Hardware Guides
These hardware guides are for the Pluribus Networks Freedom Series set of switches. You can find Dell EMC hardware guides here and Edgecore hardware guides here.
| Quick Start Guide | |
|---|---|
| F9460-T Quick Start Guide | . |
| F9432-C Quick Start Guide | . |
| F9480-V Quick Start Guide | . |
| F9460-X Quick Start Guide | . |
| F9372-X Quick Start Guide | . |
| F9532L-C Quick Start Guide | . |
| F9572L-V Quick Start Guide | . |
| F9664-C Quick Start Guide | . |
Transceiver Compatibility Information
These compatibility reference guides indicate which transceivers have been tested and qualified with the respective hardware platforms that run Netvisor ONE OS: Freedom Series, Edgecore and Dell EMC Open Networking Switches.
| Reference Guide | HTML | |
|---|---|---|
| Transceiver Compatibility Matrix for Freedom and Edgecore Switches | . | . |
| Transceiver Compatibility Matrix for Dell Switches | . | . |
Pluribus Networks Technical Documentation
This page contains online documentation for Pluribus Networks products now: Arista NetVisor OS, Arista NetVisor UNUM, and Insight Analytics™ releases. To access documentation for earlier software versions or products not listed, log in to the Customer Portal.
| Arista NetVisor UNUM Documentation | Version 6.3.3 > |
|---|---|
| Arista NetVisor OS Documentation | Version 7.0.2 > Version 6.1.1 > Version 5.2.1 > |
| Hardware Guides | Hardware Guides > |
| Transceiver Compatibility Information | Transceiver Compatibility Information > |
Arista NetVisor UNUM Management Platform and Insight Analytics Technical Documentation
Arista NetVisor UNUM is an agile, multi-functional web management portal that enhances the intrinsic automation of the Unified Cloud Fabric architecture. It combines an elastic big data database and intelligent analytics engine with an intuitive and consistent user interface that allows seamless navigation across fully integrated management and analysis modules.
Arista NetVisor UNUM 6.3.3 Software
| Reference Material | HTML | |
|---|---|---|
| NetVisor UNUM 6.3.3 Setup and User Guide Step-by-step details on installing NetVisor UNUM and configuring Insight Analytics. |
. | – |
| NetVisor UNUM 6.3.3 Appliance User Guides The User Guides provide comprehensive information about installing your NetVisor UNUM appliances. |
||
| NetVisor UNUM High Capacity User Guide | . | . |
| NetVisor UNUM Medium Capacity User Guide | . | . |
|
NetVisor UNUM 6.3.3 Release Notes |
||
Arista NetVisor OS Technical Documentation
Arista NetVisor OS 7.0.2 Software is downloaded to your open networking switch and then enabled with license keys. The documents below will help you install and operate the NetVisor OS.
Arista NetVisor OS 7.0.2 Software
| Reference Material | HTML | |
|---|---|---|
| NetVisor OS 7.0.2 Installation and Software Setup Guide Step-by-step details for installing Netvisor OS on an open networking switch and preparing the device for configuration, provisioning and production use. |
. | . |
| NetVisor OS Installation and Software Setup Guide for Dell Z9432F-ON Platforms | – | . |
| Configuration Guide 7.0.2 provides information about configuring NetVisor OS, including ports, VLANs, vRouters and vFlows. |
. | . |
| Command Reference 7.0.2 The Command Reference provides an encyclopedia of all commands, A-Z, in the NetVisor OS CLI. |
. | . |
| NetVisor OS Log Messages Guide 7.0.2 The NetVisor OS Log Messages Guide provides information about all messages, systems, events and audits, with severity levels, in PDF and HTML format. |
. | . |
| NetVisor OS Troubleshooting Guide 7.0.2 Provides simple steps to perform troubleshooting for NetVisor OS. |
. | – |
| NetVisor OS OpenStack ML2 Plugin Deployment Guide 7.0.2 The OpenStack ML2 Plugin Deployment Guide explains how to install the NetVisor OS ML2 plugin into an OpenStack environment and use it to configure layer 2 networks in the Unified Cloud Fabric. |
. | . |
