---
# source: src/content/solutions/en/vmware/vmware-secure-access-service-edge.md
# route:  /en/solutions/vmware/vmware-secure-access-service-edge/
title: SASE
tags: [network, security]
vendors: [vmware]
summary: WAN and security as one architecture. Access depends on identity and context rather than on a tunnel into the company network.
photoNeed: "A vSphere or VCF console on a real screen at soulTec: a cluster view, a running task, an inventory tree, so the reader should recognise the UI"
stub: false
draft: false
kind: product
addon: false
vendorName: VMware Secure Access Service Edge
status: current
---

## What it is

SASE delivers WAN services and security functions as one cloud-based architecture. Instead
of hauling traffic back to the datacentre, identity- and context-based access replaces the
classic VPN. The services run across a global network of points of presence.

It includes SD-WAN, Cloud Web Security, Secure Access and Edge Network Intelligence, managed
from one console, and can be run as a managed service or yourself.

## The problem it solves

Work is distributed and applications live in the cloud. A model that forces every request
through the company network creates a bottleneck exactly where it costs most: bandwidth
runs short, connections drop, and application performance is better in the office than at
home even though both are using the same SaaS application.

## What to watch

SASE replaces the VPN organisationally as well as technically. Where decisions used to be
made at the perimeter, they now get made per user, per device and per application, and
somebody has to write those policies. That is where the effort sits, not in the setup.
