91ÊÓƵ¹ÙÍø

SASE Access Architecture Becomes the Future of Cloud Security
Knowledge

SASE Access Architecture Becomes the Future of Cloud Security

Remote access and cloud computing access have become the new normal of global business after the epidemic. Enterprises are faced with many problems such as hybrid cloud configuration, diversified network access, key data security protection, and network access management.
Published: Jul 07, 2021
SASE Access Architecture Becomes the Future of Cloud Security

91ÊÓƵ¹ÙÍø to Remote access?

"Remote access" network security protection is the most concerned market. Mobile users access important enterprise applications, transfer key enterprise application data to cloud computing, or enterprise adopts hybrid cloud architecture, all of which connect the network infrastructure. The demand for the integration of online functions and network security functions has emerged. In response to this trend, Gartner has defined a SASE (Secure Access Service Edge) model based on cloud service SD-WAN technology and centered on user identity, which is considered the most important development trend of network security access architecture.

Remote access and cloud computing access have become the new normal of global business after the epidemic. Enterprises are faced with many problems such as hybrid cloud configuration, diversified network access, key data security protection, and network access management. Secure Access Service Edge (SASE) seems to be the best solution for cloud security at present. It integrates the needs of today’s enterprises for the network as a service and information security as a service and integrates comprehensive wide area network WAN functions (including SD-WAN, CDN, etc.) Integrating with network and cloud security functions (such as SWG, CASB, FWaaS, and ZTNA), is based on user identity (maybe specific individuals, branch employees, third-party vendors, specific IoT devices) at the edge of the network. Network access permissions are shunted, and then applications or smart data are accessed directly to corporate data centers or public cloud applications or platforms, instead of importing network traffic to the head office and then transferring it to the cloud, which would increase data transmission risks from attack.

SASE network edge security access service architecture introduction:

Under the impact of the 2020 epidemic, VPN (Enterprise Virtual Private Network) was the first remote access solution for enterprises. 91ÊÓƵ¹ÙÍøever, with the new normal operating model of a remote office, enterprises are accelerating the deployment of many cloud services and applications. With the rapid development of cloud data centers and mobile offices, VPNs are facing great challenges by breaking the familiar network boundary protection. Only by establishing a "trusted" security management model can the user's authentication and authorization be credible, and the information flow and information security risks can be visible, controllable, and manageable.

The Zero Trust network security framework (Zero Trust) believes that any network access requirements should be preset to be untrustworthy, and only after authentication can they be accessed by the management policy authority. 91ÊÓƵ¹ÙÍøever, the zero-trust architecture does not refer to a specific technology, but the concept of application integration of multiple technologies. Therefore, the SASE (Secure Access Service Edge) market has become the best practice for "zero-trust" security in enterprises now.

What is SASE?

SASE is to implement identity management on the terminal equipment and the edge of the network, while network traffic is diverted to the application cloud platform or the data center in the enterprise according to the identity management policy, and the network security functions and equipment are all Built-in cloud solutions. Especially in the long-distance working mode after the epidemic and the advent of the 5G era, this trend will become more and more obvious, and the market demand will continue to grow. Under the new normal, the use of traditional network access mode in this environment will bring very complex network management configuration problems. With SASE architecture, wide area network connection capabilities (such as SD-WAN) and network security protection capabilities (such as SWG, CASB, FWaaS) are integrated, thereby effectively reducing the complexity of network control. Not only can it provide a flexible and expandable network, but it can also provide software-defined security access services based on user rights policies. This flexible network provides unprecedented network visibility and manageability for the security teams of digitally transformed enterprises. The network connection can be precisely specified according to the user identity and the context of the packet content. The security team can provide secure data access, QoS performance, reliability, and security for mobile users, and branch teams, with cloud-based application services, to safely realize the dynamic storage required for digital transformation.

