1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:04,380
we're going to cover SD-WANs and SASE.

3
00:00:04,380 --> 00:00:07,020
Now, as our organizations become increasingly more reliant

4
00:00:07,020 --> 00:00:09,000
on the cloud-based applications that are used

5
00:00:09,000 --> 00:00:11,550
by our geographically-distributed workforces,

6
00:00:11,550 --> 00:00:14,190
this has led to an increased demand for agile, secure,

7
00:00:14,190 --> 00:00:17,520
and efficient network infrastructure to be created quickly.

8
00:00:17,520 --> 00:00:20,610
Now, a software-defined wide area network, or SD-WAN,

9
00:00:20,610 --> 00:00:23,070
is a virtualized approach to managing and optimizing

10
00:00:23,070 --> 00:00:26,130
wide area network connections to effectively route traffic

11
00:00:26,130 --> 00:00:29,490
between remote sites, data centers, and cloud environments.

12
00:00:29,490 --> 00:00:32,580
The Secure Access Service Edge framework, or SASE,

13
00:00:32,580 --> 00:00:33,480
on the other hand,

14
00:00:33,480 --> 00:00:34,530
is used to consolidate

15
00:00:34,530 --> 00:00:36,570
numerous networking and security functions

16
00:00:36,570 --> 00:00:38,460
into a single cloud-native service

17
00:00:38,460 --> 00:00:41,220
to ensure that secure and seamless access for end users

18
00:00:41,220 --> 00:00:42,240
can be achieved,

19
00:00:42,240 --> 00:00:44,910
regardless of their actual physical location.

20
00:00:44,910 --> 00:00:47,520
Together, SD-WAN and SASE

21
00:00:47,520 --> 00:00:49,680
represent a big innovation in our network

22
00:00:49,680 --> 00:00:51,150
and security architectures.

23
00:00:51,150 --> 00:00:53,370
So we're going to take some time to cover both of them

24
00:00:53,370 --> 00:00:54,690
in this lesson.

25
00:00:54,690 --> 00:00:57,120
Now, first, let's talk about SD-WAN,

26
00:00:57,120 --> 00:00:59,790
or software-defined wide area networking.

27
00:00:59,790 --> 00:01:02,700
Now, an SD-WAN is a virtual WAN architecture

28
00:01:02,700 --> 00:01:04,920
that allows enterprises to leverage any combination

29
00:01:04,920 --> 00:01:06,270
of transport services

30
00:01:06,270 --> 00:01:08,970
to securely connect users to their applications.

31
00:01:08,970 --> 00:01:10,560
An SD-WAN is essentially

32
00:01:10,560 --> 00:01:13,350
a software-based wide area network architecture

33
00:01:13,350 --> 00:01:16,830
with all the control extracted from the underlying hardware.

34
00:01:16,830 --> 00:01:19,020
So, instead of configuring specific infrastructure

35
00:01:19,020 --> 00:01:22,230
to handle our application traffic using something like MPLS,

36
00:01:22,230 --> 00:01:24,000
we can actually manage an SD-WAN

37
00:01:24,000 --> 00:01:26,130
entirely inside of our software.

38
00:01:26,130 --> 00:01:28,230
Plus, we can layer it over multiple types

39
00:01:28,230 --> 00:01:29,730
of network transport.

40
00:01:29,730 --> 00:01:30,960
This means we can really

41
00:01:30,960 --> 00:01:33,540
use any of our other WAN connections that we want to,

42
00:01:33,540 --> 00:01:36,720
things like MPLS, a cellular connection, a microwave link,

43
00:01:36,720 --> 00:01:39,750
or a regular broadband internet service like a cable modem,

44
00:01:39,750 --> 00:01:42,810
in order to create a virtual wide area network architecture

45
00:01:42,810 --> 00:01:45,030
that we can then run our networks over.

46
00:01:45,030 --> 00:01:46,317
To create an SD-WAN,

47
00:01:46,317 --> 00:01:48,540
you can use a centralized control function

48
00:01:48,540 --> 00:01:50,970
to securely and intelligently redirect the traffic

49
00:01:50,970 --> 00:01:52,410
across the WAN.

50
00:01:52,410 --> 00:01:53,610
Our traditional WANs,

51
00:01:53,610 --> 00:01:54,990
which were never developed with the idea

52
00:01:54,990 --> 00:01:57,750
of integrating cloud services into our enterprise networks,

53
00:01:57,750 --> 00:01:59,700
simply aren't able to do this.

