI workloads, further validates HPE’s decision to integrate DPUs into switches, making the conversation about DPU placement more relevant than ever. The entire solution is designed to simplify complex end-to-end problems by providing a holistic view from compute and storage to networking, orchestrated and managed centrally.
Presented by Marty Ma, Director of Product Management, Aruba CX Switching. Recorded live at Networking Field Day 38 in Silicon Valley on July 10, 2025. Watch the entire presentation at https://techfieldday.com/appearance/hpe-aruba-networking-presents-at-networking-field-day-38/ or visit https://techfieldday.com/event/nfd38/ or https://www.hpe.com/us/en/networking/hpe-aruba-networking.html for more information.
Transcript
My name is Marty Ma. I'm a product director of product management at the HP Aruba Networking, right? I'm mainly focused on the CX switching strategy and any innovation moving forward, right?
So today I'd like to actually share with you guys one of the topic which is, uh, very popular these days seems probably 12 months ago, right? If you search on the internet talking about virtualization strategy, a lot of end customers actually looking into how do they actually migrate from where they are to basically better protect them for the future. So today we're actually gonna introducing some new product as part of our product portfolio, as well as a recent integration that announced that really pieced all the offering together from h HP across the board.
So before I dive into what I'm gonna share in detail, let me actually quickly walk you through a history of what the HP Aruba is offering around the CX portfolio. So we started the whole CX switching portfolio since the late, uh, 2016. And since then, nine plus years later, we actually have a full breadth of, uh, switching portfolio ranging from down to one gig to all the way up to 400 gig all sitting on a common platform software feature set, and then manage, uh, together with the common platform that that was just introduced essential platform.
So these whole family of switches can basically help the customer in the enterprise pri uh, environment, basically from campus branch remote ranging from access aggregation to core. At the same time, we also have a data center focused portfolio from the CX 8,000 above basically to provide very high density of a 10 gig ranging all the way up to 400 gig portfolio and all managed by the central platform that we just talked about. And fast forward a little bit in the late, uh, 2021, we actually announced the first smart switch in the industry.
Basically, I assume most of you're familiar with the DPU, uh, use on the server nick car, right? We started with the idea working with MD Cindo to really putting the DPU together with the switching together to build the first much switch on the market, and really intended to basically solve a major problem that we have seen in the past in the networking industry, which is by putting the service closest to where the workload is, right, which is the top of rec. And just last month we actually introduced the second flavor of this whole smart switch portfolio, which is basically a CX 10,040, right?
So now this one is basically focused more on the advanced server connectivity, a hundred gig moving forward. And all these platforms share the common, uh, platform capability that I just mentioned about any common switch capability you see in the past. It's all available there and now we can have availability from 25 gig all the way up to 400 gig, up to eight terabit.
And then all the both product family is basically DP enhanced. So we will be able to offer stable layer full service across the board. 6 terabyte stateful East West following inspection, macro microsegmentation, being able to basically to be a different location, the network.
And really one unique capability is the high resolution of telemetry this platform can offer up to, we can actually manage to a couple million, uh, flow at the same time using NetFlow. All right. And then switching the gear a little bit, which is kind of a, where I want to talk about on this part.
It's really HP announced the GreenLake to basically encompass all the product offering we that we have across the board ranging from the platform all the way to the different solution. And then HP private cloud solution, which was announced last year, really putting these together to allow customer a kind of a migration path, not only available, say for to do things in public cloud, they can actually have in their private data center in a private cloud setting, manage my HP in GreenLake, and then all the existing HP solution offering product can also be landing on top of whether GreenLake or private cloud environment through the GreenLake flag. And then with last year, we announced, uh, joined at adventure, uh, with the, uh, Nvidia, the AI capability and an environment now can be consumed as part of HP GreenLake as well through the hp, uh, private ai.
And all these are orchestrated through the HP Morpheus software. And then in addition to that, we also just announced the Morpheus VM essential, which is, think about it, it's really a kind of a next generation way of how you measure VM environment, which I'm gonna talk a little bit more in the next slide. It can basically be consumed either as a standalone software or on top of the, uh, private cloud solution offering.
So what we were offering with the morphs VM essential is really e environment which help you unify your virtualized environment, right? So you can now actually having the existing VMware ESXI cluster on top of it. If you want to actually have a new vm, you can actually try to put it into the hypervisor environment offered by board with VM essential.