| NetVisor OS Virtual Netvisor Deployment Guide 7.0.2 Provides simple steps to deploying Netvisor OS virtual configuration on a network. |
. | . |
| Complete NetVisor OS RESTful API Guide 7.0.2 Provides a complete listing of all RESTful APIs in NetVisor OS software. |
. | . |
|
NetVisor OS Release Notes 7.0.2 |
||
Netvisor ONE 6.1.1 Software
| Reference Material | HTML | |
|---|---|---|
| Getting Started Guide 6.1.1 Step-by-step details for installing Netvisor ONE on an open networking switch and preparing the device for configuration, provisioning and production use. |
. | . |
| Configuration Guide 6.1.1 The Configuration Guide provides information about configuring Netvisor ONE, including ports, VLANs, vRouters and vFlows. |
. | . |
| Command Reference 6.1.1 The Command References provide an encyclopedia of all commands, A-Z, in the Netvisor ONE CLI |
. | . |
| Netvisor ONE Log Messages Guide 6.1.1 The Netvisor ONE Log Messages Guide provides information about all messages, systems, events and audits, with severity levels, in PDF and HTML format. |
. | . |
| Troubleshooting Guide 6.1.1 Provides simple steps to perform troubleshooting for Netvisor ONE OS. |
. | – |
| Pluribus OpenStack ML2 Plugin Deployment Guide 6.1.1 The OpenStack ML2 Plugin Deployment Guide explains how to install the Pluribus ML2 plugin into an OpenStack environment and use it to configure layer 2 networks in the Adaptive Cloud Fabric. |
. | . |
| Virtual Netvisor Deployment Guide 6.1.1 Provides simple steps to deploying Netvisor ONE virtual configuration on a network. |
. | . |
| Complete RESTful API Guide 6.1.1 Provides a complete listing of all RESTful APIs in Netvisor ONE software. |
. | . |
|
Netvisor ONE Release Notes 6.1.1 |
||
Netvisor ONE 5.2.1 Software
| Reference Material | HTML | |
|---|---|---|
| Getting Started Guide 5.2.1 Step-by-step details for installing Netvisor ONE on an open networking switch and preparing the device for configuration, provisioning and production use. |
. | . |
| Configuration Guide 5.2.1 The Configuration Guide provides information about configuring Netvisor ONE, including ports, VLANs, vRouters and vFlows. |
. | . |
| Command Reference 5.2.1 (A-O) The Command References provide an encyclopedia of all commands, A-O in the Netvisor ONE CLI. |
. | . |
| Command Reference 5.2.1 (P-Z) The Command References provide an encyclopedia of all commands, P-Z in the Netvisor ONE CLI. |
. | . |
| Netvisor ONE Log Messages Guide 5.2.1 The Netvisor ONE Log Messages Guide provides information about all messages, systems, events and audits, with severity levels, in PDF and HTML format. |
. | . |
| Troubleshooting and Data Collection Guide 5.2.1 Provides simple steps to perform troubleshooting for Netvisor ONE OS. |
– | . |
| Pluribus OpenStack ML2 Plugin Deployment Guide 5.2.1 The OpenStack ML2 Plugin Deployment Guide explains how to install the Pluribus ML2 plugin into an OpenStack environment and use it to configure layer 2 networks in the Adaptive Cloud Fabric. |
. | . |
| Virtual Netvisor Deployment Guide 5.2.1 Provides simple steps to deploying Netvisor ONE virtual configuration on a network. |
. | . |
| Complete RESTful API Guide 5.2.1 Provides a complete listing of all RESTful APIs in Netvisor ONE software. |
. | . |
|
Netvisor ONE Release Notes 5.2.1 |
||
The following material provides practical advice to assist in the safe and smooth installation of Arista 7800 Series devices. It should be followed in parallel with the 7800 Quick Start Guide and Safety and Compliance Guide.
It is strongly recommended that all material is reviewed and that all instructions are closely followed to avoid unnecessary damage which will impact installation schedules and system availability.
Offline Installation Training Materials
Using the PDF viewer toolbar, click the "Save / Download" icon to download PDF training materials. For videos, right-click inside the player and choose "Save Video As / Download Video As" from the menu or you can download the full . 7800 Installation training materials.