54
00:01:59,700 --> 00:02:02,040
But instead, we can use an SD-WAN,

55
00:02:02,040 --> 00:02:04,440
because they're enabled for cloud-first enterprises

56
00:02:04,440 --> 00:02:08,280
to deliver amazing quality experiences for their end users.

57
00:02:08,280 --> 00:02:10,919
Let's consider a company that has several branch offices

58
00:02:10,919 --> 00:02:12,840
and one headquarters location.

59
00:02:12,840 --> 00:02:14,850
In our traditional WAN architectures,

60
00:02:14,850 --> 00:02:17,370
each of those branch offices would likely be connected

61
00:02:17,370 --> 00:02:20,340
back to the central office using a star topology.

62
00:02:20,340 --> 00:02:21,750
This would allow the headquarters

63
00:02:21,750 --> 00:02:24,120
to conduct advanced security on that traffic

64
00:02:24,120 --> 00:02:26,460
as it went through the branch offices to the headquarters,

65
00:02:26,460 --> 00:02:28,050
and then out to the internet.

66
00:02:28,050 --> 00:02:29,850
This is great for security, sure,

67
00:02:29,850 --> 00:02:31,920
but it really does slow down the entire process

68
00:02:31,920 --> 00:02:34,170
for our end users at those branch offices,

69
00:02:34,170 --> 00:02:36,060
and it results in a poor user experience

70
00:02:36,060 --> 00:02:37,890
and loss of productivity.

71
00:02:37,890 --> 00:02:40,110
Now, unlike traditional architectures, though,

72
00:02:40,110 --> 00:02:42,660
SD-WANs can solve this by using intelligence

73
00:02:42,660 --> 00:02:44,850
to identify the network applications that are being used

74
00:02:44,850 --> 00:02:45,960
by the end users,

75
00:02:45,960 --> 00:02:49,260
and routing that data across the WAN to the right places.

76
00:02:49,260 --> 00:02:51,840
This allows your WAN environment to be much more dynamic

77
00:02:51,840 --> 00:02:53,040
and much more efficient,

78
00:02:53,040 --> 00:02:55,560
by providing improvements in visibility, performance,

79
00:02:55,560 --> 00:02:58,620
and manageability of our enterprise WAN architectures

80
00:02:58,620 --> 00:03:00,570
from a single centralized point.

81
00:03:00,570 --> 00:03:03,240
So, if you're working at a large enterprise network

82
00:03:03,240 --> 00:03:04,680
and you have a lot of branch offices,

83
00:03:04,680 --> 00:03:06,990
and they're all trying to move more and more into the cloud

84
00:03:06,990 --> 00:03:09,990
using things like IaaS, and PaaS, and SaaS,

85
00:03:09,990 --> 00:03:11,940
then you may need to use an SD-WAN

86
00:03:11,940 --> 00:03:14,040
to increase the performance for your end users

87
00:03:14,040 --> 00:03:15,930
and reduce the bottlenecks that were being caused

88
00:03:15,930 --> 00:03:18,900
by your traditional centralized WAN architectures.

89
00:03:18,900 --> 00:03:21,930
Next, we need to discuss the concept of SASE,

90
00:03:21,930 --> 00:03:24,480
or the Secure Access Secure Edge.

91
00:03:24,480 --> 00:03:27,450
Now, the Secure Access Secure Edge, or SASE,

92
00:03:27,450 --> 00:03:29,430
is a new type of network architecture

93
00:03:29,430 --> 00:03:31,020
that combines both the network security

94
00:03:31,020 --> 00:03:33,450
and wide area networks, or WAN, capabilities,

95
00:03:33,450 --> 00:03:35,370
into a single solution.

96
00:03:35,370 --> 00:03:37,710
The Secure Access Secure Edge is seen as a way

97
00:03:37,710 --> 00:03:39,750
to address the challenges of securing and connecting

98
00:03:39,750 --> 00:03:40,740
users and data

99
00:03:40,740 --> 00:03:42,990
that's being distributed across multiple locations,

100
00:03:42,990 --> 00:03:45,480
including things like branch offices, remote workers,

101
00:03:45,480 --> 00:03:48,450
and mobile users, as well as the cloud itself.

102
00:03:48,450 --> 00:03:50,880
A key aspect of SASE technology

103
00:03:50,880 --> 00:03:53,760
is that it's using software defined networking, or SDN,

104
00:03:53,760 --> 00:03:55,740
to provide security and networking services

105
00:03:55,740 --> 00:03:57,450
from the cloud rather than from

106
00:03:57,450 --> 00:03:59,640
traditional hardware-based appliances.

