Where all IT network functions come to a single, next-gen management control point is where you most likely find network administrators smiling instead of sweating. No longer must they bounce around from screen to screen and function to function trying to find the origin of a blockage and get the solution. In a unified control system everything is laid right out in front of them so they can see exactly where the pain point is, making it much easier and faster to determine a remedy.
When researching providers for this specialized type of network management, enterprise buyers should take into consideration the following factors:
- Scalability: Choose a platform that can scale to your current and future network needs. (Don't understand your future needs? Join the club seeking growth flexibility.)
- Features: Consider the specific features you need, such as network monitoring, performance analysis, fault management, configuration management, high-end security, and automation.
- Integration: Ensure the platform can integrate with your existing IT tools and systems. Ask specific questions.
- Ease of use: Choose a platform that is easy to use and manage, with an intuitive interface. A savvy line-of-business staff member should be able to understand and use it.
- Cost: Evaluate the total cost of ownership, including licensing, implementation, and maintenance. Such an investment will likely need board support.
Beware of possible pitfalls when making the changeover
Switching from a legacy IT network system to a SASE/SD-WAN system can bring many benefits, but it's important to be aware of the potential pitfalls to ensure a smooth transition. Here are some key challenges to consider:
Implementation complexity: Migrating to a SASE architecture requires careful planning and design. You need to assess your existing infrastructure, identify compatibility issues, and map out a migration strategy that minimizes disruption to your business operations. Integrating SASE with existing legacy systems can be challenging. Compatibility issues may arise, requiring additional resources and expertise to resolve. Know that the transition process can be time-consuming and require significant resources, including personnel, budget, and training.
Dependency on cloud providers: SASE relies heavily on cloud infrastructure, so your network and security operations could be impacted by issues with your cloud service provider. Choosing a SASE provider may lead to vendor lock-in, limiting your flexibility in changing providers later. This is always a chance one has to take, but if the vendor is well known and trusted, it's much less of a problem than it used to be years ago when many cloud-service providers were startups.
Cost considerations: While SASE can offer cost savings in the long run, it requires an initial investment in new hardware, software, and services that often run into seven or eight figures for larger systems. You also need to factor in the costs of migration, including planning, implementation, training, and potential downtime. And don't forget ongoing costs, such as subscription fees, maintenance, and support.
Performance and latency: The performance of your SASE solution can be affected by the performance of your cloud provider's infrastructure. Depending on your users' location and the cloud resources they access, latency can be a concern. Ensure that your chosen SASE solution can provide sufficient bandwidth to meet your needs.
Security: During the transition period, there may be security gaps that need to be addressed. SASE can be complex, and ensuring that all security components are properly configured and integrated is crucial. Stay up-to-date with the evolving threat landscape and ensure that your SASE solution can effectively protect against new threats.
Change management: Users may need training and support to adapt to the new SASE environment. Your IT team may need to acquire new skills and knowledge to manage and maintain the deployment. Effective communication with stakeholders throughout the transition process is essential.
To mitigate these pitfalls, consider the following:
- Develop a migration plan that addresses all aspects of the transition as noted above.
- Consider a phased implementation to minimize disruption and allow for adjustments along the way.
- Conduct a proof-of-concept exercise to test the SASE solution in your environment before full deployment.
- Engage with experienced consultants or managed service providers to help with the transition.
- Provide adequate training and support to your users and IT team.
- Continuously monitor the performance and security of your SASE solution to identify and address any issues.
Four of the most progressive-thinking vendors in this sector, according to Gartner Research, are Cisco, Broadcom, Fortinet, and OpenText.
Long the biggest fish in the IT networking sea (since the early 1990s), Cisco offers a range of network management hardware and software, including Cisco Catalyst Center and Cisco Prime Infrastructure. These integrated platforms provide centralized management of Cisco network devices, including switches, routers, and wireless access points. Cisco solutions offer features such as network automation, policy management, assurance, and security.
Cisco Catalyst SD-WAN is the company's core platform, providing intelligent routing, traffic optimization, and centralized management of WAN connectivity. It supports various WAN link types (MPLS, broadband, cellular) and allows for dynamic path selection based on application needs and network conditions. Cisco Secure Access is its cloud-delivered security platform, providing a suite of security functions, including secure web gateway (SWG); cloud access security broker (CASB); zero-trust network access (ZTNA); and DNS-layer security.
Broadcom
One of the few IT providers that has all the pieces to this new networking puzzle already working together in one place is Broadcom, a longtime IT leader that makes both hardware and software. Its Network Observability platform is a monitoring package that uses artificial intelligence (AI) and machine learning (ML) to help IT teams manage their networks. It combines visibility, performance monitoring, and analytics to help identify and resolve issues before they impact users.
“Globally, the components we have are led by fault management. We monitor any fault, any error happening in the network,” Yann Guernion, Broadcom Product Marketing Manager in the greater Paris Metropolitan Region, told SDxCentral. “Of course, this includes AI, because we are doing correlations between events.”
“We also are doing alarm noise reduction, because as you can imagine, when you have very large networks, it's not just a few dozen events that are coming. It can be thousands and multiple thousands every second. So we have to do some alert noise reduction and help the operators to focus only on what is important, and what can create a real business problem.”
Fortinet
Fortinet uses a security-first approach, leveraging its extensive experience in the cybersecurity space. The solution provides a full suite of cloud-delivered security functions, eliminating the need for separate security appliances.
Fortinet's SASE/SD-WAN package combines three key components to provide a unified offering. SD-WAN at the edge, using FortiGate Next-Generation Firewall (NGFW), handles the SD-WAN functionality at branch offices or other edge locations, optimizing network traffic and ensuring application performance.
FortiSASE provides the cloud-delivered security layer, inspecting traffic, enforcing policies, and protecting against threats, regardless of user location. FortiManager provides a single control panel for managing both the SD-WAN and security components, simplifying operations and reducing complexity.
OpenText
OpenText offers a SASE/SD-WAN product that combines SD-WAN with integrated security capabilities delivered from the cloud. OpenText includes a full suite of cloud-delivered security functions, such as firewall-as-a-service (FWaaS), SWG, cloud access security broker (CASB), and ZTNA.
OpenText SASE/SD-WAN is managed through a centralized console, simplifying network and security operations. Its cloud-based security service edge (SSE) security stack includes FWaaS, SWG, CASB, and ZTNA to secure access to applications and data.
OpenText leverages a global backbone network of points of presence (PoPs) to deliver its SASE services, providing low latency and high availability.
Comments