Keeping a distributed workforce connected was anything but simple even before the pandemic. With the onset of COVID-19, enterprises faced a reckoning as millions of employees set up shop at their kitchen tables, home offices, or spare bedrooms.

Branch traffic declined approximately 20% between January and March, then "in April and May it just fell off a cliff," said Alex Henthorn-Iwane, VP of Marketing at Sinefa, a company specializing in digital experience monitoring.

According to Henthorn-Iwane, anonymized data collected from 24 offices and approximately 2,000 employees showed traffic to popular software-as-a-service (SaaS) applications, like Office 365, fell by 96% between April and May as COVID-19-related work-from-home orders went into full effect across the U.S.

But what could have ended in disaster turned out to be something of a success story.

In response to the crisis, networking and security vendors moved quickly to address these challenges, and in the process, catapulted the adoption and development of technologies like secure access service edge (SASE), which combines SD-WAN and cloud-based security to provide secure access to applications from anywhere.

Meanwhile, hardware vendors like Fortinet and Juniper moved to bring branch hardware to the home, repositioning several products for use by remote workers.

And behind the scenes, internet service providers (ISPs) and carriers raced to rearchitect their networks to support the surge in bandwidth and changing traffic patterns.

Remote Workers Drive SASE Adoption

In the year since Gartner first coined the sassy sounding product category, nearly every networking and security vendor has thrown their weight behind SASE. Many, including Cisco and Versa Networks, have cited the shift to remote work under COVID-19 as an accelerating factor.

During Palo Alto Networks' fourth-quarter earnings call, CEO Nikesh Arora lauded the success of the company's Prisma Access SASE platform, which he said achieved a reported $90 million in billings during the quarter.

According to Henthorn-Iwane, the wide-spread adoption of SASE makes a lot of sense given the technology's low barrier to entry and opex-friendly subscription model. He explained that the traditional method for connecting remote workers like virtual private networks (VPNs) would have required making additional investments in expensive VPN servers in order to support the increased traffic.

While some hardware vendors like Fortinet have championed the capabilities of their next-generation firewalls as being able to support large numbers of simultaneous IPsec tunnels, many could not.

“Most of our customers were able to switch on almost 10x worth of SSL VPN in the data center without a drop for their systems,” said Fortinet CMO John Maddison, in an earlier interview with SDxCentral. “A lot of systems, that our competitors have, had a lot of problems because it was just doing that in CPU or through a standalone system.”

This ramp in demand drove Nokia's Nuage Networks to partner with software-defined edge startup Asavie to enable mobile users to securely connect to enterprise clouds and applications without the need for a VPN.

Cato Networks, on the other hand, updated its software-defined perimeter platform with a single sign-on feature designed to help remote workers access their SaaS and legacy applications. Traditional VPNs simply can’t scale effectively to meet this demand and can introduce security risks, the company said.

The Last-Mile Problem

While technologies like SASE and SD-WAN have helped address the remote access and application performance challenges, few directly address last-mile connectivity.

Between January and March, ISPs experienced a 65% leap in outages across North America, meanwhile in the Asian-Pacific market, outages nearly doubled, said Angelique Medina of ThousandEyes, in an interview with SDxCentral. This uptick in outages corresponded to the shift to remote work but not because the networks couldn't handle the traffic, she explained. "There is a perception among enterprises that the internet is more fragile than it is," Medina said.

But in the early weeks, after the first work-from-home orders went into effect, you'd have been forgiven for thinking as much as several of the top communications platforms, including Microsoft Teams, were briefly crippled by the sheer demand for their services.

"Especially in the U.S., there was an uptick in outages," said Medina. However, these outages were not the result of an inability to cope with the traffic, but rather the result of configuration changes made in an attempted to rightsize their networks.

"They had to make a lot of configuration changes. They needed to turn on services, reconfigure resources, make peering changes, and that inevitably led to more disruptions," she said.

In early March, Cisco reported that Webex traffic from China increased more than 2,000%. “We continue to see unprecedented increases in the amount of time spent on Webex video meetings in Japan, Singapore, China, and South Korea,” the company reported at the time.

In July, Cloudflare, a large content delivery network and domain name system (DNS) provider, experienced a major outage on a Friday afternoon after a bungled config change routed all traffic across the company's backbone network to a single router in Atlanta.

A little more than a month later, the DNS provider suffered another outage. Again the cause was sourced to a bad configuration file, but this time it wasn't Cloudflare's fault. Instead, the cause was linked to CenturyLink. A bad firewall figuration caused a flood of border control gateway outages across the network, taking down Cloudflare and many other services in the process.

Despite these high-profile outages, concerns that these kinds of disruptions would increase in proportion to traffic haven't come to fruition.

"The traffic has remained high, but the outages have started to stabilize," Medina said. "I think that really speaks to the resilience of the internet and the networking operators who were able to move quickly to make adjustments to their networks in order to accommodate these changes."

Challenges Remain

Network visibility continues to be a challenge for remote workers, said Henthorn-Iwane. If a remote worker is experiencing network instability, it can be difficult for tech support to identify the root cause, he explained.

To address this challenge, Sinefa has developed an endpoint client that can be installed on the employee's computer and provide better visibility into network issues like dropped packets or poor WiFi connectivity.

"It gives you the ability to really quickly look and say, 'hey, you've got a WiFi signal issue. Try moving closer to your hotspot' or 'hey, you've got a congestion issue; looks like it's on your home network,'" Henthorn-Iwane said.

The technology also gives enterprises tools to identify trends so they can advise employees what hardware or service providers are consistently having problems.

Juniper has taken a similar but hardware-centric approach with its Enterprise at Home program, which uses a combination of Mist wireless access points and its Marvis artificial intelligence (AI) operations platform.

Together, enterprise IT can quickly identify where the problem is on the network.

A customer experiencing problems with their network could simply type “what’s wrong with my network,” and Marvis would chew through the data, identify the anomaly, and suggest a resolution to the problem, explained Jeff Aaron, head of marketing at Mist in an earlier interview with SDxCentral.

“Home is where the WAN is,” he said. “That’s now the new corporate WAN, and IT help desk calls are going up astronomically, and they’re harder than hell to troubleshoot if one person is using a Netgear access point and another is using a DLink.”

While the enterprise may not be able to control which service provider the employee uses, Aaron said giving them the right equipment can go a long way to alleviating these kinds of headaches.