{"id":1023,"date":"2020-02-06T14:57:24","date_gmt":"2020-02-06T10:57:24","guid":{"rendered":"https:\/\/www.techxmedia.com\/?p=1023"},"modified":"2025-04-17T23:59:22","modified_gmt":"2025-04-17T19:59:22","slug":"sd-wan-network-security-functionality","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/sd-wan-network-security-functionality\/","title":{"rendered":"SD-WAN needs to integrate network and security functionality"},"content":{"rendered":"\n<p>By Alain Penel, Regional Vice President \u2013 Middle East,\nFortinet<\/p>\n\n\n\n<p>The one common drawback to most\u00a0SD-WAN solutions\u00a0is that they address your WAN connectivity needs as if they exist in isolation. This isn&#8217;t unique. One of the biggest challenges facing organizations undergoing rapid <a href=\"https:\/\/techxmedia.com\/tag\/digitaltransformation\/\">digital transformation<\/a> is that each new network element tends to be designed and implemented in isolation. While this approach has several significant flaws, none is more serious than the impact it has on security.<\/p>\n\n\n\n<p>One\nof the most critical functions required by security is expansive visibility\nacross the entire distributed network. While traditional hub-and-spoke WAN\nconnection models certainly have their shortcomings, they do enable all traffic\nto be scanned and secured by the centrally deployed security. Once you replace\nstatic MPLS connections with flexible connectivity that leverages a public\nnetwork and begin to support direct links to the internet and SaaS\napplications, you shift the burden of security to the SD-WAN device.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The limits of traditional SD-WAN solutions<\/strong><\/h2>\n\n\n\n<p>The\nproblem is, most SD-WAN devices offer little more than extremely basic firewall\nfunctionality. Which means that your critical data is no longer being protected\nby your full stack of security services, such as&nbsp;IPS,&nbsp;web filtering, anti-virus\nand anti-malware, and&nbsp;sandboxing. If you want those services, you have to add them as an\noverlay. This can add significant overhead to your IT team due to the heavy\nlifting of designing and deploying a solution, additional maintenance, and the\nuse of separate management consoles.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Security needs to consistently span the entire network<\/strong><\/h2>\n\n\n\n<p>Managing\nan SD-WAN connection over a platform as unreliable as the public internet\nrequires a significant amount of delicate connection management. Redundant\nsystems need to be in place for immediate failover. Links with deteriorating\nreliability need to be hot-swapped out, even during live connections. And\ntraffic management tools need to be constantly aware of application bandwidth\nrequirements and prioritization of different connections to continually make\nmicro-adjustments to support latency-sensitive applications like unified\ncommunications.<\/p>\n\n\n\n<p>SD-WAN\nconnections require end-to-end security that goes beyond simply encrypting\ndata. Communications between a branch office and a cloud-based application\nrequire data inspection at both ends of the connection. To avoid gaps in policy\nimplementation and enforcement, security solutions in the cloud need to be\nfully compatible with those running at the branch. Applications not only need\nto be identified and managed to optimize their performance, but security also\nneeds to see and understand those applications so appropriate levels of security\ncan be applied. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>SD-WAN needs to integrate network and security functionality<\/strong><\/h2>\n\n\n\n<p>But\nperhaps the most essential element required is the deep integration between\nSD-WAN network functionality and security. Unfortunately, when security is\ndeployed as an overlay, the best it can do is react to changes in network\nconnections. This might be good enough for basic connections to the core data\ncenter, but securing things like SaaS applications or accessing sensitive data\nis another matter. The lag time between a network change and the remapping of\nsecurity to match that new configuration can create security gaps \u2013 which can\nbe predicted and exploited. This problem is significantly compounded when such\nchanges can happen on a second-by-second basis.<\/p>\n\n\n\n<p>Rather\nthan deploying security as an overlay, it instead needs to be fully integrated\ninto the networking functionality of the SD-WAN solution itself. When new\nconnections are created, security policies are built and deployed as part of\nthe process. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The future requires security-driven networking<\/strong><\/h2>\n\n\n\n<p>This\ndeep interoperability between security and network functions is the hallmark of\nthe next generation of security known as Security-Driven Networking. By weaving\nthese traditionally separate systems into a single solution, organizations can\nachieve the visibility and control necessary to truly secure their entire\ninfrastructure. And as machine learning and AI become part of the solution, we\nwill finally realize the sort of self-defending, self-healing network we have\nbeen waiting for.\n\nNew&nbsp;Secure\nSD-WAN solutions&nbsp;are\nthe perfect place for this to begin. Deep integration between connectivity and\nsecurity allow for the seamless and straightforward deployment of a complete\nsolution, while networking and security functions can be managed simultaneously\nusing a single pane of glass management system, reducing overhead, increasing\nperformance and protection, and paving the way for the next generation of\nsecurity.\n\n\n\n<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SD-WAN connections require end-to-end security that goes beyond simply encrypting data. Communications between a branch office and a cloud-based application require data inspection at both ends of the connection. <\/p>\n","protected":false},"author":8,"featured_media":1078,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[9685],"tags":[206],"contributor":[],"class_list":["post-1023","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-events-middle-east","tag-fortinet"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/02\/Capture.png","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=1023"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1023\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/1078"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=1023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=1023"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=1023"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=1023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}