{"id":103575,"date":"2019-11-21T13:00:39","date_gmt":"2019-11-21T21:00:39","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=103575"},"modified":"2019-11-22T08:09:35","modified_gmt":"2019-11-22T16:09:35","slug":"cloud-sase-secure-sd-wan","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2019\/11\/cloud-sase-secure-sd-wan\/","title":{"rendered":"Better Together: Security + SD-WAN by Palo Alto Networks"},"content":{"rendered":"<p>By\u00a0<span style=\"font-weight: 400;\">Koroush Saraf, VP, Product Management for SD-WAN<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Applications moving to the cloud and increased user mobility are changing the way networking and network security services must be delivered. Palo Alto Networks founder and CTO Nir Zuk believes that the future of network security is in the cloud, and has been driving this change for the past few years, with Prisma Access, the industry\u2019s most comprehensive SASE. In this ongoing series, Palo Alto Networks thought leaders explore the core tenets of an integrated, effective SASE solution, and more broadly, its implementation and implications.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">We live in an age of cloud and digital transformation. Users and applications are moving outside the traditional network perimeter, accessing an ever increasing number of applications \u2013 both SaaS and in the public cloud. Organizations face the challenge to proactively protect their users, applications and data from security threats, without compromising user experience.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Cloud Access Needs Security That Is Simple<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In order to solve the complexity of networking and security, a single, unified platform for cloud access is needed. Gartner writes about a model known as the \u201csecure access service edge,\u201d or <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-sase\"><span style=\"font-weight: 400;\">SASE<\/span><\/a><span style=\"font-weight: 400;\"> (pronounced \u201csassy\u201d). In Gartner\u2019s words:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThe secure access service edge is an emerging offering combining comprehensive WAN capabilities with comprehensive network security functions, such as SWG, CASB, FwaaS and ZTNA, to support the dynamic secure access needs of digital enterprises.\u201d <\/span><span style=\"font-weight: 400;\">(Gartner, The Future of Network Security is in the Cloud, 30 August 2019)<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/11\/cloud-next-generation-network-security\/\"><span style=\"font-weight: 400;\">SASE solution<\/span><\/a><span style=\"font-weight: 400;\"> converges connectivity (SD-WAN, VPN, QoS, etc.) and security (including FWaaS, CASB, DLP, ZTNA, DNS, etc) into one unified, cloud-delivered solution. <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cloud-security\/prisma-access\"><span style=\"font-weight: 400;\">Prisma&#x2122; Access<\/span><\/a><span style=\"font-weight: 400;\"> by Palo Alto Networks is the industry\u2019s most comprehensive SASE solution. To further drive momentum for our SASE, Palo Alto Networks now offers the most secure SD-WAN solution in the industry. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>SD-WAN from Palo Alto Networks<\/b><\/p>\n<p><img loading=\"lazy\" decoding=\"async\"  class=\"alignleft wp-image-103577 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/blog_sd_wan.gif\" alt=\"SD-WAN by Palo Alto Networks\" width=\"444\" height=\"233\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Before we get into the details of the unique and compelling capabilities of Palo Alto Networks SD-WAN, here is a quick introduction to SD-WAN. <\/span><a href=\"https:\/\/www.securityroundtable.org\/sd-wan-an-explainer-for-cxo\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Software-Defined Wide Area Network<\/span><\/a><span style=\"font-weight: 400;\"> (SD-WAN) offers a transformational approach to optimize branch office networking and assures peak application performance. In fact, according to Gartner\u2019s Magic Quadrant for WAN Edge Infrastructure (October 18, 2018), Gartner states that \u201cby 2023, more than 90% of WAN edge infrastructure refresh initiatives will be based on vCPE platforms or SD-WAN appliances vs. traditional routers\u00a0 (up from less than 40% today).\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But although SD-WAN offers <\/span><a href=\"https:\/\/start.paloaltonetworks.com\/consistent-security-with-sd-wan.html\"><span style=\"font-weight: 400;\">many benefits<\/span><\/a><span style=\"font-weight: 400;\">, it also brings many challenges, including new security risks, unreliable performance and increased complexity. SD-WAN exposes the branch to public Internet and moves security close to the branch edge.\u00a0 When security is an afterthought, it tends to be bolted on, introducing management complexity and subpar protection. Moreover, network performance becomes less reliable because organizations use the congested internet as the WAN middle mile \u2013 and when customers try to address this by building their own SD-WAN hub and interconnect infrastructures, it can translate into more complexity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">By using Prisma&#x2122; Access as the SD-WAN hub, customers can address several transformation challenges all at once. Prisma Access provides bookended SD-WAN hub-as-a-service, as well as high-performance, low-latency global interconnect between branch offices and cloud workloads. Combining <a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/sd-wan-and-sase\">security and end-to-end SD-WAN<\/a> provides the best user to application experience. Customers can easily consume our secure Prisma Access SD-WAN hub as a service, eliminating the complexity of building their own SD-WAN hub and global interconnect fabric. Equally important, customers have options with our solution \u2013 they can build their own hub using Palo Alto Networks Next-Generation Firewalls, both hardware appliances and virtualized form factors like the <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/vm-series-virtual-next-generation-firewall\"><span style=\"font-weight: 400;\">VM-Series<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/sd-wan\"><span style=\"font-weight: 400;\">Palo Alto Networks SD-WAN<\/span><\/a><span style=\"font-weight: 400;\"> allows customers to seamlessly adopt an end-to-end SD-WAN architecture with natively integrated, world-class security and connectivity. Through tight integration, customers can manage security and SD-WAN on a <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/ebooks\/451-research-brief-security-in-sd-wan\"><span style=\"font-weight: 400;\">single, intuitive interface<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\"  class=\"alignleft size-full wp-image-103748 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1.png\" alt=\"End-to-End Secure SD-WAN hybrid deployment\" width=\"960\" height=\"540\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1.png 960w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-230x129.