- .78-0101-02 7800 Series Installation - Recommended Tools and Equipment
- .78-0102-02 7800 Series Unpacking and Rack Mounting 7804_7808 Systems
- .78-0103-00 7800 Series Unpacking and Rack Mounting 7812
- .78-0104-00 7800 Series Unpacking and Rack Mounting 7816
- .78-0105-00 7800 Series Unpacking and Rack Mounting 7816L
- .78-0106-00 Reseating 7800 Fabric Modules
- .78-0107-01 7816 De-palletizing and Transporting by Forklift
Portions of Arista Networks software are covered by open-source licenses including the GNU General Public License . Please find below the list of source files:
- Wi-Fi WM 21.2.0
- .Wi-Fi AP 21.2.0F 33 Source
- .Wi-Fi AP 21.2.0F 33 Licenses
- .Wi-Fi WM 21.2.0F 57 Source
- Wi-Fi WM 21.1.0
- .Wi-Fi AP 21.1.0F 94 Source
- .Wi-Fi AP 21.1.0F 94 Licenses
- .Wi-Fi WM 21.1.0F 94 Source
- Wi-Fi WM 21.0.0
- .Wi-Fi AP 21.0.0 103 Source
- .Wi-Fi AP 21.0.0 103 Licenses
- .Wi-Fi WM 21.0.0 103 Source
- Wi-Fi WM 20.0.0
- .Wi-Fi AP 20.0.0 179 Source
- .Wi-Fi AP 20.0.0 179 Licenses
- .Wi-Fi WM 20.0.0 179 Source
- Wi-Fi WM 19.1.0
- .Wi-Fi AP 19.1.0 4 Source
- .Wi-Fi AP 19.1.0 4 Licenses
- .Wi-Fi WM 19.1.0 4 Source
- Wi-Fi WM 19.0.0
- .Wi-Fi AP 19.0.0 183 Source
- .Wi-Fi AP 19.0.0 183 Licenses
- .Wi-Fi WM 19.0.0 206 Source
- Wi-Fi WM 18.0.0
- .Wi-Fi AP 18.0.0 176 Source
- .Wi-Fi AP 18.0.0 176 Licenses
- .Wi-Fi WM 18.0.0 176 Source
- Wi-Fi WM 17.1.0
- .Wi-Fi AP 17.1.0 57 Source
- .Wi-Fi AP 17.1.0 57 Licenses
- .Wi-Fi WM 17.1.0 57 Source
- Wi-Fi WM 17.0.0
- .Wi-Fi AP 17.0.0 236 Source
- .Wi-Fi AP 17.0.0 236 Licenses
- .Wi-Fi WM 17.0.0 236 Source
- Wi-Fi WM 16.1.0
- .Wi-Fi AP 16.1.0 51 Source
- .Wi-Fi AP 16.1.0 51 Licenses
- .Wi-Fi WM 16.1.0 51 Source
- Wi-Fi WM 16.0.0
- .Wi-Fi AP 16.0.0 214 Source
- .Wi-Fi AP 16.0.0 214 Licenses
- .Wi-Fi WM 16.0.0 214 Source
- Wi-Fi WM 15.0.1
- .Wi-Fi AP 15.0.1 22 Source
- .Wi-Fi AP 15.0.1 22 Licenses
- .Wi-Fi WM 15.0.1 22 Source
- Wi-Fi WM 15.0.0
- .Wi-Fi AP 15.0.0 114 Source
- .Wi-Fi AP 15.0.0 114 Licenses
- .Wi-Fi WM 15.0.0 114 Source
- Wi-Fi WM 14.0.0
- .Wi-Fi WM 14.0.0 35 Source
- Wi-Fi WM 13.0.2
- .Wi-Fi AP 13.0.2 28 Source
- .Wi-Fi AP 13.0.2 28 Licenses
- Wi-Fi WM 13.0.1
- .Wi-Fi AP 13.0.1 83 Source
- .Wi-Fi AP 13.0.1 83 Licenses
- .Wi-Fi WM 13.0.1 83 Source
- Wi-Fi WM 13.0.0
- .Wi-Fi AP 13.0.0 67 Source
- .Wi-Fi AP 13.0.0 67 Licenses
- .Wi-Fi WM 13.0.0 67 Source
- Wi-Fi WM 12.0.1
- .Wi-Fi AP 12.0.1 48 Source
- .Wi-Fi AP 12.0.1 48 Licenses
- .Wi-Fi WM 12.0.1 48 Source
- Wi-Fi WM 12.0.0
- .Wi-Fi AP 12.0.0 162 Source
- .Wi-Fi AP 12.0.0 162 Licenses
- .Wi-Fi WM 12.0.0 162 Source
PURPOSE
The purpose of this Anti-Counterfeit Policy (this “Policy”) is to define actions to be taken by Arista Networks (“Arista”) for the avoidance of the introduction of counterfeit materials into the supply chain for its finished products. This Policy also addresses measures that are taken to avoid the sale of counterfeit Arista products into the marketplace.