And all these environment, it's orchestrated manage through a common single pane of a glass called H VM manager. So then that way, no matter which hypervisor the end customer decide to go down to this offer a customer number one, a unified way to integrate different hypervisor environment, and at the same time reduce the cost, which is at the beginning. I talked about a lot of customer today thinking about what is my next strategy when I'm moving from a current increased price license model into a more kind of affordable model.
That's, and that's actually where this, uh, VM essential solutions coming down to. So in addition to the platform itself through morphs, I mean really earlier, we also also talk about sram give us cross the HP portfolio visibility observability through the ops ramp, right through the ops ramp and through morphs, along with the fullblown of the product solution that offered by HPE in general. This offer us a unique opportunity to truly become the only IT vendor in a be able to support to provide a full hybrid cloud stack.
So being at a private hyper, uh, hypervisor environment with v VMware, Nutanix Red Hat, or if the customer choose to go with things like, uh, Microsoft, AWS Azure, all these environment can be unified through a common set of the management orchestration platform through the morphs as a platform. Upstream has a visibility that can tap into all these environment, collect the telemetry, and then where we can see the previous talked about the genic AI and different aspect can be all aggregated together. So the next question you're gonna ask is how does it relate to the CX switching portfolio that you mentioned the very beginning or where I represent, right?
So as part of these offering, the, uh, you, the user do really have two different option. Technically. They can basically integrate the CX switching portfolio, the smart switching, basically the switching with the DPU equipped on top of it.
There is a plugin basically help you integrate this into the environment. So user can basically choose to go lower on the milking stack, on the hypervisor, uh, uh, vendor offering. And from there still continue to have all the macro micro segmentation and service they're enjoying today on a different, uh, hypervisor platform with a much lower cost entry point.
And also, alternatively or strategically, they can choose basically to start trying out a alternative for hypervisors side by side. So we are able to basically offer you the capability to basically having a KVM based environment managed jointly through the VM essential, which is part of VM essential offering. Then from there, the user can basically co-manage both the VMware environment as well as the, uh, ES, the uh, uh, the uh, VM essential environment together under a single pane of glass.
So here's kind of a more technical view looking into how these, uh, structure actually work, and then where does CX smart switching portfolio coming into place to help you solve the problem? Traditionally on the virtualized environment, um, this is dated probably 10, 15 years ago, right? There's networking requirement within the host, and then the vendor came out with a virtualized or soft switch kind of a solution to really solve the problem by providing the connectivity in between.
And then in order to offer the more advanced zero trust or kind of, uh, isolation, the isolated port group or PV land was basically commonly used to offer this kind of a solution within the box. And then this basically allowed the VM traffic even within the same host, as long as they're separate, separated at the next level, going down to the first hop switch, we will be able to start doing microsegmentation at the first hop. Now with the HVM, we offer both model, right?
With the OVS built into the KVM, you can, we can provide a basically layer two functionality, but then with the plugin actually loaded, we're leveraging native, uh, Linux, uh, vn, uh, driver, basically to provide you Mac vlan or MAC VT A to allow you also similar isolation from a K VM based hypervisor and directly connect to a DVU equipped, uh, switch where you can actually leverage in the service policy to enforce your macro and microsegmentation. And even if you have a bare metal now, you don't actually really have to run another software instance, which is commonly a problem today when you try to normalize the virtual networking across different hypervisor. If you wanted that to work with a physical world, there need to be a kind of a, a networking node or gateway, which you actually do that.
So now with a smart switch into place, basically we are the northbound, we using the HVM manager to orchestrate all these things together, the VM landing and everything. And our southbound, they also interact with the Aruba Fabric composer, where basically we can orchestrate a switch for the corresponding network construct require. At the same time, also the networking policy require for the microsegmentation Question, Molly.
Sure. From a customer perspective, do you see that they prefer having the DPU on the nick on the server itself? Mm-hmm.
Or on the smart switch, right? This is, this is the Monterrey can roll extension, right? Right, Right.
That's the project that you had back four years ago, 2021, Right? So very good question, right? So the DPUX has started as something to be consumed on a nick in the very early time.
Yep. Right. At that time, most customer, I mean, the challenges there would be cost wise, number one, it's prohibitive for them to actually buy a nick, which costs you almost doubling the price as your server just for these functionality.