The SASE network edge secure access service architecture has the following characteristics:
  1. Focus on user identity: Network Edge Secure Access Service (SASE) is a new center for using identity as the access decision-making center, not the access authority of the enterprise data center. Therefore, network access permissions are based on identities such as user identity, connected device identification, and application access permissions, rather than the IP address or geographic location of the device as in the past. It is this logic-level conversion of defined policies that greatly simplifies security policy management.
  2. Take the cloud application as the native architecture: The biggest assumption of SASE is that enterprises will gradually cloud important data and services, or directly adopt public cloud SaaS services (such as CRM, Mail, office software...), so they are outside the company. Mobile users or overseas branch offices will not redirect all network traffic back to the headquarters due to the use of VPN, nor will they allow free access to wide-area network services and lose network security protection. SASE makes full use of the main features of cloud computing in its architecture, such as flexibility, self-adjustment, automation, self-healing ability, and self-maintenance.
  3. Simplified architecture of network security equipment and configuration: By integrating secure access services from third-party security product providers, it will effectively reduce the total number of suppliers and reduce the number of physical or virtual security devices in overseas branches. This will reduce the number of agents required on the user’s terminal device. At the same time, the integration of supplier equipment will have the opportunity to use the "single-pass" architecture for network content inspection. Under this architecture, all packets at the network session layer will be decrypted at once and checked once in parallel using multiple security policy engines (FW, IDS) instead of multiple security check engines for serial check, which would increase the delay time. This will provide users with a consistent network access experience no matter where the user is, what site they are visiting, or where the site is located.
SASE architecture is the integration of network services and security services

The SASE architecture represents the structural integration trend of corporate networks and security systems. It is suitable for the trend of remote access and corporate services on the cloud under the current epidemic. It integrates security and network access and can be applied to any type of terminal access method. Enterprises do not need to place an agent on the device, and do not need to connect to the VPN and then reroute all traffic to the Internet. The SASE architecture brings security to each access service. It is estimated that by 2024, at least 40% of enterprises will adopt SASE-based cloud services.

It is not easy to build a complete SASE access service platform, as it requires extensive and diversified technologies. At present, few vendors can provide complete solutions in the market. This technology is still in its infancy, but as cloud services continue to grow, the SASE access service platform will drive the demand for edge computing equipment, and future growth is still expected.

Published by Jul 07, 2021 Source :

Further reading

You might also be interested in ...