SCOPE
This Policy covers items acquired by Arista either directly or through its contract manufacturers. It applies to the parts and components that comprise Arista’s end-products.
STATEMENT OF POLICY
Arista will not knowingly, and shall take all reasonable steps to ensure that it will not, procure, use, or supply any counterfeit item or material. Arista shall implement certain procedures as detailed below to manage the risk of counterfeit material in the supply chain. All Arista staff shall follow this Policy and associated anti-counterfeit management plans and promote awareness of the issues concerning counterfeit material in Arista’s supply chain.
ARRANGEMENTS FOR MANAGEMENT OF RISK
Arista shall mitigate the risk of acquiring counterfeit material by undertaking the following steps:
Approved Supplier List - Arista provides its contract manufacturers with a list of preferred suppliers that it has prescreened for quality and security purposes (the “Approved Supplier List”) and requires its contract manufactured to purchase all parts and components from vendors on this list.
Assessment – of likelihood and criticality of encountering counterfeit materiel in the supply chain for a particular product, part, or application; taking into account the criticality of the material in relation to performance and safety and the geo-political region from which it is sourced.
Avoidance – through application of Arista’s supplier selection process and Approved Supplier List, Arista will only acquire products and services from known, reputable and traceable sources. The business policy is to purchase directly from the original manufacturer whenever possible and to flow down the requirement to manage counterfeit material where risk is identified.
Certification – by requiring our contract manufacturers to certify on a regular basis that all purchases of parts, components and testing equipment is only from vendors on Arista’s Approved Supplier List.
Detection – by inspection of goods and materials, any new or potentially risk-bearing suppliers will have their supplied goods inspected. In addition, all goods inwards staff and technicians will be required to be vigilant for counterfeit material using their experience, training and awareness.
Elimination – any instances of counterfeit material will result in quarantine of the items and reporting of detected instances to the customer, industry, and the appropriate authorities. Counterfeit material will not be returned to the supplier. Instances of counterfeit material detection shall be communicated to the intellectual property right holder as known, the supplier, the customer if in receipt, relevant organizations, relevant authorities, including the Trading Standards Office if the occurrence is in the UK.
Testing - by requiring Arista’s contract manufacturers to test and verify suspected counterfeit material on a case-by-case basis commensurate with risk and criticality in relation to safety and performance and report all instances of counterfeit materials to Arista.
ROLES & RESPONSIBILITIES
This Policy will be maintained by Arista’s Vice President of Manufacturing or such other person as Arista’s Chief Executive Officer may designate from time to time (“VPM”). The VPM shall ensure that the Policy is available, communicated, understood, and implemented by relevant staff members. The VPM has the responsibility and authority to ensure that the necessary measures required to manage the risk of counterfeit material in the supply chain are implemented and maintained by the company.
Any Arista Employee that becomes suspicious or aware of counterfeit parts or materials in the supply chain should report any concerns to the VPM and to Arista’s vendor quality alias (This email address is being protected from spambots. You need JavaScript enabled to view it.). Reports are tracked through Arista’s Line Alert Process (DOC-00553-01).
Arista’s contract manufacturers must test and verify suspected counterfeit material on a case-by-case basis commensurate with risk and criticality in relation to safety and performance. All instances of counterfeit materials must be reported to Arista.
COMPETENCE, TRAINING, AWARENESS & COMMUNICATION
All staff that are involved in the procurement, design or manufacturing process shall receive Anti Counterfeit Training that include this Policy and its implications for Arista. The training shall be compulsory and records of training shall be maintained. This Policy shall be available to all staff through publication on the Arista Intranet. This Policy shall be made available to third parties on request and published on the Company website (https://www.arista.com/en/support/product-documentation/policies)
ARISTA BRAND PROTECTION
Arista takes measures to avoid the misrepresentation of its material by others. These measures include, among other things:
- Arista applies unique serial numbers on all manufactured products.
- Arista utilizes unique trusted platform module (TPM) chips to deter counterfeiting of select hardware products.
- Arista actively enforces its registered trademarks against manufacturers and suppliers of counterfeit materials.
- Arista controls production, packaging, and documentation to avoid misrepresentation of its products in the supply chain.
- Arista controls the production processes to prevent the misappropriation of material or unauthorized production overruns
- Arista’s channel agreements strictly prohibit the sale or distribution of counterfeit Arista products by our partners.
