Ericsson bolstered its NetCloud secure access service edge (SASE) platform with a clientless zero-trust network access (ZTNA) option that allows customers to connect third-party and bring-your-own-device (BYOD) users. The move follows recent hardware- and software-related updates to the equipment providers Cradlepoint offerings.
Bruce Johnson, senior product marketing manager at Ericsson explained that the clientless platform uses ZTNA concepts and an isolated environment to host and manage connections. It does this by hosting those connections in a containerized environment without the need for agents or plugins.
“They click on that URL and that URL actually lives in an isolated cloud portal, a cloud container, with all of the interaction between that unmanaged user and the applications they're accessing happens in that isolated container through the portal,” Johnson said. “They can get through and interact with the application, but in a sense they're doing it through … that portal.”
This allows for isolated control to enact an enterprise’s security without having to install any software onto that remote device. This makes it especially useful for IoT and hard-to-secure devices.
“It's quite common that somebody that's connecting to our network that we don't manage could have a security posture that's below our standards,” Johnson added. “They might have malware on the machine, and so when they connect to our network, it's quite possible that that malware could spread to our corporate applications or our or our corporate systems, and we don't want that to happen.”
Johnson also noted that this differentiates the product in the market.
“Clientless ZTNA has been out in the market with some of our competitors for a while now, but most of them are using either browser plugins or they're using something like an enterprise browser, so it's outside of the normal comfort zone that a lot of people are used to working in,” Johnson said.
The clientless access runs through the NetCloud SASE product, which is the cloud-delivered version of that platform. Ericsson will also continue to offer its legacy client-based version that runs through either a customer-hosted on-premises gateway or Ericsson-hosted using the vendor’s cloud infrastructure.
The initial clientless launch is targeted at monitoring the application, with support for direct management of IoT devices coming in a few months.
This access control method originated from Ericsson’s Ericom Software acquisition in 2023. That platform was added to Ericsson’s Cradlepoint NetCloud Exchange offering to provide a converged networking and security software stack for cellular-focused enterprise customers.
Ericsson accelerates enterprise SASE focus
The new offering also bolsters Ericsson’s growing enterprise focus. That effort accelerated with the $1.1 billion Cradlepoint acquisition that closed in late 2020, and hit an integration inflection point late last year.
Ericsson more recently launched a new enterprise networking combination that included the latest Cradlepoint E400 router, which houses support for the 3GPP Release 17 specification for 5G cellular, Wi-Fi 6, and low-earth orbit (LEO) satellite connectivity. It also includes the latest Cradlepoint LAN switches and access points.
The new products are managed by the NetCloud Manager platform that is a centralized point of control and provisioning of the network resources, embedded eSIM, and dual-SIM device capabilities. The NetCloud platform also supports SASE, SD-WAN, and 5G network slicing control, which includes the ability to bond different network access paths.
Johnson explained that all of Ericsson’s SASE products run on the NetCloud Manager and that the E400 platform includes a secure connect license, which is part of the NetCloud SASE, but that it doesn’t come embedded with the full NetCloud SASE suite.
Ericsson’s SASE update comes as analysts predict continued growth for the segment.
Dell’Oro Group recently predicted the overall SASE space will hit $17 billion in revenues by 2029, surging at a 12% compound annual growth rate (CAGR) over that time period. The firm added that the market will see a growing number of vendors offering SD-WAN and security services edge (SSE) capabilities that power single-vendor SASE platforms and will account for 90% of the total SASE market.
Mauricio Sanchez, senior director for enterprise security and networking at Dell’Oro Group, explained in an interview that the security (SSE) aspect remains the driving force behind SASE “while bringing along networking.”
“I think people realize that trying to treat these separately as has been done in the past doesn’t lead or it’s very hard or possible to get to the end result, which is a much more secure WAN-branch network,” Sanchez said. “I don’t want to minimize [networking], I think that’s still part-and-parcel to why people are leaving access routing … so we shouldn’t minimize that piece. But I think what the higher strategic goal here is let’s embrace this and do the total transformation because it’ll get us a better security outcome, and along with it get to a better networking outcome.”
Comments