The secure access service edge (SASE) promises to address changing enterprise traffic patterns, and threatens to render SD-WAN stalwarts irrelevant in the coming years, according to a recent Gartner report.

In its 2019 Hype Cycle report, Gartner defines SASE — pronounced "sassy" — as an emerging market that combines elements of SD-WAN and network security into a single cloud-managed package.

It's a technology that Gartner has called "transformational."

"SASE will be as disruptive to network and network security architectures as [infrastructure-as-a-service] was to the architecture for data center design," the report claims.

SASE vs. SD-WAN

Unlike a traditional WAN, SASE does away with the concept of connecting the branch to the central office and instead shifts to a model that connects users and equipment at an individual level to a centralized cloud-based service.

In traditional enterprise networks the data center is the focal point for access. Gartner contends that this approach has become increasingly ineffective as businesses transition to software-as-a-service (SaaS), cloud services, and edge compute platforms.

Gartner acknowledges that the enterprise data center isn't going anywhere soon, but maintains that it will become less relevant as service move to the cloud. The enterprise data center effectively becomes just another branch.

"A branch office is simply a place where multiple users are concentrated," the Gartner report states, and the same is true for a salesperson working remotely, only they are a branch of one.

According to Gartner, SASE brings with it several advantages over existing technologies, not the least of which include greater flexibility for the end-user, reduced operational complexity and costs, and better performance.

Distributed Access

The distributed nature of SASE will make the number of points of presence (P0Ps) offered by a vendor an important factor for customers evaluating a solution.

"The SASE solution should offer distributed [PoPs] and a portfolio of traffic-peering relationships," the report notes.

This approach means enterprise data will only rely on the open internet to get to one of the SASE vendor's PoPs.

Emphasis on Security

SASE will also open the door to enhanced security features including support for content inspection and zero-trust network access. Enterprises using a SASE platform supporting content inspection could scan active sessions for malware and sensitive content regardless of where the device or user are located.

And because SASE doesn't rely on the IP address or physical location of the device for policy enforcement, Gartner says enterprises can employ a zero-trust approach to networking, allowing for consistent policy enforcement and security wherever the user is working.

Emerging SASE Market

While still a relatively new technology with less than 1% adoption, Gartner anticipates many vendors will begin rolling out SASE products over the next several months.

Gartner reports that no vendors are offering a comprehensive SASE product today, but notes there are several SD-WAN and cloud-based security providers well-positioned to move into the space in short order. Even then the technology isn't expected to reach mainstream appeal for another five to 10 years, and is likely to undergo significant changes within that span of time.

Because of this, Gartner warns early adopters to limit contracts to no more than two years and include acquisition protection clauses. It also warns customers should be wary of vendors trying to link several services together using virtual machine (VM) service chaining to reduce the time to market.

"This approach may speed time to market but will result in inconsistent services, poor manageability, and high latency," the vendor explains.