APPENDIX A: Standards Referenced In This Policy
- Defense Standard 05-135 Avoidance of Counterfeit Materiel
Introduction
Arista modular platforms such as the 750, 7300, 7500 and 7800 families support mixed generations of line cards, fabric cards, supervisors and power supplies (referred to in this document as “modules”). A-Care is applied to the entire chassis, rather than specific modules within the chassis. This can lead to inadequate support coverage and deployed devices that contain components that are End of Support.
This document explains how to update A-Care coverage through the lifecycle of a modular platform that includes mixed generations of modules.
A-Care Entitlement Policy for Modular Products
The level of support for a modular platform is defined by the generation of the switch fabric or switch card and therefore A-Care coverage must be updated to reflect the correct switch fabric or switch card as part of the next renewal. Line cards, supervisor modules and power supplies are not considered when choosing the correct level of A-Care for a modular system.
For example, a 7500 series product with E series switch fabrics requires A-Care coverage for E series systems while the same 7500 series product with R3 series switch fabrics requires A-Care coverage for R3 systems.
If, in month 30 of a 36 month A-Care term, a 7500E is updated with R3 series switch fabric cards and therefore becomes an R3 series system, the existing A-Care coverage will remain valid until the A-Care renewal date but future A-Care coverage must be changed to the R3 coverage level instead of E series A-Care plans.
Documenting Component Upgrades to Ensure RMA Support
Although A-Care coverage may continue, when changes are made to the installed base, up to date records must be provided to Arista TAC to ensure continuity of RMA coverage in the correct geographical locations for the newly upgraded systems.
End of Sale Components Are Not Supported
In a modular platform, it is possible that a system could contain both supported and End of Support components (for example a mixture of line cards from different generations). The purchased A-Care contract will provide coverage for all components except those that are End of Support.
v1.1 Updated January, 2021
This Policy Covers:
- MOS (Metamako Operating System)
- Supported 7130 Applications:
- SwitchApp
- MetaWatch
- MetaMux
- MultiAccess
- MetaProtect
- ExchangeApp
- JTAG App
Policy:
Arista Networks' MOS and 7130 Apps Software Release Policy and Life Cycle guidelines help customers and partners facilitate MOS migration and plan multi-year infrastructure deployment. Arista will support designated LTS (Long term support) MOS and 7130 application software releases for up to 24 months from the date of the first posting of the initial minor release. (See below for definition of minor release)
To assist customers in selecting the right software releases for their environments, Arista follows a strict policy as to when new features are introduced into versions of MOS and applications. The versioning scheme identifies if a particular release is integrating new feature functionality, or a maintenance release on the previously released version.
The version numbers are defined by X.Y.Z[{alpha|beta}A]. X is the major release number, Y is the minor release number, Z is the patch release number. The alpha/beta tag identifies development releases which should not be deployed to production environments.
New minor releases -- i.e. where Z is 0 -- contain new functionality. New patch releases -- i.e. where Z is non-zero -- are maintenance releases.
Examples:
- mos-0.26.0 -- A new minor release. Contains new functionality compared with previous versions.
- mos-0.26.1 -- A new patch release. Only contains conservative bug fixes, compared with 0.26.0.
- mos-0.27.0beta1 -- A new development release. Do not use this in production environments.
Bug fixes are introduced using patch releases -- i.e. an upgrade to the latest patch release for the minor release number will be required to receive new bugfixes for that train.
Development releases (alpha/beta) carry no support commitment, though feedback is always welcomed.
Arista applications use the same versioning scheme as MOS. For example:
- metamux-3.5.6
Certain minor releases may be designated as "LTS" (Long Term Support). These will be supported with patch releases for 24 months following initial release of the .0 image. The LTS status of releases will be indicated in the release's description on the 7130 software downloads site. Releases other than LTS releases have no specific support timeline.
TAC support will be available on all versions of MOS and apps for 30 months following release.
If you need assistance with MOS or 7130 application software migration options, please contact your Arista sales representative or contact us at This email address is being protected from spambots. You need JavaScript enabled to view it.
Arista Vulnerability Management Process
An organization's communications infrastructure and the tools that support it are critical to a business's ability to function. This importance also makes the infrastructure a high-value target for malicious actors seeking to gain entry deeper into the organization or to exfiltrate sensitive intellectual property. Arista Networks sees its role in security as a continuous process that begins at manufacturing and continues throughout the lifecycle of the product as vulnerabilities are detected, mitigated, and remediated.
