With skeptics questioning its full alignment with current SD-WAN capabilities, Zscaler claims it is reimagining modern networking and the SD-WAN space, emphasizing security and simplicity over traditional network optimization strategies.

Zscaler launched its Zero Trust SD-WAN service last week, including several plug-and-play appliances, while targeting the competitive single-vendor secure access service edge (SASE) market.

However, Mauricio Sanchez, senior research director at Dell’Oro Group, argues Zscaler brings an alternative to SD-WAN, saying that the vendor approaches Enterprise networking needs from “a completely different angle.”

He added that the security vendor does not yet offer a comprehensive solution for enterprises that require the full suite of traditional SD-WAN capabilities, especially for those in areas with spotty last-mile connectivity that need services such as advanced traffic shaping, load balancing across multiple Internet service providers (ISPs), and forward error correction.

Zscaler seems to be moving toward a model where an internet-based cloud integrates various Enterprise assets altogether, Sanchez told SDxCentral. As the technology landscape evolves and the Internet becomes more reliable, he suggests that the market might shift. For certain enterprises with less demanding “heavyweight” networking requirements, Zscaler's offerings might be sufficient.

For now, though, Sanchez doesn't think Zscaler offers a “full-blown SD-WAN” yet.

Understanding traditional SD-WAN

A software-defined wide area network (SD-WAN) is a network that is abstracted from its hardware, creating a network virtualization (NV) overlay. An SD-WAN can connect several branch locations to a central hub office or cover multiple locations on a large campus.

The four central pillars of SD-WAN include edge connectivity abstraction, WAN virtualization, centralized management and elastic traffic management. These components work together to optimize network traffic, ensuring high speeds and reliable connectivity.

SD-WAN provides flexible WAN connectivity, utilizing multiple routes to reduce latency and costs. Moreover, for enhanced security, virtual private networks (VPNs) are typically installed across each WAN connection.

Responding to ‘full-blown SD-WAN’ questions

Naresh Kumar, VP of product management at Zscaler, told SDxCentral he has been asked whether the company's offering is “full-blown SD-WAN” and other related questions dozens of times since the vendor launched the new service. He argues that Zscaler’s Zero Trust SD-WAN reimagines what is essential in modern networking, shifting to a security-first and artificial intelligence (AI) (AI)-driven approach.

He noted that SD-WAN was invented to solve three original problems but modern networking has evolved:

  1. Centralized automation and orchestration: The initial goal was to simplify and automate network management, shifting from individual device management (CLI) to a centralized user interface (UI) for easier configuration and scaling of branch offices. However, now a centralized, cloud-based multitenant Orchestration System is a standard feature. “It is rare to find a product that doesn't have a global centralized UI.”
  2. Transport optimization: SD-WAN combines multiple Internet links to optimize network transport. The approach was crucial when Internet costs were high and bandwidth was limited. But along with the significant reduction in Internet costs, “the whole explosion and availability of bandwidth have completely minimized the need for SD-WAN functions around optimizing doing the magic of [bandwidth compressions],” Kumar said.
  3. Application traffic and web path selection: Original SD-WAN prioritizes certain types of traffic, like voice and video, to ensure quality collaboration and communication. However, with the growth of Software-as-a-Service and cloud applications, as well as the increased number of data centers, applications are now closer to users, diminishing the need for certain features designed to manage latency and optimize paths for traffic. Plus, applications have started becoming intelligent and AI will “automatically spin resources to accommodate the bandwidth,” he said.
Zscaler ‘relooks’ at SD-WAN

Kumar claims Zscaler is “completely relooking at the whole SD-WAN in an altogether different way.”

He noted the new Zero Trust SD-WAN solution included more hardware appliances. With the virtual form factors, these appliances act as inline gateways to allow direct termination of Internet links on the device. “We monitor those performances of the links and Switch them based on the application-aware path selection, which was one of the capabilities of a typical SD-WAN.”

“What we differ from a traditional SD-WAN is not about switching and optimizing the transport from connectivity, [but] more about securing the transport,” Kumar said.

He emphasizes that Zscaler uses zero-trust architecture to replace all the VPNs across WAN connections in a traditional SD-WAN.

“The Transmission Control Protocol/IP and SDN-based approach to networking will change. And it will be zero-trust networking with AI assistance. It is going to be AI networking,” Kumar said.

Christopher Rodriguez, research director of security and trust at IDC, noted that Zscaler’s zero-trust-based SD-WAN approach offers more flexible zero-trust network access (ZTNA) deployment options and better support for all device types, as well as the performance benefits of SD-WAN.