{"id":11376,"date":"2020-09-09T12:02:13","date_gmt":"2020-09-09T08:02:13","guid":{"rendered":"https:\/\/techxmedia.com\/?p=11376"},"modified":"2025-04-16T16:01:50","modified_gmt":"2025-04-16T12:01:50","slug":"sase-all-about-delivering-security-everywhere","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/sase-all-about-delivering-security-everywhere\/","title":{"rendered":"SASE is all about delivering security everywhere"},"content":{"rendered":"<p style=\"text-align: justify;\"><strong>By John Maddison, EVP of Products and CMO at Fortinet.<\/strong><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/sase?utm_source=blog&amp;utm_campaign=2020-q3-sase\">Secure Access Service Edge<\/a> (SASE) is an emerging enterprise strategy that incorporates multiple solutions to enable secure remote access to on-premises, cloud-based, and online resources. Unfortunately, there has been a lot of hype that has left some organizations wondering what exactly SASE is. Understanding the basic concepts and components of SASE is important, as the benefits can be significant for many organizations. Fortunately, getting to the bottom of this is easy, as many of the fundamentals of SASE \u2013 such as bringing networking and security together\u2013 are trends that customers have been gravitating to for years. However, it is still critical to properly define SASE upfront in order to avoid adding complexity or worse, missing the true value of SASE at all.<\/p>\n<h4 style=\"text-align: justify;\"><strong>Security Everywhere<\/strong><\/h4>\n<p style=\"text-align: justify;\">Today\u2019s organizations require immediate, uninterrupted access to the network and cloud-based resources and data, including business-critical applications, no matter where their users are located. The reality is that consumption patterns are changing due to the implementation of 5G, cloud migrations, sustained work from home, and similar outcomes from digital innovation efforts. This has transformed the traditional network to a network of many edges.<\/p>\n<p style=\"text-align: justify;\">At the same time, these dynamically changing network configurations, and the rapid expansion of the attack surface, means that many traditional security solutions no longer provide the level of protection and access control that organizations and users require. In this environment, security has to be delivered anywhere from any place, at any time, and for any device \u2013 the WAN Edge, Cloud Edge, DC Edge, Core Network Edge, Branch Edge, and Mobile Remote Worker Edge. This requires the convergence of traditional and cloud-based security, as well as deep integration between security and fundamental networking elements.<\/p>\n<h4 style=\"text-align: justify;\"><strong>Accurately Defining SASE<\/strong><\/h4>\n<p style=\"text-align: justify;\">SASE\u00a0is designed to help organizations secure these new distributed networks. However, as with any emerging technology category, there is still some uncertainty about what precisely a SASE solution means\u2014and what technologies are included. In addition, vendors are attempting to redefine this market in ways that best reflect their current offerings \u2013 which means that some elements are being overemphasized and others, often essential elements get overlooked. Unfortunately, some market definitions of SASE already include important omissions that are leaving some organizations confused about how to best select, implement, and manage the right sort of solution for their unique environments.<\/p>\n<h4 style=\"text-align: justify;\"><strong>Not Just Cloud<\/strong><\/h4>\n<p style=\"text-align: justify;\">SASE is generally classified as a\u00a0<a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/cloud-security.html?utm_source=blog&amp;utm_campaign=2019-q3-cloud-security\">cloud<\/a>-delivered service, providing secure access to cloud-based resources, secure communications between remote users, and always-on security for devices off-premises. However, there are situations where organizations may require a combination of physical and cloud-based solutions for SASE to work effectively. This may include supporting a physical\u00a0<a href=\"https:\/\/www.fortinet.com\/products\/sd-wan.html?utm_source=blog&amp;utm_campaign=2018-q2-sd-wan-web\">SD-WAN<\/a>\u00a0solution in place that already contains a full stack of security, or the desire to provide protection at the edge when processing confidential or sensitive information rather than shuttling it out to the cloud for inspection.<\/p>\n<p style=\"text-align: justify;\">By combining physical and cloud-based elements, the role of SASE can also be easily extended deep into the network, rather than simply handing off security to an entirely different system at the edge. This ensures that a secure SASE connection is seamlessly integrated with critical solutions that also rely on hardware, such as network segmentation and compliance requirements that a strictly cloud-based security approach can\u2019t address, to provide end-to-end protection.<\/p>\n<h4 style=\"text-align: justify;\"><strong>Secure LAN and WAN<\/strong><\/h4>\n<p style=\"text-align: justify;\">Some\u00a0SASE definitions\u00a0also omit things like Secure LAN and Secure WLAN that are essential considerations for many organizations. Including these sorts of technologies in a SASE solution helps ensure that security is applied consistently across an entire security architecture, rather than deploying separate security components for their SASE deployment \u2013 which could create gaps in security policy enforcement and limit visibility.<\/p>\n<h4 style=\"text-align: justify;\"><strong>Flexible Consumption<\/strong><\/h4>\n<p style=\"text-align: justify;\">But regardless of which tools are used or where they are deployed, there is a central issue that needs to be remembered. Every SASE solution must not only meet the access needs of today, but also have the capability to quickly adapt to rapidly evolving network changes and business requirements as they occur. This explains a key criteria for SASE, which is flexible consumption models that give organizations choices depending on their unique use-cases in order to achieve the\u00a0<em>true vision<\/em>\u00a0of SASE.