Contrail SD-WAN Deep Dive Part 3: Why Contrail Lost the Enterprise, and the Pivot to Session Smart
Part 1 covered CSO’s orchestration architecture. Part 2 went deep on the E-Hub/P-Hub routing model. This post closes the loop: what that architecture cost Juniper competitively, and why the company made the specific, fast pivot it did.
The comparison that mattered
By the time CSO reached the market in earnest around 2017–2018, three purpose-built SD-WAN companies already had multi-year head starts and, in two cases, new corporate parents with deep enterprise sales motions behind them: Cisco had closed its acquisition of Viptela in 2017, VMware had closed VeloCloud the same year, and CloudGenix (acquired by Palo Alto in 2020) was independently building the application-defined pitch that the Prisma SD-WAN series on this site covers in detail. All three were purpose-built from day one for the exact problem an enterprise network manager actually had: replace expensive MPLS with a cheaper, smarter overlay, orchestrated from one simple, centralized console.
CSO’s pitch was adjacent to that but not identical to it. It could do enterprise SD-WAN — plenty of organizations ran it that way — but its control plane, data model, and even its most natural deployment topology (hub-and-spoke through a shared, VRF-segmented provider hub) were built first for a service-provider audience managing many tenants, with single-enterprise dynamic-mesh deployment as the secondary path rather than the primary one. That’s not a flaw in isolation. It’s a mismatch against a market that had, by 2018, converged hard on “simple, fast, enterprise-first” as the winning formula.
Three specific costs of the mismatch
Time to competence. Part 2 walked through why the E-Hub/P-Hub model asked a design engineer to reason in VRF-based, service-provider routing terms. Viptela’s OMP-centralized model and VeloCloud’s business-policy abstraction both asked for less prior context to get productive with. In a market where competing vendors were actively selling “your existing team can run this,” a steeper on-ramp is a real, if quiet, competitive disadvantage.
Positioning confusion. A platform genuinely excellent for MSPs running multi-tenant SD-WAN-as-a-service was also being pitched, in parallel, at enterprises who didn’t need any of that multi-tenancy machinery. Selling the same product credibly into two audiences with meaningfully different requirements is hard even for vendors with much larger enterprise sales organizations than Juniper had built for this specific product line at the time.
Overhead inherited from NFV orchestration. Contrail Networking’s control plane was built to manage the full lifecycle of virtualized network functions across data-centre and telco-cloud infrastructure — a genuinely harder problem than “keep an SD-WAN overlay up between branch offices.” Carrying that orchestration depth into every CSO deployment, including the enterprise ones that never touched most of it, is architectural overhead that a purpose-built SD-WAN control plane like OMP or VeloCloud’s simply didn’t carry.
The pivot, read as a rationale rather than a timeline
The history post that opened this series laid out the acquisition sequence: Mist Systems in 2019, Netrounds and 128 Technology in 2020, Apstra closing out the same year. Juniper’s own public language around the 128 Technology deal is worth reading closely, because it states the rationale plainly rather than leaving it to inference — the acquisition was framed as accelerating the transformation “from network-centric SD-WANs to user-centric AI-driven WANs.” Set next to everything in Parts 1 and 2, that phrase reads as a direct, if diplomatic, verdict on Contrail’s own model: network-centric, VRF-and-tunnel-based, service-provider-shaped — exactly the profile a from-scratch, session-aware, tunnel-free architecture was built to replace.
128 Technology’s Session Smart Router wasn’t a retrofit of Contrail’s control plane. It was an entirely different company’s from-scratch answer to the same problem, acquired outright and then integrated into Juniper’s broader AI-native networking push alongside Mist’s cloud management and machine-learning layer. That’s a materially bigger commitment than an incremental product update — it’s Juniper conceding that the fastest path to competitiveness wasn’t fixing what it had, but buying something built differently from the ground up.
What carries forward, and what doesn’t
Nothing about VRF-based multi-tenancy, hub-and-spoke topology, or IPsec overlay tunnels survives into the Session Smart architecture in any direct sense — the next series on this site covers a genuinely different set of primitives: Secure Vector Routing, session-based tenant and service policy, and a tunnel-free data plane. What does carry forward is the lesson CSO’s decade in market leaves behind: an architecture built for one audience’s requirements, however technically sound, doesn’t automatically transfer to a different audience’s requirements just because the branding says “SD-WAN” on both boxes. Juniper’s answer, in the end, wasn’t to keep explaining that mismatch to customers — it was to acquire a company that had never made it in the first place.
The next series on this site starts exactly there: an eight-part deep dive into Session Smart Routing, covering the same depth already given to Fortinet, Cisco/Viptela, Arista/VeloCloud, and Palo Alto/Prisma SD-WAN.