{"id":104293,"date":"2019-12-13T06:00:45","date_gmt":"2019-12-13T14:00:45","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=104293"},"modified":"2022-04-06T23:34:33","modified_gmt":"2022-04-07T06:34:33","slug":"cloud-branch-security-sase","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2019\/12\/cloud-branch-security-sase\/","title":{"rendered":"Cloud-Connected Branch Security with SASE"},"content":{"rendered":"<p>By Brian Tokuyoshi, senior product marketing manager<\/p>\n<p><i><span style=\"font-weight: 400;\">Applications moving to the cloud and increased user mobility are changing the way networking and network security services must be delivered. Palo Alto Networks founder and CTO Nir Zuk believes that the future of network security is in the cloud, and has been driving this change for the past few years with Prisma Access, the industry\u2019s most comprehensive SASE. In this ongoing series, Palo Alto Networks thought leaders explore the core tenets of an integrated, effective SASE solution, and more broadly, its implementation and implications.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">As cloud usage increases across the globe, at large and small organizations alike, it is important to ensure your cloud strategy encompasses performance, connectivity and \u2013 too often overlooked \u2013 security for your branch offices and retail locations.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-sase\"><span style=\"font-weight: 400;\">Secure access service edge<\/span><\/a><span style=\"font-weight: 400;\"> (SASE, pronounced sassy) is a comprehensive solution that helps organizations embrace cloud and mobility by providing network and network security services from a cloud-based, unified platform.<\/span><\/p>\n<p><div class=\"styleIt\" style=\"width:560px;height:315px;\"><lite-youtube videoid=\"v0jtkhCQpzI\" ><\/lite-youtube><\/div><\/p>\n<p><b>Traditional Branch Connectivity and Security: A Thing of the Past<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traditionally, organizations had three options to choose from to <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-branch-office-network-security\"><span style=\"font-weight: 400;\">secure their branch offices<\/span><\/a><span style=\"font-weight: 400;\"> and connect them to the internet.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Use branch routers at each location to backhaul traffic over an MPLS connection to HQ for inspection and policy enforcement. This strategy is costly and inefficient.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Utilize a VPN over a standard internet connection to connect branch offices to HQ, using a hub-and-spoke architecture as an alternative to MPLS.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Utilize direct-to-internet at the branch, with a network security stack at each branch location, providing equivalent security as a centralized perimeter firewall would.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">These solutions made sense when organizations were using applications solely in internal data centers, and when applications were not so bandwidth intensive. For many years, these options were considered best practices for designing wide area networks, until the cloud started to drive new requirements.<\/span><\/p>\n<p><b>With the Onset of Cloud Comes Network Evolution<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enter the cloud. <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-saas\"><span style=\"font-weight: 400;\">Software-as-a-service<\/span><\/a><span style=\"font-weight: 400;\"> (SaaS) applications and public cloud platforms from providers like AWS, Azure and GCP provide the flexibility to meet the needs of a growing organization while reducing costs. SaaS applications have risen in popularity due to their improvements in productivity and collaboration for dispersed enterprises, while public cloud providers help to eliminate resource constraints and infrastructure costs by moving data centers to the cloud and taking over the management and services.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In light of the move to the cloud, it makes less sense to use traditional branch networking to bring traffic back to headquarters. In addition, bandwidth and performance issues arise as more cloud applications are used at the branch. Applications such as video conferencing\/streaming and cloud storage applications take up a large amount of bandwidth. As a result, organizations are looking for ways to integrate a direct-to-internet connection at the branch, without introducing new security risks.\u00a0<\/span><\/p>\n<p><b>How to Protect Branch Offices in the Cloud Era<\/b><\/p>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/sase\/branch-sd-wan\"><span style=\"font-weight: 400;\">Branch offices<\/span><\/a><span style=\"font-weight: 400;\"> not only need access to applications hosted in data centers at headquarters, they also need access to the internet, SaaS apps and public cloud services. For effective branch security, organizations need to develop their network architecture in a way that optimizes access to all resources, regardless of location. A SASE security approach provides branch offices security and visibility into all traffic, while also enabling seamless access to assets in the cloud and on-premises. By transitioning your network and network security services to a SASE solution, organizations can benefit from enhanced user experience with fast and reliable internet connection and accurate localization, while also optimizing a company's ability to grow quickly and easily add offices.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Organizations must also consider the security of the applications being accessed by inspecting apps across not just web protocols, but also ports. With a <\/span><a href=\"http:\/\/start.paloaltonetworks.com\/10-tenets-SASE\"><span style=\"font-weight: 400;\">SASE cloud-based security strategy<\/span><\/a><span style=\"font-weight: 400;\">, organizations have full visibility into and inspection of traffic across ports and protocols, so policies can be applied to all the traffic in the cloud. In addition, organizations can eliminate MPLS by utilizing the cloud, which also results in significant cost savings.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Palo Alto Networks is revolutionizing the way companies transform their cloud security infrastructure. <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/11\/cloud-next-generation-network-security\"><span style=\"font-weight: 400;\">Prisma Access<\/span><\/a><span style=\"font-weight: 400;\"> is the industry\u2019s most comprehensive SASE solution. It delivers the networking and security that organizations need in an architecture designed for all traffic, all applications and all users. Rather than creating single-purpose technology overlays that are normally associated with point products, Prisma Access uses a common cloud-based infrastructure to deliver security services, including advanced threat prevention, web filtering, sandboxing, DNS security, credential theft prevention, data loss prevention (DLP) and next-generation firewalling.\u00a0<\/span><\/p>\n<p>Learn more about SASE from two of the industry\u2019s leading experts \u2013 Gartner\u2019s Neil MacDonald and Palo Alto Networks own Jason Georgi \u2013 in our video, \"<a href=\"https:\/\/www.paloaltonetworks.com\/resources\/videos\/gartner-network-securitys-future-is-in-the-cloud\">Network Security's Future Is in the Cloud<\/a>.\"<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For effective branch security, organizations need to develop their network architecture to optimize access to all resources, regardless of location.<\/p>\n","protected":false},"author":19,"featured_media":104424,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6768],"tags":[6888,6833,6881,7006],"coauthors":[788],"class_list":["post-104293","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-cloud","tag-branch-security","tag-prisma-access","tag-sase","tag-secure-access-service-edge"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/12\/screen2.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/104293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=104293"}],"version-history":[{"count":7,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/104293\/revisions"}],"predecessor-version":[{"id":107311,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/104293\/revisions\/107311"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/104424"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=104293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=104293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=104293"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=104293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}