Headline
Knowledge
The Essential Role of Carbon Pre-Filters in RO Filtration Systems
Reverse osmosis (RO) filtration systems have long been regarded as one of the most effective methods for purifying water, removing contaminants, and improving water quality. 91ÊÓƵ¹ÙÍøever, thin-film composite (TFC) membranes are highly sensitive to chlorine, making carbon pre-filters essential for preventing membrane damage and ensuring long-term system efficiency. Carbon pre-filters protect the delicate membrane by reducing chlorine, sediment, volatile organic compounds (VOCs), and other impurities that could deteriorate the membrane and compromise performance. Over the years, advancements in carbon filtration technology have enhanced the effectiveness of RO systems, ensuring cleaner and safer water for residential, commercial, and industrial use.
Headline
Knowledge
PE Tubing for RO Filter Systems
Polyethylene (PE) tubing plays a crucial role in ensuring the safe and efficient transfer of water within RO filtration systems. Recognized for its durability, flexibility, and resistance to contaminants, PE tubing has become a preferred choice for both residential and commercial water purification applications. PE Tubing is used in RO Systems for nearly all water connections including inlet, membrane, storage tank, faucet, and drain line tubing. The benefits, types, materials, manufacturing process, and best practices for using RO filter system PE tubing are extensive.
Headline
Knowledge
Faucets in RO Filter Systems: Enhancing Performance and Aesthetics
One often overlooked component of drinking water filtration systems that significantly impacts both functionality and aesthetics is the filter system's faucet. A high-quality faucet not only ensures smooth operation but also enhances the user experience and complements the kitchen design. The right faucet for an RO system combines durability, safety, and convenience with a stylish appearance that blends seamlessly with both modern and traditional kitchen designs.
Headline
Knowledge
Pressure Gauges for RO Water Filter Systems
With any water filtration system, ensuring optimal system performance is critical for maintaining water quality and extending the lifespan of filtration components. Reverse osmosis (RO) water filter system pressure gauges are an effective solution for monitoring pressure fluctuations within filtration systems, helping users detect potential issues before they compromise water quality. By providing real-time pressure readings, these gauges enable users to assess the condition of their filters, diagnose clogs, and ensure proper system operation.
Headline
Knowledge
Garden Hose Spray Nozzles
Garden Hose Spray Nozzles attach to the end of a garden hose and provide a versatile solution to water distribution, allowing for everything from a fine mist for delicate flowers to a strong jet for cleaning garden paths. They not only help in efficient water management but also make gardening tasks more convenient and effective. Beyond garden care, these nozzles are incredibly versatile in their applications. They can be used for washing cars, cleaning outdoor furniture, and even bathing pets. This adaptability makes them an indispensable tool in any household. By controlling the spray pattern and intensity, water is utilized more efficiently, reducing waste and saving on water bills, which is particularly beneficial in regions with water usage restrictions.
Headline
Knowledge
Pressure Storage Tanks for RO Filter Systems
Reverse Osmosis (RO) filter systems have revolutionized water purification by removing contaminants at the molecular level, thereby providing high-quality drinking water. 91ÊÓƵ¹ÙÍøever, RO filtration is a slow process and cannot deliver immediate high-flow water like standard filtration methods. Without a storage tank, an RO system would require several minutes to fill just a single glass of water. Relying solely on direct filtration would be impractical for everyday use. To address this issue, RO filter systems employ a pressure storage tank that accumulates purified water, keeping it under a moderate pressure, sufficient to make it ready for immediate and convenient dispensing. These tanks have become an essential component of RO systems in residential, commercial, and industrial settings.
Headline
Knowledge
Benefits and Applications of Garden Rakes and Hoes
Garden rakes and hoes are indispensable tools for both professional landscapers and home gardeners. They have been used for centuries to cultivate, maintain, and enhance soil conditions, ensuring that gardens thrive. Their versatility and effectiveness make them essential for various gardening and landscaping tasks, including: Soil Preparation: Loosening compacted soil for better aeration and water penetration. Weed Control: Removing unwanted plants efficiently without using chemicals. Debris Removal: Clearing leaves, twigs, and other organic matter from garden beds and lawns. Leveling and Smoothing: Ensuring even distribution of soil, mulch, or compost. Furrowing and Planting: Creating uniform rows for planting seeds and seedlings.
Headline
Knowledge
RO Filter System Booster Pumps and Why a Diaphragm Pump Is the Best Choice
If you're considering purchasing a reverse osmosis (RO) water filtration system, you may have noticed that some models include a booster pump while others do not. If you’re unfamiliar with the technology, you might wonder: Why does an RO system need a pump? The short answer is that water pressure is crucial for efficient RO filtration, and a booster pump improves this system efficiency. So, you may then wonder, what does a diaphragm pump do, and why is it considered the best choice for RO filtration? Let’s examine why a diaphragm pump is the most reliable and effective type of pump for this application.
Headline
Knowledge
Garden Shovels: The Essential Tool for Every Gardener
Gardening has long been a rewarding hobby, as well as an essential practice for providing food, beauty, and practical benefits for any home or other environment. As gardening techniques evolved, so did the need for specialized tools, and among these, the garden shovel became an indispensable tool. There are a variety of garden shovels and trowels available, and it is interesting to note that gardeners can be quite particular when it comes to choosing their favorite hand trowel or shovel.
Headline
Knowledge
Grass Shears: Precision Cutting for Lawn Care
Grass shears have long been recognized as an effective solution for trimming grass in areas where traditional lawnmowers cannot reach. They offer precision cutting, allowing gardeners and landscapers to maintain clean, well-defined edges along pathways, garden beds, and other landscaping features. Advances in materials and design have improved their efficiency, durability, and ease of use.
Headline
Knowledge
Hedge Shears: Essential Tools for Precision Gardening
A good pair of hedge shears can easily transform unruly bushes into beautifully manicured landscapes. Hedge shears have been a staple tool in both amateur and professional gardening for decades, providing a practical solution for shaping and controlling plant growth, transforming unruly hedges into neat, visually appealing landscapes.
Headline
Knowledge
Introduction to Tree Pruners
Tree pruners, often referred to as pole pruners or tree trimmers, have been recognized as an ideal solution for maintaining and managing tree growth in both urban and rural landscapes. These tools facilitate the safe and efficient pruning of branches that are otherwise difficult and hazardous to reach. By enabling users to trim trees from the ground without the aid of ladders or climbing equipment, tree pruners help avoid the risks associated with traditional tree trimming methods.
Agree