Secure Access Service Edge (SASE)
Secure Access Service Edge (SASE) is an architecture concept that brings together network functions for wide area networks and security services in a common, cloud-based service. Users, sites and devices connect to distributed access points of the service, where traffic is forwarded and inspected according to uniform policies – regardless of where users and applications are located.
The term was coined in 2019 by the analyst firm Gartner. SASE unites two layers: the network layer, above all Software-Defined WAN (SD-WAN), and the security layer, which Gartner has referred to as Security Service Edge (SSE) since 2021. SSE typically includes secure web gateway, cloud access security broker, zero trust network access and firewall as a service. Inspection takes place at a provider's Point of Presence (PoP) close to the user, so that traffic does not first have to pass through a central data center.
A distinction is made between single-vendor SASE, in which network and security functions come from one provider, and multi-vendor approaches, which combine SD-WAN and SSE from different providers. SASE replaces classic hub-and-spoke networks with a central security perimeter and transfers zero trust principles to network access. In practice, SASE is obtained as a SASE platform that provides both layers via common management and a uniform policy model.