Most secure access service edge (SASE) platforms available today are compromised in one way or another, said Eyal Webber-Zvik, VP of product marketing at Cato, during the company’s Global SASE Summit earlier this month.

“No one offers a full or even real SASE solution,” he said.

The Israel-based networking and security company, founded in 2015, is an early pioneer in Gartner’s SASE product category.

SASE combines elements of SD-WAN, managed security, and edge compute into a simple cloud-delivered platform. And, in the two years since Gartner coined the term, SASE has gone from a nascent product category to one of the hottest buzzwords in the networking and security spaces.

But while nearly every SD-WAN and security company worth its salt now claims to offer a SASE architecture, Webber-Zvik argues most are fraught with compromise.

It's the Telecom Bundle All Over Again

Many of the biggest challenges facing competing SASE vendors go back to the way enterprises have traditionally handled networking and security, he explained.

Webber-Zvik is referring to telecommunications or managed service provider bundles, which often combine products like SD-WAN and firewalls from various vendors and marry them together to address a customer's specific use case.

In his example, a network operator might offer VMware’s VeloCloud SD-WAN, Symantec’s secure web gateway (SWG) and cloud access security broker (CASB), a cloud-based firewall from Fortinet, and zero-trust network access (ZTNA) from Microsoft.

The choice of services offered in this hypothetical is not surprising. They represent the five core components of a SASE architecture and are all products that Cato has independently developed internally.

Such a bundle might appear to offer greater choice than relying on a single vendor for everything, but Webber-Zvik argues this model introduces significant operational challenges that often increase costs and make services more difficult to manage.

“The telcos are slow to support because they don't own the product. They rely on a third party for resolution,” he said, adding that most service providers don’t offer a centralized management portal for customers to enact changes, and instead rely on support tickets.

And even when customers can access each service’s console, user, networking, or security policies typically have to be configured independently, Webber-Zvik said.“Where can I configure new users, and remove retired ones? If I have four different vendors with five different products, there is no chance I can do this from a single location."

Most SASE platforms on the market today were assembled through acquisitions or partnerships. For example, Palo Alto Networks acquired CloudGenix last year and paired the vendor’s SD-WAN functionality with its Prima Access security platform. Other SD-WAN vendors, including Aruba and Aryaka, have partnered with security companies like Zscaler or Checkpoint to offer a SASE architecture.

While fewer vendors are involved in those frameworks, Webber-Zvik contends many still fall prey to the same problems as the telecom bundle. One of his biggest criticisms is the complexity of managing individual components.

The crux of Webber-Zvik's argument is that even when SASE vendors acquire and integrate security or SD-WAN functionality, they are almost always managed separately, creating the same kind of operation problems as in the telecom bundle scenario.

He called out Cisco as one of the worst offenders in this regard. Cisco’s SASE platform is built around a combination of its Viptela SD-WAN, Umbrella security suite, AnyConnect client, and Duo identity management software. The problem, he said, is that all the pieces that make up Cisco’s SASE offering have their own management consoles and have to be configured independently of each other.

“I know that we say no one ever got fired for buying Cisco or IBM, but those days are ending. People are going to get fired for choosing a solution that slows the business down,” Webber-Zvik said.

The Private Backbone Problem

He also called out the reliance on public cloud providers for global connectivity.

“Internet access routing and bandwidth is only guaranteed within your ISP network,” he said. “Once you go to an out of country resource — it can be remote data center, to the cloud, etc. — traffic goes through the ISP transiting bottleneck, and it goes out to a world of unpredictable routing in performance.”

To get around this, many SD-WAN and SASE vendors have either deployed a private backbone or take advantage of existing networks operated by companies like Aryaka, Cloudflare, Megaport, or the public cloud providers.

“This is critical because the cloud needs to be as close as possible to the end user and to the resources they are trying to reach,” he said. “You want to subscribe to a SASE platform or a cloud service that is equally available across all the PoPs (points of presence) worldwide.”

Webber-Zvik claims most public cloud providers don’t provide enough PoPs to adequately service global enterprises.

“Azure has a total of 57 PoPs worldwide … but the Azure Virtual WAN is not available everywhere. It's only available from 37 of their 57 PoPs,” he said, adding that these PoPs are also often geographically limited. “Azure has an isolated instance of Azure in China which is not connected to the global cloud. The same goes for AWS.”

The result, he said, is inconsistent performance, especially for geographically distributed enterprises.

In extreme cases, Webber-Zvik said customers could discover that a SASE vendor’s closest PoP is hundreds of milliseconds of latency away.

Cato has more than 60 PoPs in colocation facilities and private data centers around the globe, and that's what's required for SASE vendors to be successful, he claimed.

Edging Out Legacy Mindsets

Many vendors have been moving toward a converged networking and security stack for years by integrating security functionality directly into the SD-WAN appliance. Versa Networks and Fortinet are two examples.

While this may have been adequate in the past, Webber-Zvik argues the idea of placing the security stack at the edge is incompatible with SASE. Though, companies like Fortinet have made a case for hardware-accelerated security.

“Converging network and security [at the edge] has many limitations because it takes place in appliances,” he said. “The edge converged solution is limited to the appliance's CPU and memory.”

This not only introduces scalability and performance bottlenecks if the hardware isn’t adequate, but it is also likely to cost more than cloud-delivered security, Webber-Zvik said.

In contrast, delivering the SASE security stack as a cloud-native package from the PoP eliminates bottlenecks and centralizes management, reducing the IT staff required to maintain the network, he said.

Room to Grow

SASE adoption may have accelerated during the pandemic, driven by the shift to remote work and the need for modern remote access technologies, but the product category still has a lot of room to grow, Gartner’s Neil MacDonald said in a recent interview with SDxCentral.

In particular, many of Webber-Zvik’s criticisms of competing SASE vendors, particularly those around edge hardware and the reliance on the public cloud, are areas where MacDonald expects to see advancement over the next few years.

Enterprises should begin moving toward a SASE architecture, but avoid long-term contracts and carefully consider potential pitfalls associated with each vendor’s approach, MacDonald said.