Networking
1821985 Members
3514 Online
109638 Solutions
New Article ๎ฅ‚
John_Spiegel

Architecture matters when it comes to SSE

cloud.office.buildings.GettyImages-184342180-1024x683.jpgโ€œThe difference between good and bad architecture is the time you spend on it.โ€

David Chipperfield

Architecture matters when it comes to SSE. The quote by David Chipperfield is revealingโ€”you want the people designing your SSE solution to take their time thinking about how to build a product that scales to modern demands, meets network and security needs with the right amount of balance, and has a solid foundation that can be innovated on. The right product will simplify the world for the employee (the customer of IT), reduce the management burden for IT, optimize the product portfolio, and lower time spent configuring, maintaining, and supporting the solution. 

Enter SSE architected by HPE Aruba Networkingโ€”designed on Zero Trust and cloud principles and focused on simplicityโ€”to converge networking and security for the modern era. Todayโ€™s distributed applications and workforces demand both SaaS and client server applications, requiring a mechanism which reduces effort on the employee and third-party access to line of business applications and dataโ€”without a security tradeoff.  One that delivers both speed and security with no compromises.

The HPE Aruba Networking SSE solution offers:

Single code base for all PoPs: Overcome the age-old dilemma of needing to choose between speed and security when deploying a new application. By distributing a network security fabric across the globe and architecting both security and network services in all PoPs, weโ€™ve created a true global network and security fabric that supports services including SD-WAN, CASB, ZTNA, and SWG and utilizes cloud native technologies like containers and microservices. 

Resiliency: Employees just want to work without poor IT solutions slowing them down. The HPE Aruba Networking Smart Routing technology built into our SSE solution supports connectivity to multiple PoPs and allows multiple paths depending on traffic type, enabling speed and low latency for real-time applications and large downloads. Failover between PoPs is fast and reliable, allowing a client device to move to the next PoP if one becomes congested to maintain uptime and application access.

Zero Trust Networking Access (ZTNA): To maintain security, employees and third parties should not be able to see the entire network or have access to all data in the cloud or in the data center.  Bad cyber actors must be prevented from moving laterally through the network. The HPE Aruba Networking SSE solution runs each transaction through an adaptive trust engine, validating identity, device, type of request, time of day, location, and other configurable factors and then matching it against a single policy engine to determine whether to grant or deny access. With ZTNA, the employee or third party gets access to only what they need to do their job, nothing more, nothing less. The solution supports both agent-based access for employees and multiple protocol agentless access for those difficult-to-secure third parties.

When selecting a security solution, make sure to dive deep into the architecture and understand its design principles. Ask about the philosophy behind the solution. Detail out resiliency features. Determine how deep the product provides ZTNA access. And finally, make sure it is easy to use and maintain. There is a difference between good and bad architectures. Understand them.

About the Author

John_Spiegel

John Spiegel is Director of Strategy and Field CTO for the Axis Atmos SSE platform, powered by HPE Aruba Networking. He has 25 years of experience running global networks and managing infrastructure. He is an industry pioneer in software defined networking (SDN) and software defined WANs (SD-WAN). When not helping companies on their journey to modernize and secure their networks, John can be found cycling on the backroads of Oregon.