What is Secure Access Service Edge (SASE)?
Secure Access Service Edge (SASE) is a network architecture that combines wide-area networking (SD-WAN) with a suite of cloud-delivered security services in a single platform. It is designed to give users, devices, and branch offices secure access to applications regardless of location.
What it does
SASE merges two historically separate disciplines: network connectivity and network security. A SASE platform typically bundles several functions into one service:
- SD-WAN: routes traffic intelligently across multiple links (broadband, MPLS, LTE).
- Secure Web Gateway (SWG): filters web traffic and blocks malicious sites.
- Cloud Access Security Broker (CASB): enforces policy on cloud application usage.
- Zero Trust Network Access (ZTNA): grants per-application access based on identity and device posture, replacing broad VPN tunnels.
- Firewall as a Service (FWaaS): applies firewall rules in the cloud rather than at a physical appliance.
Some platforms also include Remote Browser Isolation (RBI), Data Loss Prevention (DLP), and DNS security. Traffic inspection happens in the cloud, close to the user, rather than being backhauled to a central data center.
Why teams buy it
Organizations with many branch offices or remote workers face a common problem: routing all traffic through a central data center adds latency and creates a bottleneck. SASE moves security inspection to the cloud edge, so a user in a remote office gets the same policy enforcement as someone on the corporate LAN. Teams also buy SASE to reduce the number of point products they manage. Replacing separate SD-WAN appliances, VPN concentrators, and web proxies with one platform lowers operational overhead.
What to look for
- Convergence depth: does the vendor own both the SD-WAN and the security stack, or is one OEM'd from a third party?
- PoP coverage: how many cloud points of presence exist, and are they near your users?