Secure access service edge (SASE) captivated networking and security vendors throughout 2021, but service providers including AT&T took a more pragmatic view of Gartner’s red-hot product category.
“We’ve been selling multi-vendor SASE environments with VMware and Zscaler, and VMware and Palo Alto [Networks] Prisma for a number of years now, but it’s been in more of a siloed view,” said Will Eborall, who heads up AT&T’s virtual edge portfolio.
While the various networking and security components were packaged up and provided to customers as managed services, AT&T never offered a “fully integrated experience,” he told SDxCentral in an interview.
That changed early last year when AT&T announced a smattering of single-vendor, managed SASE offerings beginning with Fortinet and later adding Palo Alto Networks and Cisco toward the end of the year.
The SASE Long GameDespite the pivot, Eborall doesn’t expect customers to start ripping and replacing their existing SD-WAN or security infrastructure in favor of single-vendor SASE platforms — at least not in the short term.
Service providers have long championed a “best-of-breed” managed network and security philosophy. For example, Verizon’s own foray into the managed SASE arena last year paired Versa’s SD-WAN capabilities with Zscaler’s cloud-security functionality.
While today customers may prefer or require a multi-vendor SASE architecture, appetites are changing, Eborall said.
Fully integrated SASE architectures are about the long game, he explained. “Long term, I think in that single-vendor stack, there is huge value.”
Gartner analyst and SASE father Neil MacDonald, perhaps unsurprisingly, agrees. But like AT&T, the analyst is under no illusion regarding where customers are at in their network and security journeys.
By consolidating secure web gateway, zero-trust network access, cloud access security broker, and cloud-based firewalls under a single vendor, enterprises can not only better support remote workers and contractors, but do so in a way that cuts down on the number of products required and allows for consistent policy enforcement across all channels, he said during Palo Alto Network’s SASE Converge virtual event last fall.
Gartner still recommends a single-vendor SASE that includes SD-WAN functionality, but for those that aren’t ready or can’t yet take the plunge, MacDonald advises consolidating security functionality first.
“You could include SD-WAN in the scope of that project … but if you can’t get the teams together, or you have investments that are going to take a while to pan out, go ahead and converge the security services today,” he said.
The WAN Is ChangingMaking matters more difficult, enterprise WANs are in flux as hybrid and multi-cloud architectures invert network topologies.
Traditional branch-to-branch, hub-and-spoke architectures are dying, and SD-WAN is becoming a tool for cloud enablement, Eborall said. “We have managed SD-WAN edge points into a variety of different cloud nodes and each cloud may have different requirements.”
As these topologies change, so have customers’ expectations for performance and reliability, he added. And while MPLS offload remains a key value proposition for SD-WAN customers — Gartner predicts 40% of enterprises will cut the MPLS cord entirely by 2025 — AT&T still sees its network as a valuable asset.
Many cloud, co-location, and content delivery network vendors have stepped in to offer middle-mile transport services that promise MPLS-like performance at a fraction of the cost. The most notable being AWS’ Cloud WAN platform announced late last year.
However, these services don’t address first-and last-mile connectivity, Eborall noted. “The remote end is where the variable performance is."
AT&T claims in many cases it can provide end-to-end connectivity across its network that avoids this variability.
Comments