Multiprotocol label switching (MPLS) and other low-latency networks still have their place in a SASE world, according to Apcela CEO Mark Casey.

The managed service provider expanded its relationship with Versa today with the launch of Arcus, a platform designed to improve application performance across the vendor’s secure access service edge (SASE) platform.

Apcela operates a large, private MPLS network with more than 70 peering points globally. By combining its network with Versa’s SD-WAN and SASE platforms, Arcus is designed to address challenges faced by remote workers when accessing latency-sensitive applications by providing an alternative to the internet.

Traditionally, enterprises have relied on SD-WAN to route traffic over the internet or MPLS links based on application policy. Using SD-WAN, latency-sensitive applications could ride over the more reliable WAN link while less critical traffic is sent over the internet. However, with the shift to remote work due to the pandemic, addressing this challenge has become more challenging, Casey explained.

“Something like 70% of enterprise users are on virtual private networks (VPNs), [which] can be very stifling because they cause a lot of hairpinning,” he said. “If you’re based in New York and your data center is in Dallas, your VPN connection is going to take you [and all of your traffic] from New York, over the public internet, to Dallas” and then back again.

This is where SASE and zero-trust network access come in, Casey explained. They eliminate the need to backhaul all traffic to the corporate data center. However, Casey adds that sending business-critical traffic over the open internet is still far from ideal.

Apcela’s integration with Versa’s SASE shifts the SD-WAN-style routing into the SASE points of presence, thus allowing remote workers to achieve MPLS-like reliability even when accessing applications in geographically remote locations. This is because even though the traffic doesn't start on an MPLS connection, it only has to traverse a relatively short distance over the naked internet – from the worker's home to the nearest SASE point of presence – before it can be rerouted over Apcela’s private network.

Casey notes that the integration also opens the door to customizing the Versa's SASE capabilities. “One of the things that we really bring value is the ability to be backwardly compatible … We can service chain in Palo Alto technologies, Fortinet technologies, Symantec technologies, you pick your vendor.”

And the offering isn’t limited to existing Apcela customers either. Since the two companies have integrated their services via the Arcus platform, Versa’s SASE customers can now provision connectivity over Apcela’s network on demand and as a service.

Middle mile mania

Apcela’s partnership with Versa is the latest SASE or SD-WAN partnership to emphasize middle-mile connectivity.

Earlier this week, Google Cloud announced it had opened its private network to Cisco SD-WAN customers as a WAN link, and Cloudflare announced a similar service allowing VMware and Aruba hardware customers to route traffic over its own global backbone.

The core idea behind each of these services was providing users with an on-demand alternative to MPLS or broadband WAN connectivity, regardless of whether they are connecting branch to branch, branch to workload, or workload to workload.

Using cloud or service provider networks to augment cloud, SD-WAN, or SASE deployments isn't new, though it has gained momentum in recent months. Companies like Alkira and Aviatrix have effectively carved out a niche, effectively acting as middlemen for multi-cloud networking, automating the process of tying together workloads in disparate clouds.