107
00:03:59,640 --> 00:04:02,190
This allows us to have more flexibility, scalability,

108
00:04:02,190 --> 00:04:03,600
and cost efficiencies

109
00:04:03,600 --> 00:04:06,000
than using a traditional network solution.

110
00:04:06,000 --> 00:04:09,300
Now, Secure Access Secure Edge, or SASE solutions,

111
00:04:09,300 --> 00:04:11,070
are typically going to include a wide variety

112
00:04:11,070 --> 00:04:12,600
of security services too.

113
00:04:12,600 --> 00:04:15,120
This includes things like firewalls, VPNs,

114
00:04:15,120 --> 00:04:16,769
zero-trust network access,

115
00:04:16,769 --> 00:04:20,790
and cloud access security brokers, which are known as CASBs.

116
00:04:20,790 --> 00:04:22,920
Now, these are all going to be delivered through a common set

117
00:04:22,920 --> 00:04:24,810
of policy and management platforms,

118
00:04:24,810 --> 00:04:27,150
because this allows us to achieve our networking goals

119
00:04:27,150 --> 00:04:29,040
in a much more efficient way.

120
00:04:29,040 --> 00:04:31,350
SASE is going to help to address the challenges

121
00:04:31,350 --> 00:04:33,330
of our modern distributed enterprises,

122
00:04:33,330 --> 00:04:35,970
which is increasingly composed of mobile, cloud-based,

123
00:04:35,970 --> 00:04:38,130
and multi-cloud applications and services,

124
00:04:38,130 --> 00:04:40,320
as well as a large number of users and devices

125
00:04:40,320 --> 00:04:41,460
which are constantly growing

126
00:04:41,460 --> 00:04:44,580
and moving into larger and more distinct locations.

127
00:04:44,580 --> 00:04:47,280
SASE is going to be used to provide a more secure

128
00:04:47,280 --> 00:04:49,320
and efficient way of connecting all of these users

129
00:04:49,320 --> 00:04:52,350
and their devices back to the applications and services

130
00:04:52,350 --> 00:04:53,340
that they want to use,

131
00:04:53,340 --> 00:04:55,380
regardless of the location or the type of device

132
00:04:55,380 --> 00:04:56,880
that they're actually using.

133
00:04:56,880 --> 00:04:58,860
Now, all the major cloud service providers,

134
00:04:58,860 --> 00:05:01,740
including Amazon Web Services, Microsoft Azure,

135
00:05:01,740 --> 00:05:03,180
and Google Cloud Platform,

136
00:05:03,180 --> 00:05:04,530
are all going to offer solutions

137
00:05:04,530 --> 00:05:07,680
that align with this concept of Secure Access Secure Edge.

138
00:05:07,680 --> 00:05:09,480
But, each of these do refer to them

139
00:05:09,480 --> 00:05:11,220
by different names or acronyms,

140
00:05:11,220 --> 00:05:13,110
depending on the specific service or product

141
00:05:13,110 --> 00:05:14,790
that you're going to be referencing.

142
00:05:14,790 --> 00:05:17,310
For example, inside of Amazon Web Services,

143
00:05:17,310 --> 00:05:18,840
which is known as AWS,

144
00:05:18,840 --> 00:05:21,780
this service that's going to most closely align with SASE

145
00:05:21,780 --> 00:05:25,080
is known as a VPC, or virtual private cloud.

146
00:05:25,080 --> 00:05:27,390
Now, a virtual private cloud will provide a secure

147
00:05:27,390 --> 00:05:28,800
and flexible network infrastructure

148
00:05:28,800 --> 00:05:30,420
for your applications and data,

149
00:05:30,420 --> 00:05:33,330
and AWS's VPC enables us to be able to create

150
00:05:33,330 --> 00:05:34,710
virtual networks in the cloud,

151
00:05:34,710 --> 00:05:36,840
and connect it to our on-premise data centers,

152
00:05:36,840 --> 00:05:41,010
or other AWS services, to achieve that SASE capability.