So that become quickly something they're not willing to consume. Secondly, it's like at that time, most for server, typically, if you want to introduce any new technology, it has to kind of be somewhat greenfield, right? Nobody's gonna go back to retrofit, basically pull out their net out just for this purpose.
So that, that's a exact reason In the end of 2021, through working with MD and sendo, we found out, okay, that's actually a better way to do it by putting on top of switch, right? Again, certain things you probably won't be able to do it, for example, like storage related, if you try to accelerate with DPU, you won't be able to do that. But then in terms of networking service really put us in a very good position and a recent announcement by another vendor actually on a similar architecture, kind of proven this is a valid point.
And then this is actually a ongoing trend for customer wanting adopting that. And then we're just kind of approving us making a decision four or five years ago. That's truly the right way to drive this forward.
So Yeah. I know that the announcement that came recently, so it's sort of four years after mm-hmm. What's changed from a customer perspective to now?
I mean, this was introduced, this was a little early, right? Monterey cannery role was pretty cool back then, but the uptake was, I would say a little muted, right? Right.
But what's changed now that I think what's changing is a couple different thing, right? The speed of a network really, I mean, help with the help of ai, the server speed actually started increasing dramatically in the past. Kind of, you look at the whole industry every time the networking speed especially need to be driven from a workload or node perspective from server.
Usually it's lagging a few years behind, right? And now you actually, with the air introduction, you're actually seeing the industry asking for more, right? 6 for TOPBOX six.
These trend basically speed up a lot of these adoption cycle and making the conversation of where you're putting DPU into it and become much more relevant to begin with, right? Even the dominating AI vendor is actually doing DPU on their AI server as well. But where does your, where does the HVM manager live?
Is that something in, in central. Okay. HVM manager think about this similar to the, uh, kind of the alternative, you look at a vCenter and other things.
Okay? It could be a standardized OVA as a vm or you can live in the cloud. If you want to do a kind of a more cloud management model in both model, this can actually work.
And, and is it something that it, I mean it's configurable or is it something that's just making sure it's standard across the board? It's configurable and then it's basically, uh, something you instant and you can customize for environment. Okay.
And so would it be in, in central that you would do that? It will have the integration with a FC down the road central, and that's the model. You kind of keep it, the idea is basically keep a domain specific thing?
Mm-hmm. The HVM manager is mainly focusing on managing the whole VM environment. Got it.
Last one. Um, is there any relation here to like your, your colorless ports, any, any similarities from, uh, I know it's virtual versus physical. Mm-hmm.
But you've mentioned micro SAG a couple times that I'm curious if there's any, any similarities there is that, It's basically based on the workload you can think of as a server workload. If you assign, for example, on the virtualized world, you have the VM tag, right? Mm-hmm.
That's more like the color on the client side. Yeah. Yeah.
So the policy can be enforced based on that, and that's supported today. Okay. Yep.
Thank you. So finally, this is my last slide by putting everything together, right? So what we're really introducing is basically, okay, if we only talk about a new platform in the networking today, right?
A new switches that it's not really that interesting. You really need to help solve customer solving a end-to-end problem with a lot of customer being concerned about the current prevailing hypervisor, increasing their subscription model. A lot of customer has been thinking, and a lot of vendor has been talking about this, right?
HP really it's in a very unique situation because we offer compute storage networking together. And also we have been well known for putting solution together on top of all the platform we're selling into an integrated end-to-end view, right? So through the combination of the morphs VM essential plus the, uh, the CX 10,000 product family, we are really creating a unique position that we want to share with you that, okay, now you are not looking only at the software specific solution for virtual networking.
It's a holistic view. Looking at end-to-end where the problem space is and then really try to solve it. And to simplify the process, the only thing user need to do is really by inserting a simple software plugin onto the HU VM manager, the HU VM manager.
Now start talking with the, uh, the switches side, basically help you programming, orchestrate all the VLAN together. And then if the user prefer to manage everything from the hypervisor manager perspective, this give you the model. So the typically at the customer side, you have kind of the server hypervisor administration that actually operate from their side, right?
So every visibility is basically presented to the h VM manager. So then that way you can manage, orchestrate together, either a VMware environment, HVM, uh, environment today, and then on the policy side, later down the road, we're gonna enhance the networking platform basically to show that part as well.