Network Design & Resilience

SASE Explained: What It Is, What It Replaces, and Whether You Need It Yet

SASE is sold as a single product, but it is really a change in where security happens. Here is what is inside it, what it replaces, and when it is worth the switch.

SASE (secure access service edge, pronounced "sassy") combines SD-WAN networking with security services delivered from the cloud: web filtering, cloud app control, zero trust remote access and a cloud firewall. Instead of hauling every site's and every remote worker's traffic back to a firewall at head office, each user and location connects to the provider's nearest point of presence, and policy is applied there. It pays off when staff work from many places and most applications live in the cloud. A single office with everyone at their desks may not need it yet.

The term gets attached to a lot of products, so it helps to take it apart. Underneath the acronym is a fairly simple idea about where security inspection should happen now that the office is no longer where the work is.

The problem SASE was invented to solve

The traditional design put everything valuable in a head office or data centre, protected by a firewall. Branches connected back over private circuits, remote staff connected in through a VPN, and all internet traffic went out through that one firewall where it could be inspected. It made sense when the applications were in the server room.

Now the email, the files, the CRM and the phone system are cloud services. A branch worker opening a cloud app still gets sent to head office first, inspected, then sent back out to the internet. That round trip is called hairpinning, and it adds delay, fills the head office circuit and makes the head office firewall a single point of failure for every location.

The analyst firm Gartner coined "SASE" in 2019 for the alternative: move the inspection into a cloud network with points of presence near users, and let every site and person reach it directly.

What is inside SASE

ComponentWhat it doesWhat it usually replaces
SD-WANManages the circuits at each site and steers traffic over the best pathBranch routers and private-circuit meshes
Secure web gateway (SWG)Filters web traffic, blocks malicious sites, enforces acceptable useOn-site web filters and proxy servers
Cloud access security broker (CASB)Sees and controls use of cloud apps, including unapproved onesLittle, usually; it fills a gap
Zero trust network access (ZTNA)Gives users access to specific applications after checking identity and device, rather than putting them on the whole networkThe remote access VPN
Firewall as a service (FWaaS)Firewall policy applied in the cloud for all trafficSome or all branch firewalls
Data loss prevention (DLP)Watches for sensitive data leaving where it should notSeparate DLP tools, if you had any

Not every product sold as SASE includes all of these, and the depth of each varies a lot between vendors. Ask for the list in writing.

SASE, SSE and SD-WAN: the naming

  • SD-WAN is the networking half on its own: circuit management, path selection and failover. Our guide to SD-WAN covers it in plain terms.
  • SSE (security service edge) is the security half on its own: SWG, CASB, ZTNA and often FWaaS, without the SD-WAN. Gartner split the term out in 2021, because many companies buy the security first.
  • SASE is both together, ideally managed with one policy and one console.

"Single-vendor SASE" means one company supplies both halves. "Dual-vendor" means an SD-WAN from one company and SSE from another, integrated. Single-vendor is simpler to run. Dual-vendor lets you keep an SD-WAN you already like. Neither is automatically better.

What changes for your circuits

SASE makes every site an internet-first site. Traffic goes straight from the branch to the nearest point of presence, so the quality of each location's local internet matters more than it did when a private circuit carried everything home.

  • Each site needs a good primary connection. For busy offices that usually means dedicated internet access. For smaller ones, shared fiber is often enough.
  • Each site needs a second path. If the only circuit fails, the site loses its security service as well as its internet. SD-WAN handles the failover, as long as there is something to fail over to.
  • Distance to the point of presence matters. A provider whose nearest location is hundreds of miles from your Austin office adds delay to every packet. Ask for the list.
  • Private circuits may shrink or go. Some businesses keep a private link for a data centre or for cloud connectivity; many retire the branch mesh at its next renewal.

A worked example

The company, sites and figures are a hypothetical illustration. Latencies are approximate physics, not measurements of any provider.

Suppose a firm has offices in New York, Chicago and Austin, 90 staff in total, of whom 30 work mostly from home. Today every branch sends its internet traffic over private circuits to the New York office, where one firewall inspects it, and remote staff connect through a VPN into New York.

Light travels through fiber at roughly 200,000 km per second, which works out to about 1 millisecond of round-trip delay for every 100 km of fiber route. Austin to New York is roughly 2,400 km in a straight line and longer by fiber. Say the route is about 3,000 km: that is around 30 milliseconds of round trip before any equipment delay, added to every request an Austin user makes to a cloud app, because it must travel to New York and back first.

With SASE, the Austin office connects to a nearby point of presence, perhaps in Texas, and reaches the same cloud app with a small fraction of that added delay. The 30 home workers get the same treatment wherever they are, and the New York circuit stops carrying the whole company's internet traffic.