This vulnerability management process encompasses several primary components: Secure Development Best Practices, Vulnerability Discovery, Mitigation and Remediation, and Vulnerability Communication. Product security must also be complemented through best practice configuration during the installation and operation of the infrastructure.

Arista Vulnerability Management Process
Secure Development Best Practices: A Secure-by-Design Philosophy
Both the design of new Arista features and the maintenance of our existing portfolio—including EOS®, DANZ Monitoring Fabric (DMF)™, CloudVision (CV)™, CloudVision CUE™, Enterprise Threat Management (ETM), Network Detection and Response (NDR), and VeloCloud—are driven by security as a foundational priority.
Arista ensures the inherent security of our products through a proactive, secure-by-design methodology. Rather than relying solely on post-development testing, our goal is to eliminate vulnerabilities before they ever see the light of day. We achieve this by combining memory-safe development with rigorous defensive programming, all reinforced by a culture of continuous vigilance.
- A Memory-Safe Technical Foundation: We eliminate entire classes of common vulnerabilities (such as buffer overflows and memory leaks) directly at the source code level:
- Memory-Safe Languages: The majority of our products are built using inherently memory-safe languages like Go, Java, and Python. For performance-critical components, we utilize a custom meta-language that combines the speed of C++ with the rigorous safety checks expected of a more secure language.
- Defensive Coding Practices: Our development pipeline mandates automated bounds checking on each operation, enforces safe initialization (defaulting pointers and data structures to safe, NULL values upon creation), and prevents resource leaks through safe memory operations, reference counting, and Valgrind analysis.
- Memory-Safe Languages: The majority of our products are built using inherently memory-safe languages like Go, Java, and Python. For performance-critical components, we utilize a custom meta-language that combines the speed of C++ with the rigorous safety checks expected of a more secure language.
- Resilient Execution & Architecture: Our software architecture is explicitly designed to prevent complex execution flaws and unauthorized data manipulation:
- Safe Concurrency: We eliminate race conditions and deadlocks by treating each program as a single thread of execution that communicates safely with other programs to share data, rather than sharing memory directly.
- Input Sanitization: To proactively neutralize the risk of malformed data injection, all internal and external APIs enforce strict, uncompromising input sanitization.
- Safe Concurrency: We eliminate race conditions and deadlocks by treating each program as a single thread of execution that communicates safely with other programs to share data, rather than sharing memory directly.
- Proactive Security Culture & Supply Chain Trust: The human element and the supply chain are critical to our secure development lifecycle:
- Continuous Threat Awareness: Our Product Security Incident Response Team (PSIRT) continuously monitors the threat landscape for emerging attack vectors, actively integrating these rising trends into company-wide engineering training.
- Empowered Engineers: Arista engineers receive ongoing, specialized training designed to help them architect inherently secure features and easily identify insecure design patterns during peer reviews.
- Strict Library Auditing: We proactively reduce supply chain risk by strictly limiting the usage of security-critical open-source software to highly audited, universally well-understood libraries.
- Continuous Threat Awareness: Our Product Security Incident Response Team (PSIRT) continuously monitors the threat landscape for emerging attack vectors, actively integrating these rising trends into company-wide engineering training.
Vulnerability Discovery - A Proactive and Prevention First Approach
Arista uses a multi-layered, proactive approach to detect emerging vulnerabilities across every major release. By combining advanced automation, artificial intelligence, and expert manual review, we ensure comprehensive coverage of our software supply chain and internal codebase.
- Automated Threat & Supply Chain Monitoring: Arista continuously scans for publicly disclosed vulnerabilities across our entire product portfolio using SBOM scanners, open-source review tools (nmap, static linters, dynamic memory analysis tools), and commercial scanners (Rapid7, Qualys, Tenable). This is heavily augmented by automated threat ingestion from the National Vulnerability Database (NVD) and close communication with third-party vendors.
- Frontier AI & Penetration Testing: Arista conducts traditional penetration testing utilizing both internal teams and external qualified third-party organizations for compliance, application, network, web, and red team testing. We act as an early adopter of advanced AI-driven security discovery. By leveraging frontier AI models (such as Anthropic and OpenAI), we utilize AI harnesses for advanced threat modeling, automated proof-of-concept testing, comprehensive assessment and continuous auditing to actively defend against autonomous zero-day vulnerabilities.
- Rigorous Manual Auditing & Architecture Review: Specialized PSIRT engineers and vetted outside consultants manually validate all automated scan results. These teams conduct ongoing, detailed reviews of design documentation, internal host configurations (boot loaders, kernels, networking stacks), and high-risk code—particularly functions that parse user input or handle external packets.
