LAS VEGAS – Palo Alto Networks Chairman and CEO Nikesh Arora and CPO Lee Klarich met with the press after the first keynote sessions at the vendor's Ignite event this week. Arora detailed to SDxCentral Palo Alto Networks’ secure access service edge (SASE)-first sales strategy and the market's competitive landscape.

SDxCentral: You mentioned during the latest Palo Alto Networks earnings call that the company has trained all of your salespeople to become “SASE-first." What is this SASE-first strategy?

Arora: The firewall as a concept, at the end of the day, there's no difference in any of that traffic being inspected by a hardware firewall, has been inspected by software form-factor, or in SASE. It is the same traffic, the techniques are the same, DLP [data loss prevention] has been applied similarly, DNS [domain name system] has been applied similarly, so our salespeople should understand this is the same kind of product, [but] different use case. This type of firewall sales team used to sell firewalls, which was for a specific use case, actually, using a hardware form factor. And we had a SASE team because Zscaler was out there chasing SASE and we were competing with that. And it's fine because we were early, we're building our product, we're getting specialists, we're learning this stuff.

As we matured, as we saw this big SASE market and our pipeline becoming bigger and bigger, we flipped it and said every one of our salespeople needs to understand their security and zero trust and be able to sell and understand the full paradigm as to which firewall customers needed.

So we embarked on this journey at the beginning of this fiscal year where every core rep in our company is now a full network security rep. Instead of a SASE specialist deploying backup, the whole intent is to turn all these frontline people into full network security, zero-trust salespeople because that's what customers need. The customer shouldn't be buying a different hardware firewall, different software firewall, or different SASE [products], so we flipped it and it's working.

When you go forward two years and look back and say: wow, that's amazing, Palo Alto [Networks] has SASE salespeople who are basically network security and zero-trust salespeople, right? Because I think this is a long trend. SASE is a trend. I still believe that it is in its early part of its evolution. The reason I say that was this year, about $200 million in public cloud consumption, [which is] on a trend that in 10 years, [this will be] a trillion dollars. It's constant. And if you believe that, in concept, half of the traffic is now going to the cloud – the public cloud of your own apps. Forget about the SaaS [software-as-a-service] apps on top of that. So you can assume that 50% to 70% of traffic is going to have to go straight to the web for any part of either the deployed use case or bigger stores.

So every store is gonna have a lot of traffic with all these apps on the cloud. The traditional approach was to take that data from your store, the payment data, and run it through a tunnel into your data center, backhaul it there, or if you care you spend money buying a tier-one line from AT&T or T-Mobile or somebody and backhauled it over a data center, [but] that is expensive. You basically run a national network to bring the traffic back.

Well, you don't need to have your own network anymore. The thing is called the internet. You don't go to the internet from your store. Comcast will carry it or you can run a backhaul of GCP [Google Cloud Platform] or AWS [Amazon Web Services] or Palo Alto [Networks] to the GCP, or you can run a Verizon backhaul where you want to run it, and you can split the traffic and you can take it back to your data center to Google Cloud.

So what is happening is that every network architecture design in the last 30 years will be redesigned in the next 30 years. That's the entire SD-WAN [and] MPLS market. MPLS is being replaced by SD-WAN. SD-WAN was always big in the past and is going to be bigger. SD-WAN has a different market than SASE in the past. I think they're going to converge because there's contention between SD-WAN and security.

I think from that perspective, SASE is going to be a huge market. All of our customers have to go through big network transformations. It is great for us because we've already said this publicly: SASE customers are two-and-a-half-times more valuable to us than firewall customers because we own their traffic. Firewall we sold them a product they ran their own traffic. In [SD-WAN], we own their traffic, we're moving MPLS spend to SASE, a huge market, so we need that capability out of the field to make that transformation happen for all customers.

SDxCentral: How do you see the competitive landscape for SD-WAN and SASE, especially SASE competition between networking vendors vs. security vendors?

Arora: At least the last four-and-a-half years we’ve observed as a firewall business sometimes you end up in contention between the security team and the networking team. Sometimes security teams tell network teams which firewall to buy, all depending on the internal dynamics of the organization. The same thing happens for SASE: sometimes networking people tell the security guys, "I run SD-WAN, you go figure out the security." Sometimes security guys [say] "that's SASE, what are you gonna be doing with SD-WAN?" So that’s general contention.

But I think that's a shortish-term issue. As people start relying on this at scale they realize that they want to run this as-a-service. And over time the more they understand the reason why you need to have an integration of SD-WAN and SASE you'll see them converge.

And I'm very relaxed: they converge, I’ve got both; they don't converge, that's fine too. I sell SASE and SD-WAN, but very few SD-WAN players are SASE-capable. Their SASE products work on every SD-WAN. So I don't fuss about SD-WAN merging into SASE. But I can tell you that Aruba's not doing SASE, they are doing SD-WAN. I don’t think Fortinet’s doing SASE, they are in SD-WAN, just bought it. McAfee is doing SASE. But if you want, you can get it.

This interview was edited for length and clarity.

Photo (L-R): Palo Alto Networks Chairman and CEO Nikesh Arora and CPO Lee Klarich