The pandemic has changed a lot more than how and where we work. It has also upended decades of networking and security conventions all while spotlighting the fact not all SD-WANs are created equal.

In a matter of weeks, enterprise security perimeters and network complexity exploded as more than 100 million Americans suddenly found themselves setting up shop in their home offices and at their kitchen tables. SD-WAN and security infrastructure perfectly suited to serving tens or even hundreds of branch offices were suddenly faced with a new and far more complex challenge: securing the branch of one.

According to Ben Niernberg, EVP at managed service provider MNJ Technologies, after enterprises got over the initial shock of having to transition to a remote workforce, they moved on to the more pressing issue of how to approach network and security policy.

A typical SD-WAN deployment enables secure communications between the headquarters and the branch office. These deployments usually use multiple WAN links and require SD-WAN appliances at either end.

"There's SD-WAN that is significantly more complex and robust that's great for the corporation and the branch office, but that's not going to work in the home office, both from a standpoint of costs and a standpoint of ease of use," Niernberg, explained, adding that some vendors handle the so-called branch of one better than others.

Tunnel Trouble

But while it's certainly possible to deploy SD-WAN hardware to every employee, it isn't always economically or operationally feasible, let alone necessary.

Instead, many enterprises are scaling up their use of virtual private networks (VPNs), already used by remote workers, to meet demand.

This approach, however, isn't without challenges, said Fortinet CMO John Maddison, in an interview with SDxCentral.

A typical enterprise with 10,000 employees might have had 1,000 workers who needed remote access to the data center, he said. With the onset of the pandemic, "suddenly everybody in the company needs SSL VPN access."

"A lot of our customers actually were able to spin up a teleworker solution very quickly," Maddison said.

Fortinet's enterprise and data center firewalls, which feature purpose-built security ASICs, can support tens of thousands of concurrent VPN tunnels, which is something Maddison says few others can achieve.

"Most of our customers were able to switch on almost 10x worth of SSL VPN in the data center without a drop for their systems," he said. "A lot of systems, that our competitors have, had a lot of problems because it was just doing that in CPU or through a standalone system."

This ramp in demand ultimately drove Nokia's Nuage Networks to partner with software-defined edge startup Asavie to enable mobile users to securely connect to enterprise clouds and applications without the need for a VPN. Asavie’s clientless connectivity service is designed to integrate and extend enterprises’ existing SD-WAN, secure access service edge (SASE), or zero-trust security deployments beyond the branch office without relying on IPsec tunnels.

In the wake of the pandemic, SASE vendor Cato Networks also updated its software-defined perimeter platform with a single sign-on feature designed to help remote workers access their software-as-a-service (SaaS) and legacy applications. Traditional VPNs simply can’t scale effectively to meet this demand and can introduce security risks, the company said.

Hardware Advantage

While most enterprise customers are relying on VPN tunnels, Niernberg said some are starting to recognize the value of a small SD-WAN appliance for remote workers, especially as quality of service and unified communications are concerned.

"It's becoming more prevalent to send something about the size of a computer," he said.

Fortinet, Cradlepoint, Adtran, and Versa are just a handful of the companies that have launched products aimed at small to midsize businesses or home offices in recent months.

According to Maddison, these boxes have been popular among executives and engineers that may require a more robust assortment of features. These features vary from vendor to vendor but may include SD-WAN functionality, next-generation firewall, quality-of-service assurance, or network redundancy.

And, like Niernberg, Maddison believes there is a real possibility that as companies transition to remote work as the new normal, employees wouldn't only be given a company laptop, they will also receive a small, low-cost SD-WAN appliance.

Providing workers with SD-WAN appliances also allows security to be applied to the whole home rather than just the worker's computer or mobile phone.

"A lot of people go, ' well, with this SD-WAN, I'll do all security via SASE in the cloud and that's good,'" said Maddison. "They forget the whole LAN security component. There are all these devices attaching, so you do need that security on the SD-WAN to face both the LAN and the WAN. Otherwise you've got a gaping hole in your security."

Regardless of which avenue enterprises take, one thing is for sure, Niernberg said. "COVID-19 has ripped the BandAid off on working remote and is forcing companies to do it."

This, he said, has not only accelerated their digital transformation but also forced them to think very carefully about which SD-WAN vendor they choose.