From Contrail to Session Smart: A History of Juniper's SD-WAN Journey
Every other vendor on this site got one SD-WAN origin story. Fortinet built SD-WAN into a firewall it already sold. Viptela and VeloCloud were purpose-built SD-WAN startups. CloudGenix bet on an application-defined abstraction from day one. Juniper is the one vendor here that shipped a full SD-WAN product, largely lost the enterprise with it, and then bought its way to a second, architecturally unrelated one. Understanding Juniper SD-WAN today means understanding both acts, because the market position, the terminology, and even some of the still-shipping hardware carry the scar tissue of the first attempt.
Act one: Contrail, built for a different problem
Juniper acquired Contrail Systems in December 2012. Contrail wasn’t an SD-WAN company — it was an SDN controller for OpenStack-based clouds, built to automate overlay networking (VXLAN-style tunnels, virtual routing and forwarding) inside a data centre or a telco’s NFV infrastructure. Juniper later open-sourced the core as OpenContrail, which lives on today as Tungsten Fabric under the Linux Foundation. That lineage matters: Contrail’s data model was built to orchestrate multi-tenant virtual networks for service providers, not to steer a branch office’s internet and MPLS circuits.
Contrail Service Orchestration (CSO), the product that eventually became Juniper’s SD-WAN play, was layered on top of that same Contrail Networking control plane and launched into the market around 2017–2018 — several years behind Viptela (2012), VeloCloud (2012), and CloudGenix (2013), all of which are covered in more depth in the earlier history post on this site. CSO ran the SD-WAN service lifecycle — zero-touch provisioning, policy, monitoring — across two device families: the SRX Series (Juniper’s existing next-generation firewall line, repurposed as SD-WAN CPE) and the NFX Series (a purpose-built “universal CPE” box designed to run virtualized network functions at the branch). It supported both a dynamic-mesh topology and a hub-and-spoke one built around two distinct hub device roles — an architecture detailed in the next two posts in this series.
CSO’s target customer, in practice, skewed heavily toward managed service providers. The multitenancy model — VRF-based segmentation through a shared provider hub device — reads like exactly what it was: SDN/NFV orchestration DNA repurposed for a service-provider SD-WAN offer, with enterprise self-managed deployments supported but clearly the secondary use case. That’s a defensible product decision, but it put Juniper in a different lane from Viptela and VeloCloud, who were selling directly into enterprise IT from the outset and iterating fast on the specific pain points — DIA breakout, app-aware routing, simple centralized policy — that made SD-WAN an easy sell to a network manager tired of MPLS pricing.
The market moved past it
By 2018–2019, the enterprise SD-WAN market had a clear leaderboard, and Juniper wasn’t near the top of it. Cisco had bought Viptela in 2017. VMware had bought VeloCloud in 2017. Palo Alto would buy CloudGenix in 2020. Fortinet, Cisco (Meraki), and a handful of others were converging fast on the “enterprise buys one platform, gets SD-WAN plus security plus centralized management” pitch. CSO, built on a control plane designed for a different job, carried more operational complexity than the market wanted for straightforward site connectivity, and Juniper’s own commentary through this period acknowledged the company had struggled to find enterprise traction with it.
Rather than continue investing in retrofitting Contrail’s architecture for a use case it wasn’t originally built for, Juniper made a different call: acquire its way into a second, purpose-built enterprise SD-WAN stack, and treat it as the successor rather than a variant.
Act two: four acquisitions in twenty months
The pivot ran through a specific, fast sequence of deals:
- Mist Systems — March 2019, $405 million. An AI-driven enterprise Wi-Fi company, notable for building a genuine machine-learning layer (Marvis) over wireless telemetry rather than bolting analytics onto an existing controller. Mist became the cloud management plane Juniper would eventually put everything else behind.
- Netrounds — September 2020. A WAN automation and active-testing company, folded in for service-assurance and synthetic testing capability.
- 128 Technology — October 2020, $450 million. The acquisition that mattered most for SD-WAN specifically. 128T’s Session Smart Router used a genuinely different approach — Secure Vector Routing (SVR) — that routes by session rather than by tunnel, with no IPsec/GRE encapsulation overhead. Juniper’s own announcement framed the deal explicitly as accelerating “the industry transformation from network-centric SD-WANs to user-centric AI-driven WANs” — language that draws a direct, if diplomatic, line under Contrail’s network-centric model.
- Apstra — December 2020, price undisclosed. A data-centre intent-based automation company, not itself an SD-WAN product, but part of the same strategic bet on AI-native, intent-driven operations across the whole Juniper portfolio.
The plan that emerged from these four deals was to fold the Session Smart Router into Juniper’s AI-native networking story, managed either through an on-premises Session Smart Conductor or through the same Mist cloud that already ran WAN Assurance for wireless and wired estates — one dashboard, one AI operations layer (Marvis), across access and WAN. That product, not CSO, is what Juniper now sells as its primary enterprise SD-WAN platform.
What happened to Contrail
Contrail Service Orchestration didn’t vanish overnight, and existing CSO estates didn’t get ripped out — but it stopped being the product Juniper leads with for enterprise SD-WAN, and new deployments have shifted to Session Smart. The underlying Contrail Networking control plane lives on in its original habitat: NFV and telco cloud infrastructure, now largely carried forward as open-source Tungsten Fabric, decoupled from the enterprise SD-WAN story it was drafted into for a few years.
There’s a coda to this history worth noting for anyone reading Juniper documentation today: HPE completed its acquisition of Juniper Networks in 2025, and current Juniper collateral — including the Session Smart and Mist documentation referenced throughout this series — is now published under the “HPE Juniper Networking” banner. The SD-WAN architecture and terminology are unchanged by that; it’s an ownership change layered on top of a product story that had already fully turned over once already.
Where this series goes next
The next two posts stay with the first act: a proper architecture walkthrough of Contrail Service Orchestration, followed by a deep dive into the hub-and-spoke routing model — specifically the enterprise hub and provider hub device roles this site’s readers will know informally as E-Hub and P-Hub — and why that model became a genuine operational burden at scale. From there, the series moves to the current product: an eight-part deep dive on Session Smart Routing matching the depth already given to Fortinet, Cisco/Viptela, Arista/VeloCloud, and Palo Alto/Prisma on this site — architecture, control planes, security model, cloud onramp, a cutover playbook, and a closing five-way comparison.