Analyst Report | Guide to Optimizing SD-WAN Performance and Security for Any Size Business
Learn how integrated SD-WAN and cyber security improve application performance, connectivity, and threat prevention across distributed environments. This Enterprise Strategy Group showcase examines SD-WAN best practices, network modernization, and Check Point Network Security solutions.

This Enterprise Strategy Group Showcase was commissioned by Check Point Software Technologies Ltd. and is distributed under license from TechTarget, Inc.
© 2023 TechTarget, Inc. All Rights Reserved 1
AUGUST 2023
Guide to Optimizing SD-WAN Performance and Security for Any Size Business Bob Laliberte, Principal Analyst
Abstract: Modern application environments are highly distributed across data centers, public clouds and edge locations. As a result, organizations must ensure secure connectivity and consistently positive experiences, regardless of where the application is located. Check Point recently announced its Quantum SD-WAN offering to provide a fully integrated solution that delivers optimized security and network performance.
The Current Environment Modern IT environments are highly distributed. Applications are distributed across private data centers, multiple public cloud locations, and edge environments. As shown in Figure 1, research from TechTarget’s Enterprise Strategy Group revealed that cloud usage is virtually ubiquitous, with 96% of respondents indicating that they use public clouds (IaaS and SaaS).1 Even more telling is that 9 out of 10 stated they are using two or more public clouds (IaaS and PaaS), and more than half of those respondents said they are using them in a meaningful way. In addition, applications are increasingly being deployed in edge locations as well, with 94% citing it as a top 10 priority for their organization.2 This is especially true of organizations deploying IoT devices at these locations and requiring applications to provide real-time insights and a secure network to transfer the data to an aggregation point.
Figure 1. Application Environments Are Becoming More Distributed
Source: Enterprise Strategy Group, a division of TechTarget, Inc.
1 Source: Enterprise Strategy Group Complete Survey Results, 2023 Technology Spending Intentions Survey, November 2022. All Enterprise Strategy Group research references are from this survey results set unless otherwise noted. 2 Source: Enterprise Strategy Group Research Report, The State of Digital Ecosystems at the Edge, September 2022.
S H O W C A S E
2
Showcase: Guide to Optimizing SD-WAN Performance and Security for Any Size Business
However, despite the rapid growth and increasing use of public clouds and edge locations, the majority of workloads are still located in private data centers. Therefore, organizations need to ensure that users can securely connect to these applications, regardless of their location.
These distributed IT and application environments, while creating greater agility for the business, also have a downside. The majority of respondents (53%) to the Enterprise Strategy Group research survey said they believe that their IT environment is more complex or significantly more complex than it was just two years ago.
Even worse, most of the legacy architectures created when all applications were in the data center are not fit for the purpose of today’s modern designs. The castle-and-moat security and hub-and-spoke networks don’t provide the optimized performance and security required for modern environments. Indeed, hub-and-spoke networks drive all the traffic through the data center (see Figure 2). Therefore, when connecting to cloud-based or other branch locations, they introduce latency and poor experiences. This suited the castle-and-moat security well, as it enabled all corporate traffic to run through the security stack in the data center. However, modern environments require that all users have both secure connectivity and optimized performances that deliver positive experiences.
Figure 2. Legacy Network and Security Architecture
Source: Check Point Software.
IT teams need to overcome legacy architectures and the inherent complexity arising from these distributed environments. Operations teams need to leverage solutions that drive greater operational efficiency and comprehensive security, freeing up time to work on strategic digital transformation initiatives.
3
Showcase: Guide to Optimizing SD-WAN Performance and Security for Any Size Business
What Is Needed In a digital economy, organizations can’t afford to trade off network performance for security, or vice versa. All connections need to be highly secure and optimized for performance. Fortunately, new network and security architectures and solutions have been developed to overcome these challenges.
For example, modern WAN implementations leverage direct internet access architectures, which use SD-WAN technology to enable organizations to connect directly to applications located in cloud service provider (IaaS or SaaS), data center, or remote branch locations without the need to traverse the data center security stack. This transition also means the data center security stack needs to be distributed to the remote branch locations. Providing functions such as firewalls, application control, data protection, and threat prevention can ensure secure connections in highly distributed environments.