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-768x432.png 768w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-500x281.png 500w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-510x287.png 510w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-71x40.png 71w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-533x300.png 533w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/image1-1-874x492.png 874w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Palo Alto Networks SD-WAN enables organizations to confidently manage their branch and cloud transformation initiatives, and realize a host of benefits:<\/span><\/p>\n<p><b>Flexible Deployment Options \u2013\u00a0<\/b><span style=\"font-weight: 400;\">Palo Alto Networks is the only vendor in the industry to offer both cloud-based SD-WAN Hub and Interconnect as a service, as well as components (both VM-Series virtualized form factor and hardware appliances) for customers to build their SD-WAN deployment on their own.\u00a0\u00a0<\/span><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Prisma Access offers a simple-to-consume, cloud-based model. NGFWs are located in each branch, and they all connect to the closest Prisma Access node that acts as the regional SD-WAN hub. This offers book-ended SD-WAN and also includes a global backbone for high-performance branch to branch, branch to cloud, VPC, SaaS and datacenter with world-class security inserted in the path of all traffic.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">NGFW appliances (or the <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/vm-series-virtual-next-generation-firewall\"><span style=\"font-weight: 400;\">VM-Series<\/span><\/a><span style=\"font-weight: 400;\">) at the branch can apply security locally for east-west branch segmentation, <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-a-zero-trust-architecture\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/a><span style=\"font-weight: 400;\">\u00a0and direct internet access. The branch can run in a thin mode, with security in the cloud, or apply security locally. Also, as mentioned before, classic DIY (do-it-yourself) is an option \u2013 NGFW appliances can be used to build a hub-and-spoke deployment, also deployed in customer data centers, Equinix performance hubs or on a service provider infrastructure to interconnect regional hubs with each other.\u00a0<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><b>Optimized Connectivity for Improved User Experience \u2013\u00a0<\/b><span style=\"font-weight: 400;\">Palo Alto Networks SD-WAN<\/span> <span style=\"font-weight: 400;\">delivers an optimal user experience for cloud applications without compromising security. All users, whether at headquarters, branch offices or remote, can connect to Prisma Access to optimally use SaaS, public cloud and data center applications, delivering security and optimized end-to-end performance for SD-WAN. Additionally, with our recently announced <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/content\/dam\/pan\/en_US\/assets\/pdf\/datasheets\/support\/prisma-access-service-sla.pdf\"><span style=\"font-weight: 400;\">SLAs for SaaS<\/span><\/a><span style=\"font-weight: 400;\"> delivered by the Prisma fabric, customers can now be confident in their cloud experience, with guaranteed access to a growing list of SaaS providers, such as Microsoft Office 365, Box.com, Salesforce.com and more.\u00a0<\/span><\/p>\n<p><b>Central Management and Simplified Branch Onboarding \u2013\u00a0<span style=\"font-weight: 400;\">Palo Alto Networks SD-WAN eliminates the need to manage multiple, disparate consoles from different vendors by using <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/panorama\"><span style=\"font-weight: 400;\">Panorama<\/span><\/a><span style=\"font-weight: 400;\"> to centrally manage both security and connectivity for all deployment options. We are also introducing zero touch provisioning (ZTP) capability for our NGFWs to enable customers to automate tedious branch device onboarding processes. Appliances can be drop-shipped to the branch and, with a few simple steps, the devices will connect to the customer\u2019s Panorama to automatically configure the branch for SD-WAN, routing and, of course, security policies.<\/span><\/b><\/p>\n<p><span style=\"font-weight: 400;\">These are exciting times for Palo Alto Networks and SD-WAN. When I speak with customers, many believe SASE is the next step in the SD-WAN evolution. I am pleased to say Palo Alto Networks is well-positioned to lead the way.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Learn more about <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/sd-wan\"><span style=\"font-weight: 400;\">Palo Alto Networks SD-WAN capabilities<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><em><span style=\"font-weight: 400;\">Source: Gartner, Magic Quadrant for WAN Edge Infrastructure, Joe Skorupa, Andrew Lerner, et al., 18 October 2018.\u00a0 (Gartner: 2018, October)<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400;\">Source: Gartner, The Future of Network Security Is in the Cloud, Neil MacDonald, Lawrence Orans, et al., 30 August 2019.<\/span><\/em><\/p>\n<p><em><span style=\"font-weight: 400;\">GARTNER is a registered trademark and service mark of Gartner, Inc. and\/or its affiliates in the U.S. and internationally, and is used herein with permission. All rights reserved.<\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Networks allows customers to seamlessly adopt an end-to-end SD-WAN architecture with integrated, world-class security and connectivity.<\/p>\n","protected":false},"author":663,"featured_media":103590,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[308,6768,6765],"tags":[6888,1815,414,6833,6881,5846],"coauthors":[6898],"class_list":["post-103575","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcement","category-secure-the-cloud","category-secure-the-enterprise","tag-branch-security","tag-firewall","tag-mobile-security","tag-prisma-access","tag-sase","tag-sd-wan"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/11\/SD-WAN-Image.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/103575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=103575"}],"version-history":[{"count":25,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/103575\/revisions"}],"predecessor-version":[{"id":103782,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/103575\/revisions\/103782"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/103590"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=103575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=103575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=103575"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=103575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}