IT professionals are under constant pressure to improve the WAN security architecture. They need to support and improve the efficiency of their employees while resisting the increasing complex threats, but they cannot significantly increase costs.
Why do you need to change your WAN security architecture?
There are some trends that force enterprises to make comprehensive adjustments to the WAN security architecture in a timely manner. The first is the shift in employee location and behavior. There are fewer employees in the office of the branch, and with the emergence of new collaboration tools and mobile applications, employees can easily work remotely. In addition, about 70% of enterprises use the BYOD procurement model to varying degrees, forcing security personnel to consider security issues from the perspective of protecting and managing enterprise data, rather than from the perspective of equipment.
Second, more and more enterprises are using cloud computing solutions. about 1/4 to 1/3 of enterprises are using infrastructure as a service (IaaS) or platform as a service (PaaS) Cloud solutions. This transforms network traffic from an internal cycle (from user to enterprise data center) to external transmission (from user to cloud environment ). Therefore, many enterprises are replacing their return branch network architecture with the direct connection network.
What are the results? IT professionals need to consider other approaches to provide universal policy-based WAN security.
Option 1: Combined with WAN optimization and existing security
A potential alternative is to combine WAN optimization with Branch security. This requires enterprises to review the traditional method of providing Internet connections to branch sites. The return branch or traditional method must be combined with the MPLS Service (to ensure the security of site-to-site connection) and the WAN optimization controller of each branch. At the same time, security is handled in the data center through the enterprise-level gateway, which provides firewall, network intrusion prevention, anti-virus/anti-spam (AV/) VPN, content filtering, and data leakage protection (DLP.
The advantage of this method is that IT provides consistent security to all sites, and IT still firmly controls the implementation of policy changes. However, the disadvantage is: cost. IT needs to pay for all the equipment of the Branch and the security equipment of the data center (plus the annual software maintenance cost), as well as the internal operation cost (Labor) for managing and maintaining the equipment ). Finally, enterprises also need to pay two Internet and cloud computing Traffic Transmission and service costs: one is a WAN return, and the other is the traffic transmitted over the Internet.
Solution? Start to use the direct connection method. In this architecture, enterprises integrate functions into a branch device-combined with WAN optimization functions and traditional security functions (aforementioned) and unified Threat Management (UTM ). They use the most direct method to route traffic to their final destination: Internet traffic to cloud computing, and data center traffic is returned through the private WAN. Vendors such as Blue Coat, Cisco, Juniper Networks, and Riverbed provide such devices.
Option 2: WAN-optimized security as a service
However, the above method still requires IT professionals to manage internal equipment and all related headaches. The longer-term solution will be WAN optimization and security as cloud services. Although many carriers have separate WAN optimizations as services and security services, they have not yet provided a comprehensive solution. Moreover, carriers are still reluctant to allow customers to modify their configurations in their networks, which means that when these services are transferred, IT professionals lose a certain degree of response speed and control.
However, the integrated WAN Security cloud service is booming. Nemertes research predicts that such cloud services will be widely used within 24 to 36 months. At the same time, IT professionals should consider using branch WAN optimization and security services to ensure that their architecture can withstand the test of time.