<\/p>\n<h4 style=\"text-align: justify;\"><strong>Essential Security Elements Defined<\/strong><\/h4>\n<p style=\"text-align: justify;\">Any true SASE solution must include a core set of essential security elements. To realize the full potential of a SASE deployment, organizations must understand and implement these security components across the WAN-edge, LAN-edge, and Cloud-edge.<\/p>\n<ul style=\"text-align: justify;\">\n<li><a href=\"https:\/\/www.fortinet.com\/products\/sd-wan.html?utm_source=blog&amp;utm_campaign=2018-q2-sd-wan-web\">A fully functional, SD-WAN solution<\/a>. SASE starts with an SD-WAN solution that includes such things as dynamic path selection, self-healing WAN capabilities, and consistent application and user experience for business applications.<\/li>\n<li>An NGFW (physical) or FWaaS (cloud-based) <a href=\"https:\/\/techxmedia.com\/tag\/firewall\/\">firewall<\/a>.\u00a0SASE also needs to include a full stack of security that spans both physical and cloud-based scenarios. For example, remote workers require a combination of cloud-based security for accessing resources located online, and physical security and internal segmentation to prevent network users from accessing restricted corporate network resources. However, physical hardware and cloud-native security need to deliver the same high performance at scale, enabling maximum flexibility and security.<\/li>\n<li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/network-access.html?utm_source=blog&amp;utm_campaign=2020-q2-zero-trust-network-access\">Zero-trust Network Access<\/a>. It is primarily used to identify users and devices and authenticate them to applications. Because ZTNA is more of a strategy than a product, it includes several technologies working together, starting with <a href=\"https:\/\/techxmedia.com\/tag\/mfa\/\">multi-factor authentication<\/a> (MFA) to identify all users. On the physical side, ZTNA should include secure network access control (NAC), access policy enforcement, and integration with dynamic network segmentation to limit access to networked resources. And on the cloud side, ZTNA needs to support things like micro-segmentation with traffic inspection for secure East-West communications between users, and always-on security for devices both on and off-network.<\/li>\n<li><a href=\"https:\/\/www.fortinet.com\/products\/secure-web-gateway.html?utm_source=blog&amp;utm_campaign=2018-q3-secure-web-gateway\">A Secure Web Gateway<\/a>.\u00a0It\u00a0is used to protect users and devices from online security threats by enforcing internet security and compliance policies and filtering out malicious internet traffic. It can also enforce acceptable use policies for web access, ensure compliance with regulations, and prevent data leakage.<\/li>\n<li><a href=\"https:\/\/www.fortinet.com\/products\/cloud-access-security-broker.html?utm_source=blog&amp;utm_campaign=2018-q3-forticasb\">A CASB<\/a>.\u00a0A\u00a0cloud-based service enables organizations to take control of their SaaS applications, including securing application access and eliminating Shadow IT challenges. This needs to be combined with on-premises DLP to ensure comprehensive data loss prevention.<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\"><strong>SASE \u2013 The Convergence of Networking and Security<\/strong><\/h4>\n<p style=\"text-align: justify;\">At a high level, implementing SASE really comes down to enabling secure connectivity and access to critical resources from anywhere on any edge. Unfortunately, very few vendors can provide this because their portfolios are full of disparate, acquired products, or they simply don\u2019t have enough breadth to provide all of the security elements that a robust SASE solution requires. And even when they do, their solutions simply do not interoperate well enough to be effective.<\/p>\n<p>This is a problem because for SASE to work well, all of its components need to interoperate as a single integrated system \u2013 connectivity, networking, and security elements alike. This means every component needs to be designed to interoperate as part of an integrated strategy bound together by a single, centralized management and orchestration solution. They also need to seamlessly integrate with the larger corporate security framework, as well as dynamically adapt as networking environments evolve. If not, it\u2019s not a true SASE solution.<\/p>\n<p style=\"text-align: justify;\">The recent market momentum around SASE is exciting because it underscores the need for a\u00a0<a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/network-security.html?utm_source=blog&amp;utm_campaign=2020-q2-network-security\">Security-Driven Networking<\/a>\u00a0approach. In the era of cloud connectivity and digital innovation, networking and\u00a0security must converge. There\u2019s no going back to outmoded and siloed architectures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SASE is designed to help organizations secure these new distributed networks. However, as with any emerging technology category, there is still some uncertainty about what precisely a SASE solution means\u2014and what technologies are included. In addition, vendors are attempting to redefine this market in ways that best reflect their current offerings<\/p>\n","protected":false},"author":8,"featured_media":11380,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[9715],"tags":[3253,3254,2773,3252,963,554],"contributor":[],"class_list":["post-11376","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-expert-opinion","tag-cloud-based","tag-dlp","tag-firewall","tag-full-stack","tag-mfa","tag-sase"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/09\/JMaddison-SASE-TECHx.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/11376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=11376"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/11376\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/11380"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=11376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=11376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=11376"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=11376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}