Section 16.153 SD-WAN and SASE Flashcards
Objective 3.2 Given a scenario, you must be able to apply security principles to secure enterprise architecture. Objective 4.5 Given a scenario, you must be able to modify enterprise capabilities to enhance security
SD-WAN (Software-Defined Wide Area Network)
A virtualized approach to managing and optimizing wide area network connections to efficiently route traffic between remote sites, data centers, and cloud environments
● Software-based architecture with control extracted from underlying
hardware
SD-WAN (Software-Defined Wide Area Network)
Benefits
Increased agility, security, and efficiency for geographically distributed workforces
SD-WAN (Software-Defined Wide Area Network)
Transport Services
Allows the use of various transport services:
○ MPLS
○ Cellular
○ Microwave links
○ Broadband internet
SD-WAN (Software-Defined Wide Area Network)
Centralised Control
Utilises centralised control function for intelligent traffic routing
SD-WAN (Software-Defined Wide Area Network)
Traditional WAN vs. SD-WAN
Traditional WANs: Cannot efficiently integrate cloud services
SD-WAN: Enables dynamic and efficient routing, improving visibility, performance, and manageability
SD-WAN (Software-Defined Wide Area Network)
Use Cases
Ideal for enterprises with multiple branch offices moving towards
cloud-based services:
○ IaaS
○ PaaS
○ SaaS
SASE (Secure Access Service Edge)
A network architecture combining network security and WAN capabilities in a single cloud-based service/solution
● Addresses challenges of securing and connecting users and data across distributed locations
SASE (Secure Access Service Edge)
Key Technology
Utilises software-defined networking (SDN) for security and networking
services from the cloud rather than traditional based network solution
SASE (Secure Access Service Edge)
Components/Security Services
● Firewalls
● VPNs
● Zero-trust network access
● Cloud Access Security Brokers (CASBs)
SASE (Secure Access Service Edge)
Policy and Management
Delivered through a common set of policy and management platforms
SASE (Secure Access Service Edge)
Cloud Providers
Major cloud providers offer services aligned with SASE: they will call it something esle
○ AWS = Virtual Private Cloud (VPC)
○ Azure Virtual WAN
○ Azure ExpressRoutes
○ Google Cloud Interconnect
○ Google Cloud VPN
These cloud services offer secure, flexible, and global networking capabilities, aligning with SASE principles