Secure access service edge (SASE) has seen widespread adoption over the past year, but with its rise in popularity the market has been flooded with noise. Industry trade group MEF want to cut through the noise by beginning work on a SASE definition (MEF W117), much the same way it did with its MEF 70 SD-WAN definition late last year.

"We removed the confusion with our SD-WAN with our first service definitions and now we have certifications," MEF CTO Pascal Menezes told SDxCentral. "You remember there was a lot of confusion about labels, constructs; we've removed all that, and now we have SD-WAN policies."

While Gartner, which coined SASE in its 2019 Hype Cycle report, has called out the individual pieces of the SASE stack, Menezes argues that those pieces aren't always well defined themselves. According to MEF, this has contributed to an environment where SASE marketing is causing fragmentation and confusion.

To overcome these challenges, MEF is working with players across several industries including Fortinet, VMware, Juniper Networks, Nuage Networks, Nokia, Versa Networks, Ciena, CMC Networks, and Datavision to develop a SASE definition.

Defining the SASE Stack

The way enterprises architect their networks and connect to resources is fundamentally changing, Menezes said. "The major problem today ... is people want to work from anywhere and they want the same application performance guarantee. They want it frictionless. They don't want to think about it," he explained.

Like MEF's SD-WAN definition, the consortium isn't trying to dictate how a SASE product should be implemented. Instead, the consortium is looking at how it should behave. Effectively asking the question: what does each part of the SASE stack do, rather than how it does it.

However, MEF isn't starting from scratch here. "We started a year and a half ago with security for SD-WAN," Menezes said.

While SASE is a relatively new concept, MEF has been working on defining the individual components that make up the SASE stack for some time.

However, Menezes notes that SD-WAN and security are only two pieces of a much larger SASE puzzle. Edge compute, orchestration, and identity-based policy enforcement all have a part to play in the SASE framework.

"This framework is really around this idea of access from the subscriber and devices, and they go through an SD-WAN or non-SD-WAN layer, security layer," he said. "They're really trying to get to four major areas: the internet through the SASE cloud, to a private data center, to a hyperscale area, or to the service provider where they might have services."

To address SASE's inherent complexity, MEF will draw on existing and emerging definitions covering everything from SD-WAN, security, and zero-trust networking to performance monitoring, orchestration, and policy enforcement.

“MEF has a proven track record of standardizing abstract constructs, attributes, and architectures for network services such as SD-WAN, carrier Ethernet, optical transport, and IP,” said MEF President Nan Chen. “By achieving consensus on what a converged networking and security framework and associated SASE services should look like, MEF can empower technology and service providers to focus on providing a core set of common capabilities and then building their own innovative, differentiated offerings beyond those core features.”