Zscaler continues to enhance its secure access service edge (SASE) by integrating the technology from its recently acquired Airgap Networks and adding new hardware appliances to its Zero Trust SD-WAN solution.
The security vendor recently closed on its acquisition of Airgap Networks. That deal provides a zero-trust isolation platform designed to protect branch offices and eliminate the need for firewall-based segmentation.
“We have two customers already under Zscaler’s logo, so the deal is pretty much completed,” Naresh Kumar, VP and GM of product management at Zscaler, told SDxCentral. “What we have been working on as a zero-trust SD-WAN solution is going to enable and simplify the transport and bring zero trust. ”
Airgap Networks’ approach employs an intelligent dynamic host configuration protocol (DHCP) proxy architecture, which isolates every device and controls access based on identity and context. This strategy is designed to prevent sophisticated threats from moving laterally within a LAN compared to traditional network access control (NAC) and network-based firewalls that use static access control lists to control east-west traffic.
Integrating Airgap and SD-WAN One of Zscaler's focus areas with the Airgap Networks integration is building it into its Zero Trust SD-WAN appliances for small and medium branch offices, Kumar said.
In January, Zscaler announced the general availability of its Zero Trust SD-WAN solution and portfolio of plug-and-play Z-Connector appliances. Those are designed to help customers modernize secure connectivity for branch offices, factories, and data centers while also eliminating the need for ineffective firewalls and VPNs.
The vendor plans to combine its Zero Trust SD-WAN solution with Airgap Networks’ agentless segmentation technology to help customers implement zero-trust segmentation to IoT and operational technology (OT) devices, particularly eliminating the need for east-west firewalls. Kumar added that Zscaler is also expanding these capabilities to branches, campuses, factories, and retail verticals.
Zscaler to introduce hardware to support large campuses and data centers The security vendor also plans to introduce high-throughput boxes to support the traffic demands within larger campuses and data center environments.
“For very large campuses and data centers, usually you separate the role of a gateway from an east-west firewall functionality,” Kumar said. “We are introducing a very big [5 Gb/s] and [10 Gb/s] throughput boxes. So those are the new line of products, which we are going to announce toward the end of this year.”
“If you look in the campus environment, most often times software is connected through a switch to the core switch, and oftentimes there is a need for the inter-VLAN traffic to be up to 10 Gb/s, or even 40 Gb/s. That's where we are going to add a portfolio of hardware platforms which can support that sort of scale,” Kumar added, noting, “we are looking for a dual power supply, high throughput one RU [rack unit] and two RU with high port density boxes.”
The role of SD-WAN appliances in Zscaler’s cloud-delivered SASE Kumar did clarify that these appliances are essential for on-premises needs, noting the vendor’s SD-WAN solution is built in-house, emphasizing a lean branch office setup and leaving all the security in the cloud as a service. This approach aligns with the SASE model, ensuring essential on-premises functions while delivering comprehensive security through the cloud.
It also adheres to Zscaler’s single-vendor SASE vision.
“If not us, someone has to terminate the internet circuit, someone has to provide a path selection between one circuit to another circuit, someone has to stop all inbound connections,” Kumar said. “And our whole point of going into this SD-WAN area is to really make a cloud-native SASE in a zero-trust model. And it is only to complete that vision and provide a true SASE solution.”
Comments