Red Hat wants a piece of the secure access service edge (SASE) pie, but probably not in the way you think.

Red Hat doesn’t want to compete with the litany of well established SD-WAN and cloud security vendors that have coalesced around the Gartner-coined product category. Instead, the company sees an opportunity to orchestrate the deployment of the red-hot networking and security service across telecommunications and large enterprise infrastructure.

In fact, Red Hat is already working with several vendors, including VMware's VeloCloud and Turnium, to deploy their respective services using tools like its Kubernetes-based OpenShift container orchestration platform.

“We have a large set of enterprise customers, and SASE is where we increasingly see the intersection point between enterprise and public cloud or enterprise and the telcos … In both of these scenarios, there is an enterprise MEC edge play,” Azhar Sayeed, senior director of telco technical development at Red Hat, told SDxCentral.

Can OpenShift Unbundle SASE

Using OpenShift, Sayeed claims customers can deploy containerized services, including SD-WAN or SASE, in the cloud, in the data center, at the telco edge, on multi-access edge computing (MEC) infrastructure, or on enterprise CPE.

“Far edge can also mean enterprise on-prem where you can deploy an OpenShift-like capability … onto a very small footprint, single-node type of device, host microservice applications on that, and connect that back to the public cloud or private infrastructure,” Sayeed explained, adding that this means a communications services provider could use OpenShift to dynamically deploy SD-WAN routing and/or security capabilities to generic white box CPE located on premises, using the same tools used to orchestrate the rest of its network.

“We’ve enabled these guys to run their workloads natively with Kubernetes on the platform so they can actually go and deploy pretty much anywhere,” Sayeed said.

One of the biggest benefits of this approach, he added, is that it simplifies the process of deploying multi-vendor SASE services that may use SD-WAN from one vendor and cloud security functionality from one or more others.

Sayeed argues that while all-in-one SASE services will likely remain popular among many enterprises, Red Hat is positioning OpenShift as an alternative that doesn’t compromise on ease of deployment, manageability, or customer preferences.

Cloud Native Conundrum

While Gartner’s SASE literature calls for a cloud-native, microservices-based networking and security feature set, not every vendor has embraced this approach. However, this isn’t a problem for Red Hat, Sayeed said.

“Ideally, we would prefer [the SD-WAN or SASE platform] to be cloud native because we can provide the same cloud experience that you see in the data center at the far edge as well,” he said. “But practically, we understand that not all of these workloads … are containerized.”

Because of this, the vendor also supports deploying services using virtual machines or on bare metal if they’re installed on a Red Hat Enterprise Linux-based system, Sayeed said.

VMware Targets SASE MEC

VMware, which Sayeed named as an early parter, recent detailed its own SASE MEC strategy.

In a recent blog post, VMware’s Director of Service Provider and Edge Ramkumar Venketaramani and 5G Solutions Architect Ajitesh Gupta argued the rise of 5G and abundant edge compute would not only disrupt traditional MPLS networking, but open the door to new deployment schemes and use cases.

One of these uses cases would do away with proprietary CPE in favor of running that software stack on a MEC node.

Instead of deploying CPE, a communications service provider could simply spin up a new SD-WAN or SASE instance on a MEC node just outside the branch office. This, VMware argues, will vastly simplify deployments and lower the barrier to SD-WAN and SASE adoption.