The other side of the ledger: SASE is usually licensed per user, per site or by bandwidth tier, and the monthly total has to be compared with what it replaces, including the private circuits, the VPN appliance, the web filter and the firewall renewals. In our hypothetical firm, the case is strong because the private-circuit contracts and the firewall renewal fall in the same year. Without that timing, a phased move would make more sense.

Signs you are ready, and signs you are not

SASE usually makes sense when several of these are true:

  • A meaningful share of your staff work outside an office.
  • Most of your applications are cloud services rather than servers you own.
  • You run three or more sites, or plan to. See multi-site business internet.
  • Your VPN is a source of complaints or tickets.
  • Firewalls or private circuits are coming up for renewal or replacement.

It can wait when you have one office, nearly everyone on site, a firewall with years of support left, and no complaints. Buying it then mostly means paying for a design built for a problem you do not have.

A sensible migration path

  1. Replace the VPN with ZTNA first. It is often the most visible improvement and does not touch the branch networks.
  2. Move web filtering to the cloud gateway so remote users are covered the same way as office users.
  3. Add or convert SD-WAN at each site as circuits and routers come up for renewal.
  4. Retire what is left: redundant private circuits, old appliances, overlapping licences.

Running old and new side by side for a period is normal. The mistake is doing everything at once on a single weekend.

Common misunderstandings

  • "SASE is a box we install." It is mostly a cloud service. There may be an SD-WAN device at each site, but the security work happens in the provider's network.
  • "SASE means we can drop to cheap internet everywhere." The reverse is closer to true. Each site now depends on its own connection, so a weak circuit becomes a weak site.
  • "Zero trust means we trust nothing and nobody can work." In practice it means access is granted per application after checking identity and device, which users usually find less awkward than a VPN, not more.
  • "It removes the need for a security team." It moves where the tools live. Someone still has to write the policy, review the alerts and handle exceptions, whether that is your staff or a managed service.
  • "Every product labelled SASE is the same." Coverage, point-of-presence locations and the maturity of each component vary widely. Compare them feature by feature.

Questions to ask your provider

  • Where are your points of presence relative to my sites and my remote staff?
  • Which components are included, and are they one platform or several products joined together?
  • How is it licensed: per user, per site, per bandwidth tier? What happens when I add ten people?
  • Do you decrypt and inspect encrypted traffic, and how is sensitive traffic such as banking or health data handled?
  • What happens to a site's traffic if your nearest point of presence has a problem?
  • How long are logs kept, and can I export them?
  • Who runs it day to day: you, a managed service, or my own team?

Getting SASE and the circuits under it priced together

A SASE project is really two purchases: the security platform and the connections every site needs underneath it. We price both, the SD-WAN and security services alongside the circuits at each address, with several carriers bidding on every location. The carrier pays us, so there is no markup, and if your current setup is fine for now we will say so. The quote is free, carries no obligation, and you usually hear back the same day. Send us your sites, call 478-758-8091 or text (347) 870-0965.

// QUESTIONS

Frequently Asked Questions

01What does SASE stand for?

Secure access service edge. It describes a design that combines SD-WAN networking with security services such as web filtering, cloud app control, zero trust remote access and a cloud firewall, delivered from the provider's cloud network rather than from appliances in your office.

02What is the difference between SASE and SSE?

SSE, or security service edge, is the security half of SASE on its own: secure web gateway, cloud access security broker, zero trust network access and usually a cloud firewall. SASE adds SD-WAN, so the networking and the security are managed together.

03Does SASE replace my firewall?

It can replace some or all branch firewalls with firewall policy applied in the cloud. Many businesses keep a firewall at head office or in a data centre for a period, and retire appliances as they come up for renewal.

04Does SASE replace a VPN?

Usually, yes. The zero trust network access part of SASE gives remote users access to specific applications after checking who they are and what device they are on, instead of placing them on the whole network the way a traditional VPN does.

05Do I still need good internet at each office with SASE?

More than before. SASE sends each site's traffic directly to the provider's nearest point of presence, so every location depends on its own internet connection. Each busy site should have a solid primary circuit and a second path for failover.

06Is SASE worth it for a single office?

Often not yet. With one office, most staff on site and a firewall with years of support left, the benefits are small. SASE earns its cost when you have several sites, many remote workers and most applications in the cloud.

// FREE · NO OBLIGATION · SAME-DAY RESPONSE

Want This Priced for Your Address?

Reading is cheap; a real number for your building is better. Pick a time below, or call and we will talk it through.

EMAIL INFO@FIBERXINTERNET.COM · TEXT (347) 870-0965

FIBERX · APPOINTMENT CONSOLE
Book an Appointment

Talk to Phil. Pick a Time.

A quick call with your dedicated agent — internet quotes, AI automation, or both. No obligation, same-day response.

Pick your 30-minute slot ALL TIMES ET
or call 478-758-8091

REQUEST GOES STRAIGHT TO PHIL · SAME-DAY CONFIRMATION