Frequently asked questions about SASE

Answers about SASE

SASE FAQ: From VPN and MPLS to ZTNA and SD-WAN

SASE (Secure Access Service Edge) brings networking and security together in a modern, cloud-based architecture. Many companies are asking whether and how traditional VPN and MPLS can be replaced by a modern, cloud-based architecture. Our FAQs answer questions about the specific benefits of SASE, ZTNA and SD-WAN, and how migration can be implemented step by step with minimal risk.

Symbol eines stilisierten Cloud-Icons mit Linien, die nach unten führen – dargestellt als Symbol für Netzwerkverbindungen oder Cloud-Konnektivität.

SASE (Secure Access Service Edge) combines network functions such as SD-WAN with security functions such as Firewall-as-a-Service, SWG, CASB and ZTNA in a cloud-native architecture. It does not necessarily replace all existing components immediately, but it enables a gradual migration towards a consolidated, centrally managed security architecture.

Traditional VPN often grants broad network access after login, which increases the risk if accounts are compromised. ZTNA (Zero Trust Network Access), by contrast, grants only granular, application-specific access based on the principle of “never trust, always verify”. A move to ZTNA is particularly worthwhile for hybrid working models, many external partners or suppliers, or when the attack surface needs to be reduced.

Compared with traditional MPLS, SD-WAN offers more flexibility, often lower costs, dynamic traffic routing, for example direct internet breakout for cloud applications, and centralised control across all locations. The business case depends on the number of sites, bandwidth requirements and the degree of cloud usage. An individual analysis shows the potential for savings.

SASE brings networking and security functions together in a cloud-based architecture. This allows users and locations to access applications and data according to consistent security policies, regardless of where they are located. At the same time, the complexity of many separate security and connectivity solutions can be reduced.

No. A step-by-step approach often makes sense, for example starting with VPN replacement and ZTNA, connecting individual sites, or migrating from MPLS to SD-WAN. This allows the architecture to be developed in a controlled way and the benefits of individual steps to be measured. An Asecus SASE transformation workshop is a good first step. You receive an assessment of the current situation, a clear definition of the requirements for a new architecture, and a possible step-by-step approach to benefit from SASE.

A phased approach is recommended: first, an analysis of the existing network and security landscape; then pilot sites; followed by a gradual rollout with parallel operation of the legacy systems during the migration phase. This minimises risks and allows experience to be gathered for the full rollout.