153
00:05:41,010 --> 00:05:43,680
Microsoft Azure actually has a lot of different services

154
00:05:43,680 --> 00:05:45,960
that align with this SASE concept,

155
00:05:45,960 --> 00:05:47,820
including Azure's virtual WAN,

156
00:05:47,820 --> 00:05:50,010
which provides secure, global and efficient connectivity

157
00:05:50,010 --> 00:05:53,160
between branch offices, data centers, and Azure resources,

158
00:05:53,160 --> 00:05:54,900
as well as Azure express routes,

159
00:05:54,900 --> 00:05:57,480
which enable you to create a dedicated private connection

160
00:05:57,480 --> 00:05:58,890
between an Azure data center

161
00:05:58,890 --> 00:06:01,320
and your on-premise network infrastructure.

162
00:06:01,320 --> 00:06:03,210
Now, if you happen to be using GCP,

163
00:06:03,210 --> 00:06:05,040
which is the Google Cloud Platform,

164
00:06:05,040 --> 00:06:07,560
they actually call their SASE-aligned services

165
00:06:07,560 --> 00:06:09,450
the Google Cloud Interconnect.

166
00:06:09,450 --> 00:06:11,190
Google Cloud Interconnect allows you

167
00:06:11,190 --> 00:06:12,780
to connect your on-premise infrastructure

168
00:06:12,780 --> 00:06:14,610
to the Google Cloud Platform

169
00:06:14,610 --> 00:06:16,740
over a dedicated private connection.

170
00:06:16,740 --> 00:06:19,440
They also have a service known as the Google Cloud VPN,

171
00:06:19,440 --> 00:06:20,273
which allows you

172
00:06:20,273 --> 00:06:22,320
to securely connect your on-premise infrastructure

173
00:06:22,320 --> 00:06:24,360
back to your virtual private cloud network

174
00:06:24,360 --> 00:06:26,700
through an IPsec VPN tunnel.

175
00:06:26,700 --> 00:06:27,990
Now, it's important to realize

176
00:06:27,990 --> 00:06:31,170
that these services are not exclusively SASE providers,

177
00:06:31,170 --> 00:06:34,170
and the definition of SASE here is not completely aligned

178
00:06:34,170 --> 00:06:35,970
with all the features and functionality

179
00:06:35,970 --> 00:06:39,060
of any single cloud service from these cloud providers,

180
00:06:39,060 --> 00:06:42,210
but they do provide a lot of the aspects of SASE for you,

181
00:06:42,210 --> 00:06:43,890
such as having secure, flexible,

182
00:06:43,890 --> 00:06:45,660
and global networking capabilities

183
00:06:45,660 --> 00:06:47,220
by using these different services.

184
00:06:47,220 --> 00:06:49,500
So remember, as cyber threats evolve

185
00:06:49,500 --> 00:06:50,340
and our work environments

186
00:06:50,340 --> 00:06:52,830
become increasingly more geographically dispersed,

187
00:06:52,830 --> 00:06:54,420
understanding and implementing solutions

188
00:06:54,420 --> 00:06:56,610
like SD-WAN and SASE

189
00:06:56,610 --> 00:06:58,770
is going to be important for you to consider.

190
00:06:58,770 --> 00:07:00,840
These technologies aren't just about keeping pace

191
00:07:00,840 --> 00:07:02,340
with the digital transformation,

192
00:07:02,340 --> 00:07:04,650
but they're actually focused on anticipating the future,

193
00:07:04,650 --> 00:07:06,030
preparing for its challenges,

194
00:07:06,030 --> 00:07:08,820
and capitalizing on its potential opportunities.

195
00:07:08,820 --> 00:07:11,850
An SD-WAN, or a software-defined wide area network,

196
00:07:11,850 --> 00:07:13,710
is going to be a virtualized approach to managing

197
00:07:13,710 --> 00:07:15,930
and optimizing wide area network connections

198
00:07:15,930 --> 00:07:18,300
to efficiently route traffic between remote sites,

199
00:07:18,300 --> 00:07:20,670
data centers, and your cloud environment.

200
00:07:20,670 --> 00:07:24,000
The Secure Access Secure Edge, or SASE, on the other hand,

201
00:07:24,000 --> 00:07:26,340
is a security framework that combines network security

202
00:07:26,340 --> 00:07:28,140
and wide area network capabilities

203
00:07:28,140 --> 00:07:30,150
in a single cloud-based service.

204
00:07:30,150 --> 00:07:31,470
By leveraging these tools,

205
00:07:31,470 --> 00:07:33,990
we're able to elevate our organizational security posture

206
00:07:33,990 --> 00:07:36,510
and continue to move forward in our security careers

207
00:07:36,510 --> 00:07:38,040
as we begin to migrate more heavily

208
00:07:38,040 --> 00:07:39,573
into cloud-based environments.

