DNS & SASE

SASE vs traditional perimeter security

6 min readDNS & SASE

For decades, security followed a castle-and-moat model: a strong perimeter around the corporate network, with everything inside treated as trusted. Cloud, SaaS and remote work have dissolved that perimeter. Secure Access Service Edge (SASE) is the architecture built for this new reality — converging networking and security into a single, cloud-delivered service that protects users and data wherever they are.

The traditional perimeter model

In the classic design, all traffic was routed back to the data centre, where a stack of appliances — firewall, web gateway, VPN — inspected it. This worked when applications and users lived inside the building. But when users are at home and applications are in the cloud, backhauling traffic to a central choke point is slow, expensive and increasingly pointless: the data you are protecting is no longer behind the moat.

What SASE is

SASE (pronounced "sassy") combines wide-area networking and network security into one cloud-native platform. It typically brings together SD-WAN, a secure web gateway, cloud access security broker, firewall-as-a-service, DNS security and zero-trust network access — all delivered from points of presence close to the user. Instead of routing users to security, SASE brings security to the user.

SASE vs perimeter security

  • Trust model — perimeter trusts the internal network; SASE applies zero trust, verifying every access.
  • Location — perimeter protects a place; SASE protects users and data anywhere.
  • Traffic flow — perimeter backhauls to the data centre; SASE inspects close to the user.
  • Delivery — perimeter is appliance-based; SASE is cloud-delivered and elastic.
  • Management — perimeter stitches many tools together; SASE converges them into one policy.

Zero trust at the core

SASE operationalises zero trust: no user or device is trusted by default, and access to each application is granted per session based on identity, device posture and context. This replaces the broad network access of a traditional VPN — where a compromised device could roam freely — with least-privilege access to specific applications, dramatically shrinking the attack surface for remote and hybrid work.

A pragmatic path to SASE

Few organisations rip out their perimeter overnight, and they do not need to. A sensible journey starts with the components that deliver immediate value — Secure SD-WAN to unify and protect branch connectivity, and DNS-layer security to block threats network-wide — then adds zero-trust access and cloud-delivered web security as remote work and SaaS adoption grow. SASE is a destination reached in stages, not a single purchase.

How iconnet helps

iconnet helps Thai organisations build toward SASE with the components that fit today — Forcepoint Secure SD-WAN and NGFW for the network edge, and VeraDNS for protective DNS — and a roadmap to converge security in the cloud over time. Talk to our engineers about a staged, practical path to a perimeter-less architecture.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.