Secure access service edge, better known by its sassy sounding acronym SASE, is quickly crystallizing as the way forward for distributed enterprise and not just because it's fun to say.
Well OK, let's be honest, if you can read SASE without at least thinking about snapping your fingers and whipping your hair, it's time to take a break and go outside.
Since Gartner analysts first described the category in their 2019 Hype Cycle report, we've seen security and SD-WAN vendors of all shapes and sizes get a whole lot SASE-er.
Vendors like Cato Networks, whose platform already closely resembled a SASE, were quick to adopt the sigil. It didn't take long before industry giants like VMware and Palo Alto Networks, trailed by a stream of smaller vendors, joined in on the fun, albeit often without a complete SASE stack. And in the past few weeks, Cisco and Versa have thrown their weight behind the architecture too.
At this point, there's no question SASE is more than hype.
What the Hell Is a SASE, Really?While Gartner's literature does a good job laying out the framework for a SASE, what that looks like in the real world is often less obvious. Over the last nine months or so I've heard various vendors describe what a SASE is and how theirs is different from the next.
Fundamentally, SASE is a fairly simple concept: it stitches together elements of SD-WAN and security into a single cloud-native package.
It makes a certain kind of sense when you consider security has increasingly become a differentiator among SD-WAN vendors. Further, SASE promises much tighter integration between security and SD-WAN than can be achieved through simple service chaining.
However, this really only describes the secure access part of what a SASE is. The other piece of the puzzle is, you guessed it, the service edge, which refers to the network of points of presence (PoPs) on which the service runs. This is opposed to most SD-WAN platforms where the software stack runs on an appliance on premises.
You can think of the service edge as kind of like a train station where the train is always ready to go — what a dream right. Traffic takes a short trip to the nearest station — the PoP — where it passes through security, is assigned an identity, and travels to the station nearest to where it's going. Once it arrives, the traffic leaves the station and travels to its final destination whether that be in the cloud, a private data center, or in some cases the station itself. The larger and more diverse the vendor's service edge, the faster and more reliably the traffic can get to and from its destination.
Why Get SASE?From a business standpoint, the advantages of a SASE platform are even simpler and more transparent. Traditionally, functions like quality of service (QoS) or next-generation firewalls have only been available when connecting to an appliance.
However with SASE, workers can take advantage of SD-WAN functionality and enhanced security from anywhere using an agent running on their computer or mobile device.
In most cases, these agents don't do much more than connect to the nearest PoP and identify the user. Most of the SD-WAN and security functions run in the service edge.
But by eliminating the need and the cost of an SD-WAN appliance, and with many vendors delivering SASE as a software-as-a-service (SaaS) model, the barrier to entry is actually much lower than SD-WAN, despite what is often a much more diverse feature set.
With the sudden influx of workers as a result of the pandemic, we've seen several early SASE vendors benefit from this low barrier to entry.
Not long after work-from-home orders started going into effect around the world, Cato updated its SASE platform with a single sign-on feature designed to help remote workers access their SaaS and legacy applications.
Meanwhile, Palo Alto Networks on its third-fiscal quarter earnings call reported strong sales of its Prisma Access SASE platform, driven by the rapid change in workforce dynamics.
And Versa CMO Mike Wood said the company's decision to move up its own SASE launch was also motivated by the pandemic.
Having a Complete SASE Stack Now May Not MatterWhile the SD-WAN market is maturing rapidly and the security market is well established, SASE is still very much in its infancy. Very few vendors have managed to build a full SASE stack, and some vendors, like Cato and Netskope have been quick to point that out.
However, I'm not sure the lack of a complete SASE stack from the get-go is as big a disadvantage as one might think.
Building out a full SASE stack isn't easy and buying one is absurdly expensive. To that point, Palo Alto paid $420 million for SD-WAN vendor CloudGenix to fill the gaps in their SASE.
Now that's not to say vendors that do have a complete or nearly complete SASE stack won't have a competitive advantage early on. They almost certainly will, especially given SASE's low barrier to entry.
But many of these vendors will be fighting against entropy here. Change is hard and expensive. So, for a good number of enterprises it wouldn't surprise me if they put up with their existing SD-WAN vendor's incomplete SASE offering rather than deal with the added complexity of another service, even if it is demonstrably better.
With that said, vendors that can provide a full SASE stack while undercutting their competition could steal away customers from more established vendors.
What Does This Mean for the Future of SD-WAN?Questions about what SASE will mean for the SD-WAN market is something I've been seeing more and more often lately. During a recent presentation put on by VMware COO Rajiv Ramaswami compared SD-WAN to SASE.
However, while SD-WAN and SASE achieve very similar results, they are not mutually exclusive. There are no doubt going to be enterprises that will stick with rigid SD-WAN and security for some parts of their network while rolling out SASE in others.
This is a belief shared by Cisco, which announced their transition to SASE late last month.
In an interview with Scott Harrell, SVP of Cisco’s intent-based networking group, he explained that the adoption of SASE will likely be a gradual process as enterprises reassess how they connect a global workforce to an increasingly distributed landscape where applications and resources are located in multiple clouds.
I don't think SD-WAN is going anywhere, but I do expect SASE will become a much bigger part of the conversation moving forward.
Comments