- Accurate Evaluation & Industry Alignment: When vulnerabilities are identified, Arista carefully evaluates them using CVSS v3.1/v4.0 scoring to reflect their actual impact in the context of Arista products. All security baselines are strictly aligned with industry standards, including official CIS Hardening Benchmarks and our living Arista EOS Hardening Guide.
Mitigation and Remediation: Flexible, Low-Impact Patching
When a security vulnerability is identified, traditional network OS upgrades often force disruptive system reboots and significant downtime. To give customers maximum flexibility and immediate protection, Arista provides a staged remediation strategy designed to secure environments rapidly while minimizing operational impact.
- Rapid Risk Reduction via Configuration Mitigation: As an immediate first line of defense, Arista prioritizes providing clear, highly effective configuration changes whenever possible to mitigate the risk of an active vulnerability. These documented workarounds allow customers to swiftly secure their environments—such as by altering access controls or temporarily disabling an affected service—blocking the attack vector while teams evaluate patch deployment strategies.
- Targeted Patching via Hotfixes: For many vulnerabilities, Arista can provide a targeted hotfix rather than requiring a full OS upgrade. Delivered as an extension, a hotfix installs directly onto a running system to patch the specific vulnerable component without forcing a system-wide reboot.
- Real-World Example: If a publicly disclosed CVE impacts the SSH Server, Arista can release a hotfix to resolve it. Upon installation, only the SSH service restarts—causing less than a second of service-specific downtime. All other switch services, routing protocols, and traffic forwarding remain completely unaffected.
- The Advantage: Hotfixes provide immediate remediation that persists across switch reboots. This allows our customers to secure the device instantly and defer a full OS upgrade to a regularly scheduled maintenance window.
- Real-World Example: If a publicly disclosed CVE impacts the SSH Server, Arista can release a hotfix to resolve it. Upon installation, only the SSH service restarts—causing less than a second of service-specific downtime. All other switch services, routing protocols, and traffic forwarding remain completely unaffected.
- Seamless OS Updates via Smart System Upgrade (SSU) For vulnerabilities that do require a complete OS update, Arista eliminates the friction of traditional upgrades using our Smart System Upgrade (SSU)—an advanced In-Service Software Upgrade (ISSU) capability built into Arista EOS. Learn more at EOS: Smart System Upgrade.
- How it works: SSU allows the switch to reload its entire operating system with less than one second of data-plane downtime.
- The Advantage: Because SSU performs the upgrade without resetting the forwarding ASIC, single-homed and active connections remain alive. This provides an ability to apply comprehensive OS-level remediation and load the newest, fully patched image without dropping critical traffic or triggering broader network topology recalculations.
- How it works: SSU allows the switch to reload its entire operating system with less than one second of data-plane downtime.
- Our Remediation Philosophy When it comes to engineering resource allocation, Arista operates under a strict mandate: securing our customers is our absolute highest priority. The development, testing, and delivery of fixes for security vulnerabilities will always take precedence over new product enhancements or feature upgrades. We are committed to ensuring our customers have the patches they need, as quickly as possible, without compromise.
Communication: Transparent Disclosure
To help our customers keep pace with the rapid rate of modern vulnerability discovery, Arista prioritizes transparent, flexible, and proactive communication. We provide the critical information required for effective risk management through a variety of delivery options and release schedules tailored to the urgency of the threat.
- Flexible Advisory Release Strategies: Arista utilizes two distinct timelines for releasing security advisories, ensuring that our communication matches the operational needs of our customers:
- Scheduled Grouped Releases (Predictable): To coordinate communications and streamline patching efforts, Arista publishes routine advisories on a predictable, regular release schedule. When a larger volume of advisories is scheduled, we consolidate them into a single bulk publication and issue a 1-week advance public notification. This courtesy notice allows organizations to strategize and allocate resources before the technical details are published.
- Time-Sensitive Releases (Immediate): For critical, externally disclosed, or actively exploited vulnerabilities, Arista bypasses the scheduled cycle. These advisories are published immediately as time-sensitive releases without advance notice, ensuring our customers have the information needed to protect an environment instantly.
- Scheduled Grouped Releases (Predictable): To coordinate communications and streamline patching efforts, Arista publishes routine advisories on a predictable, regular release schedule. When a larger volume of advisories is scheduled, we consolidate them into a single bulk publication and issue a 1-week advance public notification. This courtesy notice allows organizations to strategize and allocate resources before the technical details are published.
