Exploring Advanced Security Features for a Seamless SD-WAN Experience
When architects and IT professionals embark on the journey of SD-WAN deployment, thoughts often revolve around connectivity, protocols, and traffic steering. However, one crucial aspect that sometimes gets overlooked is the security of the SD-WAN infrastructure. In this blog, we delve into the security considerations of SD-WAN, focusing on the robust features offered by Riverbed's SteelConnect EX solution.
Does SD-WAN Deployment Require Backhaul?
Traditionally, in network deployments with MPLS branches, all traffic is backhauled to the data center and routed through high-end firewalls. However, with the advent of SD-WAN, the landscape is changing. The plan to replace WAN-edge routers with Riverbed's SteelConnect EX SDWAN solution introduces the potential for multiple lower-cost Internet circuits, application identification, and path-quality-path selection. But are all security bases covered?
Direct-to-Net and Latency Considerations
With Internet circuits deployed at each branch, SD-WAN provides the flexibility to send select traffic directly to the Internet, reducing latency. Notably, traffic bound for services like Microsoft Office 365, Salesforce, or Workday can benefit from this approach.
SteelConnect EX SD-WAN Security Capabilities
Riverbed's SteelConnect EX goes beyond traditional SD-WAN solutions, offering a licensed-based security feature set with three levels: Secure SD-WAN Essentials, Secure SD-WAN Standard, and Secure SD-WAN Advanced.
1. Stateful Firewall:
- Provides full visibility of traffic.
- Enforces fine-grained access control.
- Tracks the state of traffic, granting or rejecting access based on port, protocol, and state table history.
2. Next-generation Firewall (NGFW):
- Distinguishes different types of traffic beyond traditional methods.
- Includes application firewall, intrusion prevention system (IPS), TLS/SSL encrypted traffic inspection, website filtering, and QoS/bandwidth management.
3. Unified Threat Management (UTM):
- Requires NGFW and includes features such as antivirus and vulnerability (IDS/IPS) protection.
- Features a built-in antivirus engine with configurable threat profiles.
Implementing Advanced Security Features
Implementing these features involves thoughtful configuration, especially when considering performance impacts. Each feature, from the stateful firewall to the UTM capabilities, can be selectively enabled based on the specific needs of the network.
Final Thoughts on SD-WAN Security
Understanding the three levels of security capabilities in Riverbed's SteelConnect EX empowers decision-makers to tailor their SD-WAN strategy. While backhauling all Internet-bound traffic may not necessitate advanced security features, enhancing the user experience by sending specific traffic "direct-to-net" demands a discussion on the degree of implementation.
Beyond Security: Considering Performance
While SteelConnect EX offers a commendable level of protection for branch traffic, optimizing performance is equally crucial. Regional disparities in services, especially for Microsoft and other SaaS offerings, might impact user experience. Here, the integration of Riverbed's SaaS Accelerator service with SteelConnect EX becomes paramount, ensuring the highest level of WAN connectivity, branch security, and end-user performance.
In conclusion, a well-thought-out approach to SD-WAN security, coupled with performance optimization measures, sets the stage for a seamless and secure networking experience. Riverbed's SteelConnect EX emerges as a comprehensive solution, providing the necessary tools to tailor security measures according to specific organizational needs.