SD-WAN technology provides a number of enhancements over legacy fixed-line connections. This includes the ability to:
• Dramatically improve network performance and experiences. The ability to connect directly to applications hosted in the cloud, at the data center, or at other remote branches ensures that users have a positive experience.
• Prioritize and optimize application traffic based on its importance to the business. SD-WAN enables organizations to keep mission-critical applications online and perform optimally in a failover situation -- while deprioritizing non-business-critical applications.
• Enable remote and branch offices to leverage multiple network links (broadband, MPLS, or cellular 4G/5G) to take advantage of an active-active-backup WAN connection that enables fast failover times. In addition to providing more bandwidth, leveraging broadband and cellular connections can typically reduce network costs as compared with multiple MPLS connections.
• Utilize centralized cloud-based management that enables network teams to create policies that are then distributed and consistently enforced at each of the remote locations.
• Provide enhanced threat prevention to better protect branches that are connecting directly to the internet through local ISPs. This would include the ability to have capabilities such as sandboxing, content disarm and reconstruction, data loss prevention (DLP), antimalware, and virtual patching with an intrusion prevention system (IPS).
• Facilitate enterprise-grade visibility and troubleshooting. A centrally managed SD-WAN solution provides a view of the network at both the organization and branch levels for improved visibility, monitoring, and troubleshooting of the WAN’s health. With real-time monitoring, organizations always know the quality of their branch connections (e.g., down, poor, good, or excellent), and they can drill down into an event to pinpoint the source of a failed or bad connection. Looking at steering events, they can see when a WAN link failed over to another connection (e.g., from ISP1 to ISP2 or mobile network operator), why the link swap occurred (e.g., jitter, packet loss, or latency), which applications or services it affected, and which specific users or groups it affected, according to the steering policy involved.
While SD-WAN technology in itself is beneficial to a business, the value is far greater when it is tightly integrated with security solutions.
Check Point Quantum SD-WAN Enables an Integrated Network and Security Solution Check Point is well known for its Quantum, CloudGuard, Harmony, and Horizon security solutions. The Quantum line focuses on network security, including high-efficacy, next-generation firewalls and threat prevention solutions in
4
Showcase: Guide to Optimizing SD-WAN Performance and Security for Any Size Business
its Quantum Gateway. In fact, according to Check Point, its Quantum solutions have a 99.7% block rate.3 Harmony solutions provide a security service edge for remote users with Harmony Connect. To provide secure connectivity to modern distributed environments, Check Point now offers an SD-WAN software blade for the Quantum and Spark gateways. Details of this solution include: • Converged security and networking
o With fully converged security and network optimization in a single appliance, organizations can take advantage of their existing Check Point security gateways to easily deploy SD-WAN with no additional hardware required. Plus, using a single vendor ensures tightly integrated security and SD-WAN technologies.
o Unified cloud-based management for both SD-WAN and on-premises security appliances/gateways will be especially important for highly distributed SD-WAN environments, as it will drive operational efficiencies. Enterprise Strategy Group research highlights that almost three-quarters (73%) of organizations prefer cloud-based management.4
o Advanced threat prevention features a full branch-level security stack that includes application control, DLP, sandboxing, virtual patching with an IPS, antimalware, zero-phishing and anti-bot capabilities, etc.
o The secure access service edge (SASE) offering leverages unified cloud-based management for cloud- based FWaaS and SD-WAN.
• Optimized connectivity and accelerated time to value o Immediate performance optimization with Check Point’s first-packet application detection engine and out-of-
the-box steering policies ensures that organizations can rapidly improve connectivity upon installation. o Dynamic path selection technology based on an application, user, or group in addition to link health—as
determined by jitter, packet loss, and latency data—enhances the optimization capabilities. o The application detection engine automatically identifies more than 10,000 different apps to create granular
application- and user-based policies. This saves organizations the significant amount of time it would take to identify all applications and create individual policies for them. The engine also includes autonomous steering policies for SaaS applications out of the box (e.g., prioritizing remote help desk support over other business applications), based on the latency-sensitivity of an application.
o Subsecond failover, which enables failover to secondary and tertiary links, ensures uninterrupted experiences. This is extremely important for web conferencing (Zoom, etc.) and VoIP applications.
