Written By: Matthew Watkinson
As discussed in our previous blog (you can check it out here), being technology aware is important in today’s landscape as threats and security are advancing at a rapid rate. Sometimes we face challenges in finding the right technology for our organization, one being long-term, cost effective solutions. As we near the end of the second week of Cyber Security Awareness Month, we move our focus to a second security technology with key implications for today’s landscape and a discussion of how you can simplify networking and reduce your costs: private WAN technologies and SD-WAN.
Within the last couple of years, there has been an increase in requests to move away from dedicated private WAN technologies like MPLS to more flexible technologies such as SD-WAN and those that facilitate Zero-Trust architectures.
Security implementation is not exclusively about denying process, blocking activities, and eliminating risk by being in the way. Security should be about empowering the business to operate as smoothly as possible, and empower users to work in the most effective manner possible.
In traditional Private WAN topologies, many remote sites are all interconnected through a Private WAN setup, like a dedicated MPLS provider or even dedicated SD-WAN hardware which is operating like MPLS funnelling all internet bound traffic to the internet through the Private WAN.
With more services being consumed in a SAAS model, or IAAS model from public clouds, these services are moving even further away from office workers. Applications that were available in the local site, organizational datacenters, or even colocation facilities over private WAN links now have to cross these same boundaries, but then add additional networking distance by crossing internet links to access the required resources.
Bringing internet access closer to the consumer has become a way to reduce spending in private WAN links, simplify routing and networking, and distribute internet access through SD-WAN topologies. This has been a very popular request from our customers as they have adopted these cloud technologies faster, especially during the current heavy reliance on work–from–home. As these technologies are being adopted, it is putting more demand on enterprise WAN edges and decentralizing this access has relieved this pressure across the organization.
Managed Private WAN circuits cost money. Serious money. Providers are accounting for the possibilities of outages and SLA penalties are costed into your monthly fees. You effectively pay extra for the privilege of the service provider having to provide a “rebate” in an SLA non-compliant window. Unmanaged WAN technologies like GPON and DSL have become so much more resilient and stable in the last decade. These networks that are traditionally “less stable” have greatly increased in stability with advances in technologies and the reduction of costs that come along with them. This said, the cost for the services increased. Managed network circuits still have a fantastic uptime and stability, but the delta between managed and unmanaged circuits in actual performance has dropped significantly.
Managed circuits still experience outages, rare as they are, but the money you “get back” on an SLA penalty doesn’t really recover the costs for a site being down or degraded. It is just an incentive to get your ISP to not make silly mistakes. But with unmanaged circuits being so affordable now, 3rd party players in the market reselling primary provider bandwidth, and reasonably priced LTE bandwidth available just about everywhere in North America, you can self-manage a reasonably high connectivity profile just by getting your WAN bandwidth from one of these more cost-effective solutions. To reduce single points of failure, layer multiples of these more cost–effective WAN solutions and you are well on your way to providing better performing networks.
The benefits of SD-WAN over private networking is that the consumer can take advantage of the increased resilience in commodity networks over managed circuits, and using the power of software bond cheaper circuits together to “add” up to the resiliency of more robust networking.
By moving traffic to unmanaged circuits, moving off of dedicated bandwidth links, and taking the power into your own hands, you can absorb the risk of outages and operate at:
SD–WAN topologies come with their own complications. Distributed environments already have their own wireless and wired networking, authentication to networks, and adding a distributed and decentralized security model has its own complications. With private WAN links, internet edge filtering is easily accomplished through a limited set of controlled network access points, firewalls, web filters, IPSs etc. but as soon as you have multiple internet ingresses into the environment, all of these security resources must be also made available at each local site. Tying security into SD-WAN is fundamental for its success.
When we look at the Fortinet SD-WAN/SDBranch model of distributed network access, it offers the following benefits:
As you can see in the above diagram, by leveraging SD-WAN secure internet access can be delivered directly to remote sites. Even if you are hosting content in public cloud infrastructures, we can leverage SD-WAN edge technologies to take advantage of the excellent internet connectivity these services offer and provide access directly to your remote sites. Your costly private WAN links have been eliminated and latency and bandwidth for access to collocated datacenter facilities, private cloud infrastructure, and even hybrid environments have all been improved. Connectivity between remote sites will be sent using the best path available as discovered and measured by the SD-WAN controllers and ensure a resilient path for all applications communicating between sites inside the SD-WAN ecosystem. If you have multiple public clouds being used, each one can be attached to the SD-WAN environment, giving each one diverse connectivity through various paths.
If you don’t have the expertise to run your own SD-WAN deployment, this is where our new Managed BYOA SD-WAN Service comes in. BYOA, bring your own access, allows you the consumer to be in control of what you want to spend on a per-link basis to get the best performance/dollar available. We will glue all of the links in each of your sites together using SD-WAN technologies to effectively provide you with the best resiliency of all links combined. Alternatively, through our partnership with Telus, we can bring network connectivity along with the service and you still get full control over what connectivity and WAN links are used. Our engineering and architecture staff will guide you through what your options are for each of your sites, and you are able to broker connectivity with your ISPs directly or as a bundle with our Telus partnership, ensuring that you are in control of all your data.
Contact your Secure Sense sales representative at email@example.com.
Don’t forget, our week 2 pop quiz will be available at 12:00pm EST on LinkedIn. Each week we will be givingaway a Yeti Tumbler to one lucky participant!
Talking to our experts can answer any questions you may have about any security technology issues you are facing and give your organization the awareness and confidence to make the best decisions for your security now and for the future. Don’t hesitate to reach out to us at 866-999-7506 or shoot us an email at firstname.lastname@example.org.
In honour of Cyber Security Awareness Month, we will be sharing insight on the latest cybersecurity news, tips from Secure Sense experts and general security knowledge geared towards keeping you out of the headlines and focused on what matters most, your business. Don’t miss a beat by following along on our Twitter, Facebook and LinkedIn Pages.
Secure Sense is the security provider that cares. We are a team of experts with a passion for IT and protecting your organization is what motivates us daily. If you have questions or want to learn more about how we can improve your organization’s security, our services or just want to chat security please give us a shout.