Versa Networks announced today the launch of a new software-defined branch and campus Local Area Network solution called Versa Secure SD-LAN. The new offering aims to address limitations of traditional LAN architectures by delivering integrated switching, routing, security and network services.
The new offering extends Versa's existing Unified SASE (secure access service edge) platform that includes SD-WAN and security services with secure web gateway, next-generation firewall and zero-trust network access (ZTNA) capabilities. The Versa Secure SD-LAN solution consists of software that runs on certified Ethernet switches and access points to software-define the LAN. The software-defined architecture provides user, device and Application awareness and centralized policy management for full visibility and control.
“Versa Secure SD-LAN is a new solution,” Kevin Sheu, VP of product marketing at Versa Networks, told SDxCentral. “It's noteworthy to mention that this solution is built as an extension of our Unified SASE platform, so it shares the same management console, policy repository and data lake as our Versa Secure SD-WAN, cloud and data center products.”
Why Versa is extending SASE to the LANVersa has been deploying SASE as part of its portfolio for several years. In 2023, the company expanded its SASE efforts with improved zero-trust functionality in April and provided new artificial intelligence (AI) capabilities in August.
The benefits of Versa's zero-trust and AI capabilities will now extend beyond just the WAN. Sheu noted that the new SD-LAN solution extends the principles of SASE and security services edge (SSE) networking to LAN users.
“This means that access policies for users and devices are continuously adjusted based on identity, user or device posture, and the specific Application being accessed,” Sheu said. “As a result, SSE functions like ZTNA are now extended to users and devices connecting inside the Enterprise LAN at the campus or branch.”
In addition, the new Versa offering enables organizations to software-define the LAN, similar to the way that SD-WAN software is able to software define the wide area network, meaning software is now disaggregated from hardware.
“You now have a controller-based architecture that extends your overlay from the WAN to the LAN, closest to the user or device,” he said.
How the Versa SD-LAN worksIn terms of how it works, the Versa Secure SD-LAN is a license tier of Versa Network's software designed specifically for Enterprise LAN.
“It is infrastructure software that is part of our Versa Operating System (VOS) that runs directly on bare metal Versa-certified CSG WAN Edge appliances and Versa CSX SD-LAN switches,” Sheu said.
As part of its SD-LAN rollout, Versa also announced that its CSG3300 and CSG3500 appliances, which had already been providing routing and SD-WAN services, will now be certified for the SD-LAN software. Additionally, the Versa Networks CSX4000 and CSX8000 series Ethernet switches are now certified as well, bringing software-defined networking (SDN) capabilities inside of the LAN.
Zero trust is in the buildingWith SASE and SSE deployments, remote workers are a primary user group. Deploying zero trust for remote workers has long been a cornerstone of SASE, but that same type of zero-trust enforcement isn't typically used within a campus LAN. Versa is now changing that paradigm with its SD-LAN technology.
“This software introduces zero-trust policy and enforcement directly within the campus for on-premises users,” Sheu said. The end result: The same kind of conditional-access ZTNA that companies have for remote workers, which works to reduce the damage of security breaches by preventing lateral movement within a network, is now being applied to workers and devices within a campus or branch.
Comments