Blog
The Network Architecture of the New Way of Working: SASE
5 April 2023

SASE (Secure Access Service Edge) is a vision of converged technologies for improving network performance and security for users who may be anywhere, may be using any device, and need to reach content and applications in corporate data centres and on cloud platforms.
The core goal of the SASE architecture is to provide a seamless user experience, improved connectivity and comprehensive security in a way that supports the dynamic secure access needs of digital organizations. Rather than backhauling traffic to traditional data centres or private networks for security inspection, SASE allows devices and remote systems to reach applications and resources seamlessly, wherever they are and at any time.
SASE has four fundamental attributes:
1. Identity-driven: access is granted based on the identity of users and devices.
2. Cloud-native: both the infrastructure and the security solutions are delivered from the cloud.
3. Supports all edges: every physical, digital and logical edge is protected.
4. Globally distributed: users are secure wherever they work.
The core components of SASE
Software-defined wide area network (SD-WAN)
A software-defined wide area network is a layered architecture that uses routing or switching software to create virtual connections between both physical and logical endpoints. SD-WANs provide near-limitless paths for user traffic, improving the user experience and giving strong flexibility in encryption and policy management.
Secure web gateway (SWG)
A secure web gateway is a web security service that prevents unauthorized traffic from reaching a given network. The goal of an SWG is to neutralize threats before they enter a virtual perimeter. It does this by combining technologies such as malicious code detection, malware removal and URL filtering.
Cloud access security broker (CASB)
A cloud access security broker is a SaaS application that acts as a security checkpoint between on-premises networks and cloud-based applications and enforces data security policies. CASB protects corporate data through a combination of prevention, monitoring and risk mitigation techniques. It can also identify malicious behaviour and alert administrators to compliance violations.
Firewall as a service (FWaaS)
Firewall as a service moves firewall protection from the traditional network perimeter to the cloud. This allows organizations to connect a remote, mobile workforce to the corporate network securely while continuing to enforce consistent security policies beyond the organization's geographic footprint.
Zero Trust Network Access (ZTNA)
Zero Trust Network Access is a set of converged, cloud-based technologies running on an infrastructure where trust is never implicit and access is granted on a need-to-know, least-privileged basis across all users, devices and applications. In this model, every user must be authenticated, authorized and continuously validated before being granted access to private corporate applications and data. ZTNA removes the poor user experience, operational complexity, cost and risk of a traditional VPN.
Central, unified management
A modern SASE platform allows IT administrators to manage SD-WAN, SWG, CASB, FWaaS and ZTNA through central, unified management across network and security. That lets IT team members focus their energy on other, more pressing areas and improves the user experience for the organization's hybrid workforce.

The advantages of SASE
SASE platforms offer significant advantages over traditional on-premises network options. Here are some of the main reasons organizations may want to move to a SASE infrastructure:
1. Lower IT costs and less complexity
Older network security models rely on a range of solutions to secure the network perimeter. SASE saves IT costs and simplifies management by reducing the number of solutions needed to protect applications and services.
2. Greater agility and scalability
Because SASE is delivered from the cloud, both the network and the security infrastructure are fully scalable. The system can grow as your organization grows, which makes it possible to accelerate digital transformation.
3. Designed to sustain hybrid work
Where traditional hub-and-spoke networks struggle to handle the bandwidth needed to keep remote workers productive, SASE provides enterprise-grade security for every user regardless of how and where they work.
4. A better user experience
SASE improves security for users by managing security trade-offs intelligently in real time. This reduces the latency users experience when connecting to cloud applications and services and shrinks the organization's attack surface.
5. Stronger security
In a SASE infrastructure, SWG, DLP, ZTNA and other threat analysis technologies come together to give remote workers secure access to corporate resources while reducing the risk of lateral movement on the network. With SASE, every connection is inspected and secured, and threat protection policies are clearly defined in advance.
Why SASE?
Even when digital transformation is highly complex and costly, organizations are embracing it through initiatives such as mobility and cloud that promise greater productivity, efficiency and competitiveness. Delivering that transformation, however, brings problems of its own, including compromised security visibility and control, along with added complexity, higher costs and lower performance.
SASE helps you solve those problems by converging network and security as a service in a cloud-delivered service model, allowing you to achieve:
- An optimized user experience
- A move to the cloud without complexity
- A productive remote workforce
References
-https://www.microsoft.com/tr-tr/security/business/security-101/what-is-sase
-https://www.broadcom.com/solutions/symantec-security-solutions/secure-access-service-edge