We start today a series of
deliveries in which we will give you some keys to SD-WAN
deployment. Keys that take into account aspects such as security,
deployment or how to segment applications for better control.
What is most interesting
when deploying any architecture, whatever the type? Safety. This is a premium
condition above all things, so it is vital to give it the attention it
deserves.
So, in the case of
SD-WAN, how can you not dedicate a few minutes before performing the desired
deployment with this technology? Because what is clear is that moving from a
traditional WAN architecture to another defined by software (SD-WAN) results in
an improvement in security. Especially in an environment where business agility
is required for remote sites to run quickly.
A key value of SD-WAN is
that it unifies secure connectivity in all transports without losing their
independence. Therefore, it is not necessary to use or provide a different
security mechanism for different types of transport or to depend on the
transport provider for your secure network.
In addition, another
aspect to keep in mind: the network overlay can support a wide variety of
security capabilities. That said, here are the main requirements that should be
in each SD-WAN security checklist.
Segmentation
SD-WAN is able to
perform a deep recognition of applications, which allows very granular control
over how specific traffic is routed
Most companies today
have a need for segmentation to isolate different types of traffic for
regulatory reasons, for example, PCI data, or to provide their own network
segments to different business groups. Companies can address these needs in the
same way that a service provider would use virtual LANs (VLANs) or virtual
routing and forwarding (VRF).
Where is the value of
SD-WAN? Where you can drive the segmentation and do it in a much more secure
way than even MPLS, because MPLS does not encrypt any traffic at all, while
SD-WAN automatically encrypts all traffic.
Secure insertion of services
An SD-WAN
solution will incorporate basic security features, such as a next generation
Layer 7 firewall in edge devices, but it will not necessarily be a first-class
security solution. However, additional security services can be inserted
in multiple locations as needed to provide all the security capabilities and
business needs.