Rajiv Ramaswami, VMware's COO of products and cloud services, discussed the nuances of SD-WAN and secure access service edge (SASE) at a Piper Sandler event last week. He also managed to open a can of worms on the efficacy of SASE service chaining.

Service chaining is a practice commonly used by SD-WAN vendors to integrate functions like security from other vendors.

During the event, Ramaswami argued that VMware's network of gateways — the points of presence on which VMware's SASE runs — put it in a unique position to stitch together multiple services.

“The traffic comes from the user, wherever they are, into one of our gateways. And at that gateway, it's a great place for us to deliver a range of services. Some of the services could be VMware built and delivered, and some of it could be partner ecosystem,” he said. “For example, we are able to partner with all the secure web gateway providers, and we can actually stitch and service chain to them if needed.”

The Problem With Service Chaining

In its 2019 Hype Cycle report describing the SASE category, Gartner analysts explicitly warned customers to be wary of vendors trying to service chain multiple services to reduce the time to market.

According to Gartner analyst Neil MacDonald, who co-authored the original report on SASE, service chaining is fraught with problems that make it highly inefficient for a SASE architecture.

“In theory, you could service chain secure web gateway from one vendor to cloud access security broker from another, and then, perhaps, daisy chain that to another vendor to do sensitive data inspection, perhaps yet another vendor to do malware inspection and sandbox detonation,” he said, in an interview with SDxCentral. “The latency, the user experience would be horrible.”

MacDonald explained that each service in the chain introduces latency, and that latency is further exacerbated by encrypted traffic.

“Of course when you go to Office 365, that's all encrypted. Google Apps, that's all encrypted. Even when you go to your banking site, search engines, it's all encrypted,” MacDonald said. “How are you going to inspect that? Well, the answer is we decrypt the session, and you can inspect the payload and content.”

The more services that are chained together, the more often the traffic has to be decrypted and inspected. This introduces risk because each service has to have a copy of the encryption key, MacDonald explained.

Service chaining is also a management nightmare when it comes to applying consistent policy across the services.

“You've got one vendor's console to set policies for secure web gateway access, which is different than the console to set policies for [cloud access security broker], which is different than the policies to set access for the private apps,” MacDonald said. “It makes no sense.”

Converged Vs. Integrated

Cato Networks, which was among the first vendors to adopt the SASE category as their own, has been critical of the approach taken by some vendors in the space.

Many of the early SASE vendors lack the complete SASE stack and instead rely on partners for services, said Cato CEO Shlomo Kramer in an interview with SDxCentral. “Something that many companies that call themselves SASE are conveniently forgetting or ignoring, is that the key here is convergence between the network and network security, not just convergence of network security services like Zscalar does or Netscope does,” he said.

But while MacDonald called out service chaining as inefficient, he dismissed the idea that SASE vendors have to provide the full software stack. That argument he said, “just sounds like vendors trying to say 'well, if you don't have both pieces you can't compete here, effectively.' That's not true.”

MacDonald explained that how SASE is ultimately architected, whether it be a single-vendor approach or split networking and security approach, is going to depend on what investments the enterprise may have already made.

“Have they already made an SD-WAN decision? If not, then they absolutely would be open to the idea of a single vendor providing both. If they have, they can connect the two easily because, in either situation, you're connecting the branch to a security hub,” he said.

However, MacDonald notes that this only works if the security fabric is a “single-pass architecture” and isn't the product of service chaining.

Life in the Real World

Open Systems, an SD-WAN and managed service provider turned SASE vendor, looks at service chaining more like a necessary evil. “Service chaining in our mind, and I think in the in the SASE element side of that, doesn't work particularly well,” admitted Open Systems CEO Jeff Brown.

Very few enterprises can make a clean switch to a SASE model because they “still have a fair amount of legacy at the edge that we have to deal with. So, there's a hybrid model there that has to work,” he said.

One scenario where service chaining may become unavoidable, at least temporarily, is when dealing with mergers and acquisitions, Brown added. In this case, he said enterprises need a vendor and service provider that can guide them through the migration.