- Standardized, Actionable Content: When Arista publishes an advisory, our goal is to provide a complete risk management package rather than just a vulnerability notification.
- Comprehensive Solutions: Every advisory includes actionable remediation paths. While a full software image upgrade is always provided, we also strive to include recommended configuration mitigations and targeted software hotfixes depending on the vulnerability.
- MITRE CVE Tracking: Arista strictly follows industry best practices by assigning official CVEs via MITRE to all security issues. This ensures our vulnerabilities can be easily and accurately tracked across most internal security scanners, third-party advisories, and compliance management procedures.
- Comprehensive Solutions: Every advisory includes actionable remediation paths. While a full software image upgrade is always provided, we also strive to include recommended configuration mitigations and targeted software hotfixes depending on the vulnerability.
- Proactive Delivery & Automation: We offer multiple channels for vulnerability disclosure, allowing our customers to consume security data in the way that best fits individual operational workflows:
- Public Portal & Push Notifications: All security vulnerabilities and their associated solutions are documented publicly on the Arista Advisories and Notices page. Customers can also opt into proactive alerts via email updates and RSS feeds.
- Automated Evaluation via CloudVision AlertBase: For customers utilizing CloudVision, AlertBase automatically ingests updates about new security advisories and proactively evaluates the vulnerability status of all EOS devices managed by that instance. This speeds up the remediation process and transforms manual advisory reading into automated fleet auditing.
- Public Portal & Push Notifications: All security vulnerabilities and their associated solutions are documented publicly on the Arista Advisories and Notices page. Customers can also opt into proactive alerts via email updates and RSS feeds.
Summary
Arista goes to great lengths to ensure the ongoing security of its products and rapid mitigation of emerging threats, following industry best practices and leveraging close relationships with suppliers. The effectiveness of these robust processes is demonstrated by extremely limited exposure to common security issues as well as rapid and usually impact-free solutions for remediation. Arista customers following our recommended hardening steps can be confident that they have deployed the industry's leading secure networking solutions.
Subcategories
Field Notices
Field Notices
This page aggregates the Arista hardware and software product field notices. For further information on Arista’s hardware and software support policies, please see product documentation.
Security Advisories
Security Advisories
Arista Networks is committed to maintaining the highest standards of security across our product portfolio. Leveraging extensive testing and monitoring of vulnerabilities to isolate and neutralize threats early, Arista's Product Security Incident Response Team (PSIRT) provides global coverage for public reporting of possible security vulnerabilities across the product portfolio.
The PSIRT team monitors industry-wide vulnerability reporting as well as providing a single point of contact for customers and interested third parties to investigate and identify potential threats. The PSIRT team also works to communicate these issues back to the user community in a timely manner.
Arista's approach to vulnerability management and links to best practice guidelines can be found here.
For technical assistance with workarounds and hotfix installations recommended in security advisories, please contact the Arista Support team at This email address is being protected from spambots. You need JavaScript enabled to view it..
Report security vulnerabilities found in Arista products to the PSIRT team via This email address is being protected from spambots. You need JavaScript enabled to view it.. It is recommended to use Arista's PGP key for secure and private communication directly with the PSIRT team.
Arista PSIRT is happy to work with researchers on discovered vulnerabilities in Arista products, the assignment of CVEs, and timelines for responsible disclosure. If a researcher discovers a new vulnerability they will be acknowledged in the advisory related to the vulnerability. Arista PSIRT is interested in receiving reports on issues affecting features in both Arista code as well as Open Source Software used in Arista products. Security issues found in Open Source Software which do not affect Arista products are out of the scope of Arista and should be referred to the appropriate CNA found here.
PSIRT Advisories
The following advisories and referenced materials are provided on an "as is" basis for use at your own risk. Arista Networks reserves the right to change or update the advisories without notice at any time.
End of Sale
End of Sale
This page aggregates hardware end of sale notices. Arista offers a five year end of sales lifecycle for most products. Selected products and legacy systems have a three year lifecycle. For further information on Arista’s hardware support policies see the Three Year End of Life Policy or Five Year End of Life Policy. Detailed product policy information may be found here.
The Product Lifecycle Tool can be used to find detailed information about Arista products.
End of Software Support
End of Software Support
This page aggregates end of software support notices. Detailed information on the lifecycle of each software component may be found here.
The Product Lifecycle Tool can be used to find detailed information about Arista products.
