As 5G networking use cases continue to expand there are important security considerations to be made, according to Versa Networks CEO Kelly Ahuja – and he thinks secure access service edge (SASE) should be part of that conversation.
5G networks are becoming increasingly robust and disaggregated in a manner that better supports new services like mobile edge compute (MEC) and IoT networks. Ahuja pointed out that instead of offering a legacy 4G LTE network as a failover option at a particular office or a branch, many service providers now offer 5G as a fixed-wireless access (FWA) service that can support failover or be the primary connection.
New 5G use cases introduce a new set of security threats, such as kernel bypass, distributed denial-of-service (DDoS) attacks, and exploitation of software or hardware vulnerabilities leading to zero-day exploits, he explained in a blog. Ahuja said SASE can enable automated 5G rollout of thousands of devices with end-to-end security, including zero-trust network access (ZTNA), firewall, secure web gateway (SWG), and cloud access security broker (CASB).
“It becomes very important to offer security consistently and have that flexibility that 5G provides,” he told SDxCentral. “SASE cloud implementation, taking all the traffic from that 5G node or branch and bringing it into a SASE cloud, allows the enterprise to do it very quickly and effectively.”
SASE can also deliver visibility and telemetry for highly distributed 5G networks, and enforces compliance through a consistent security posture across public cloud, hybrid cloud, on-premises, and MEC.
“Most folks have not connected the dots. Everyone thinks SASE is only for remote workers, and that’s not right,” Ahuja noted. “The use cases for SASE are actually expanding quite rapidly. And SASE for 5G is a very hot area for most operators because they're deploying 5G everywhere, and now they need to roll out services, they've got to deal with the traffic that's coming in.”
SASE Pairs Well With 5G SlicingVersa VP Chitresh Yadav said one of the most notable components offered by 5G is network slicing – a useful feature that can separate traffic from the radio access network (RAN) based on different service-level agreements (SLAs), bandwidth requirements, and security requirements.
But the catch is you cannot have different infrastructure for every network slice, Yadav said.
“What it means is that you have to make use of the existing infrastructure or maybe some enhanced infrastructure, but you create an overlay network so that you can create an overlay for different slices,” he added, and SASE can be applied through that overlay network.
Ahuja said SASE can work with 5G network slicing to guarantee “aggressive 5G SLAs” with end-to-end security and enable flexible operator implementation of services between their evolved packet core (EPC) and the internet.
“SD-WAN, a SASE component, combined with network slicing guarantees that SLAs are met, and provides end-to-end security, including UTM, IDS/IPS, anti-virus, and more,” he wrote in the blog. “SASE is crucial to a successful 5G environment.”
Comments