Since the COVID-19 pandemic began, corporate IT staff have been working to update their cloud, network, and security infrastructure to adapt to the new hybrid work environment.
To support digital transformation initiatives that prioritize cloud, many enterprises are SD-WAN, SASE and present SWe are verifying technologies that start with the letter S, such as SE (Security Service Edge).
SD-WAN vs. SASE vs. SSE
A network technology that emerged innovatively in 2015 SD-WANis already being used by many enterprises to modernize their WANs. Aruba’s EdgeConnect Enterprise Advanced SD-WAN platforms, such as the SD-WAN Edge Platform, reduce network complexity and improve application performance, making connections between users and applications in the cloud and data centers more efficient.
SASESecure Access Service Edge (SASE), a term coined by Gartner in 2019, is a framework for converging WAN and network security functions into a single, cloud-based model. SASE is one of the essential elements for the digital transformation businesses demand today.
The third is SSE(Security Service Edge). This is the security component of SASE, which Gartner announced in February 2022, integrating all security services, including a Secure Web Gateway (SWG), a Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA). It protects access to web, cloud services, and individual applications.
SSE provides both data protection and threat protection, as shown in the figure below.

This picture should prompt us to reflect on whether we are simply accepting SASE as a comprehensive security or network framework, a blueprint for digital transformation.
Two requirements for providing a secure network connection
The requirement of enterprise IT managers is to connect to all business applications across all devices and locations. “"safe"” It provides network connectivity. There are two main requirements here.
- How do you securely access applications distributed across multi-cloud environments, data centers, and Software-as-a-Service (SaaS) environments?
- How do you secure a growing number of IoT devices that cannot run agents on their endpoints?
Of course, SSE capabilities offered by cloud security vendors like Zscaler, Netscope, and CheckPoint can be integrated with SD-WAN platforms like EdgeConnect via APIs or orchestrators to ensure secure connections to cloud, data centers, and branch office environments. This addresses the first requirement.
Regarding the second requirement, in environments with a large number of IoT devices, installing the SSE ZTNA agent on them is often impractical or even impossible. IoT devices represent a major vulnerability that can lead to potential security threats or breaches. If you deploy IoT devices from hundreds of manufacturers, one of them will eventually develop a security vulnerability and cause a breach.
Aruba's ClearPass or the recently released Aruba Central NetConductorUsing an identity-based role access control solution like this one allows you to extend microsegmentation and security policies across Aruba's entire product stack, even integrating with advanced SD-WAN solutions to automatically segregate user and IoT device traffic.
Therefore, SSE solutions and advanced SD-WAN solutions not only address the security and network requirements for both secure access and IoT connectivity, but also help enterprises transform toward SASE.
Single vendor vs. multi-vendor?
Another important decision companies must make is whether to implement SASE in a multi-vendor environment or use a single vendor platform.
In fact, a recent Gartner report, “How to Align SD-WAN Projects with SASE Initiatives,”(1)“We recommend the following:.
Choosing a single-vendor SASE solution presents challenges for many enterprises, as few vendors offer best-in-class solutions and even those that offer satisfactory functionality across all SASE functional areas.
Gartner, How to Align SD-WAN Projects With SASE Initiatives, Published 18 April 2022
After evaluating the SD-WAN vendor that best suits your organization, evaluate the available options for SSEs that can be operationally integrated with your preferred SD-WAN. Specifically, evaluate whether integration is possible at the console or API level.
Gartner, How to Align SD-WAN Projects With SASE Initiatives, Published 18 April 2022
Best-in-class SSE and SD-WAN in a multi-vendor environment gives enterprises the flexibility to choose the best technology available for their SASE migration based on their business requirements.
For example, a company might acquire another company or business that uses a different cloud security provider. In this case, how will the existing SD-WAN platform integrate with the two security providers?
What if an SD-WAN platform supported service integration and automation within APIs or orchestrators, seamlessly integrating SD-WAN and cloud security?
Aruba's EdgeConnect Enterprise is a best-of-breed SD-WAN platform with proven integrations with leading network cloud security vendors including Zscaler, Netscope, CheckPoint, McAfee, iBoss, and PaloAlto Networks Prisma Accecss.
This allows enterprises to configure, deploy, and develop their SASE frameworks while gaining the added flexibility of cloud-delivered security options without compromising best-in-class technology. Having a single manufacturer supply all components risks becoming reliant on that vendor for secure, cloud-first digital transformation.
However, using a flexible, multi-vendor approach to SASE can mitigate these risks.




