Is SASE Just a Marketing Term?
An On-Premise IT Roundtable spotlight on Palo Alto Networks with Chris Grundemann and Rohan Grover. Recorded in the thick of the pandemic, when we were scaling customers onto Prisma Access in droves. SASE turned out to be more than a rebrand.
Gestalt IT's On-Premise IT Roundtable, a spotlight on Palo Alto Networks. Published 8 February 2021. Host: Tom Hollingsworth, with Chris Grundemann of Myriad360 and GigaOm, and Rohan Grover, Senior Director of Product at Palo Alto Networks.
Tom's premise was that SASE is more than a marketing term, and he admitted the cynicism up front: the industry has been burned by rapid rebrands before, and "a bunch of old things cobbled together" is a fair first reaction to Secure Access Service Edge. I was CTO at WAN Dynamics at the time, and we had spent 2020 living the reason SASE exists.
The sum greater than the parts
Rohan framed SASE as the natural next step after SD-WAN: networking moved to a cloud-delivered model first, and everyone quickly realized connectivity without security was not a transformation. Chris added the list of what gets bolted on, secure web gateway, firewall as a service, CASB and zero trust network access, all in service of one thing, a secure and mobile workforce. My take was the same one I had about SD-WAN itself. The technologies were not new, but the integration made the whole worth more than the parts, and it finally gave us a way to blend the WAN and security conversations that had always been a turf fight between two teams.
The department of no
Tom asked how to reduce that friction. Rohan's answer was role-based control, letting networking teams do their thing and security teams do theirs on one platform with some cross-pollination. My observation was that once the workforce scattered to home offices, the security team's assumption of total oversight was already slipping, and zero trust was how they were responding: nothing is trusted, and policy is defined the same whether the user is in the branch or at the kitchen table. Chris gave it the proper name, de-perimeterization. The users left the building and the applications left the closet.
What we saw in April 2020
The story I told was from the spring. Customers sent everyone home and discovered their data center firewalls could not terminate that many remote users. We used Prisma Access to scale the infrastructure elastically instead of guessing how many appliances to cobble together, and clients moved over in droves through April and May. Rohan had his own example, a professional services firm that went from a few hundred branches to 220,000 mobile users. Nobody manages that by hand; it has to be API-driven and automated from day zero. I called it connectivity transformation to go with digital transformation: SD-WAN made the WAN manageable, and SASE lets you build zero trust architectures that scale with the business, up when everyone goes home, and back down when they return.
The one feature to look for
Tom asked each of us for the single SASE capability a buyer should evaluate. Chris picked ZTNA, since a physical firewall still works fine in most places but zero trust is the genuinely new piece. Mine was one comprehensive network security policy: unified across branch, home and anywhere else, so you can change it quickly and know you are compliant everywhere. Rohan cheated and agreed with both, then added consistent user experience, because bolt-on solutions with pieces from everywhere are what fail in practice. Tom's summary was that security has to be shifted to the beginning of everything, not promised for later, and that is the case for buying it baked in.