• Unified management with advanced provisioning and monitoring o Organizations can take advantage of zero-touch provisioning in Quantum and Spark gateways.5 o Check Point SD-WAN management includes:
Advanced management, monitoring, and analytics.
Real-time network health per branch, including service-level agreement metrics. Single pane logging for all security products and events.
• Flexible solutions for any size or type of organization o Check Point offers a range of secure SD-WAN solutions, including an all-in-one enterprise solution
(Quantum SD-WAN), all-in-one managed SMB solution (Quantum Spark), and SD-WAN agnostic cloud- based security that can be managed from the same portal (Harmony Connect SASE).
3 Source: Check Point, 2023 NGFW Firewall Security Benchmark. 4 Source: Enterprise Strategy Group Research Report, End-to-end Visibility and Management, April 2023. 5 General availability expected in Q3 2023.
5
Showcase: Guide to Optimizing SD-WAN Performance and Security for Any Size Business
o Check Point solutions provide the ability to scale to support configurations ranging from a small branch office to large data center environments (from 1 to 30 Gbps) and anything in between.
o Integrated Wi-Fi and 5G (Quantum Spark) offers support for all-in-one branch and SMB appliances. o Check Point supports industrial use cases with ruggedized appliances by providing embedded wireless
support (Quantum Rugged).
Figure 3. Quantum SD-WAN With Tightly Integrated Security
Source: Check Point.Software
As shown in Figure 3, the Check Point solution enables fully embedded and integrated security that leverages a vast array of gateway appliances covering branches and ruggedized appliances for industrial needs, as well as on- premises data centers, cloud data centers (IaaS), and enterprise locations.
Conclusion The reality today is that applications are rapidly being distributed across multiple data centers, public clouds, and edge locations. Yet, users must also be able to securely access these applications and have positive experiences. Unfortunately, these distributed environments create more network complexity and increase risk for the business. Legacy architectures and solutions focused on supporting applications located solely in a private data center are not able to support these modern environments and can’t deliver the requisite levels of security and experience.
6
Showcase: Guide to Optimizing SD-WAN Performance and Security for Any Size Business
Organizations need comprehensive network and security solutions that ensure both optimized network connectivity and robust security for all applications, regardless of where they are located. Check Point now offers Quantum SD- WAN to complement its vast array of Harmony and Spark security solutions, ensuring both optimized network performance and effective security solutions for highly distributed modern environments. Leveraging a tightly integrated platform for networking and security will help to drive operational efficiency, reduce risk, and ensure consistently positive user experiences.
©TechTarget, Inc. or its subsidiaries. All rights reserved. TechTarget, and the TechTarget logo, are trademarks or registered trademarks of TechTarget, Inc. and are registered in jurisdictions worldwide. Other product and service names and logos, including for BrightTALK, Xtelligent, and the Enterprise Strategy Group might be trademarks of TechTarget or its subsidiaries. All other trademarks, logos and brand names are the property of their respective owners.
Information contained in this publication has been obtained by sources TechTarget considers to be reliable but is not warranted by TechTarget. This publication may contain opinions of TechTarget, which are subject to change. This publication may include forecasts, projections, and other predictive statements that represent TechTarget’s assumptions and expectations in light of currently available information. These forecasts are based on industry trends and involve variables and uncertainties. Consequently, TechTarget makes no warranty as to the accuracy of specific forecasts, projections or predictive statements contained herein.
Any reproduction or redistribution of this publication, in whole or in part, whether in hard-copy format, electronically, or otherwise to persons not authorized to receive it, without the express consent of TechTarget, is in violation of U.S. copyright law and will be subject to an action for civil damages and, if applicable, criminal prosecution. Should you have any questions, please contact Client Relations at cr@esg-global.com.
About Enterprise Strategy Group TechTarget’s Enterprise Strategy Group provides focused and actionable market intelligence, demand-side research, analyst advisory services, GTM strategy guidance, solution validations, and custom content supporting enterprise technology buying and selling. www.esg-global.com
contact@esg-global.com
Abstract: Modern application environments are highly distributed across data centers, public clouds and edge locations. As a result, organizations must ensure secure connectivity and consistently positive experiences, regardless of where the applicati... The Current Environment What Is Needed Check Point Quantum SD-WAN Enables an Integrated Network and Security Solution Conclusion