Zscaler & Zero Trust operations glossary ยท Access & traffic

What is SASE?

Definition

SASE (Secure Access Service Edge) is an architecture model that combines network functions such as SD-WAN with cloud-based security services such as zero trust access, firewall, web protection and data protection on a single cloud platform. Instead of routing traffic through a data centre and securing it there with individual appliances, network and security come together at a cloud point close to the user, geographically the nearest one available. The concept replaces rigid, site-bound networks and suits organisations with many locations, plenty of remote work and cloud-based applications.

SASE in detail

SASE classically consists of two layers: a network layer that connects sites and users to the cloud, usually through SD-WAN, and a security layer known as SSE (Security Service Edge), which bundles zero trust access, web filtering, cloud firewall and data protection functions. Both layers run on the same cloud infrastructure, so policies apply consistently across every access path.

For organisations, this means moving from many separate, locally managed systems to central, cloud-based control of network and security.

Why SASE matters in Zscaler operations

Adopting SASE shifts responsibilities: network and security teams work more closely on the same platform, and faults can no longer be cleanly assigned to a classic network or security team. Slow access can come from the SD-WAN connection, a security policy or the cloud service itself.

For operations, this means diagnostic tools need to look across the whole SASE chain instead of showing just one slice, so causes can be told apart reliably.

Common sources of error

SASE in practice: what CentaurNexus contributes

CentaurNexus brings together the views on ZIA, ZPA and ZDX as a cockpit layer above the Zscaler security part of SASE, so usage, policy and experience status can be checked in one place, without Zscaler admin rights. That makes it easier to tell whether a fault sits in the network connection or in the security layer. What this operational view looks like in practice is shown in the guide Zscaler support without admin rights.

See the cockpit view of the Zscaler SASE layer in the live demo.Watch the live demo

Related terms

Frequently asked questions about SASE

What does SASE mean?

SASE stands for Secure Access Service Edge. The model combines network functions such as SD-WAN with cloud-based security services such as zero trust access, firewall and web protection on a single cloud platform, instead of running the two separately through a data centre and individual appliances.

What is the difference between SASE and SSE?

SSE (Security Service Edge) covers the security functions of SASE, meaning zero trust access, web protection, firewall and data protection, without the SD-WAN network component. SASE is therefore the broader concept, and SSE its security-focused core.

How does Zscaler fit into a SASE concept?

Zscaler covers the security part of SASE with ZIA, ZPA and other services, effectively forming the SSE layer. For the network component, organisations often combine this with SD-WAN solutions from partners to get the complete SASE picture.

Why SASE matters in Zscaler operations

SASE brings many previously separate systems together in one cloud layer. That simplifies the architecture, but it also shifts diagnosis: a problem can involve the network, a security policy or the cloud service itself, and without the right tools it is hard to tell them apart cleanly.

Does SASE fully replace classic firewalls and VPNs?

Yes, in most SASE rollouts, at least for standard traffic from sites and mobile users. Individual special cases, such as OT environments with particular requirements, are often migrated in stages rather than switched over in one step.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.