From time to time, every network and security vendor reveals new kinds of products. One example is SD-WAN. Nowadays, Software-Defined WAN is nothing uncommon, but five years ago, it was quite unusual. Today, SD-WAN technology is widely adopted.
Currently, something similar is happening with SASE (Secure Access Service Edge) products. Vendors are claiming that traditional remote access VPN technology is becoming obsolete and insecure, and that we should generally move to SASE. I guess they might have specific sales targets for their SASE products. 🙂
I conducted a Proof of Concept (PoC) for a SASE solution (the vendor is not important), and what are my opinions? Like every SaaS product, SASE — which is essentially a SaaS solution — has its limitations. If those limitations do not affect the capabilities of your infrastructure, then you don’t need to worry. I tested SASE to connect hundreds of branch locations, where traffic filtering was performed for both internet and data center traffic. Vendors claim that in this scenario, you can deploy simple devices at branches that only require IPsec support.
What limitations did I encounter? For large-scale implementations, we need dynamic routing. While SASE supports dynamic routing, it has limited capabilities. For instance, there were no options to filter BGP routes at the central SASE level. By default, SASE propagates all routes to every branch location without allowing any customization — a limitation that was a deal-breaker for both my customer and me. This happened about a year ago, and it’s possible that routing has become more advanced since then.
I also tested SASE for remote access purposes. In that case, I didn’t encounter any significant limitations. Compared to traditional remote access VPN solutions from the same vendors, the capabilities are more or less the same. The major difference is that SASE provides faster access to cloud resources, it is independent of hardware devices and on the other hand, much more expensive…
To summarize, every product is valuable to the extent that it solves specific problems or adds needed capabilities. I can’t definitively say that SASE is better than a typical remote VPN solution — it depends on the use case. However, SASE is definitely not the best option for connecting branches; in that scenario, SD-WAN should be our choice.