White Paper | Internet Access Hybrid SASE

White Paper | Internet Access Hybrid SASE

Check Point SASE hybrid Internet Access uses on-device and cloud-based security for unmatched performance and better privacy. Download the White Paper.

White Paper | Internet Access Hybrid SASE

INTERNET ACCESS WITHOUT COMPROMISE: THE HYBRID SASE APPROACH

2THE HYBRID SASE APPROACH

Overview Ransomware and other types of malware infections are some of the most dreaded cybersecurity incidents that companies face. Almost daily we hear about yet another business falling victim to an attack; it seems no one is immune to the enterprise of cybercrime.

A common way malware reaches the organizational network is of course the Internet. This endless gateway to knowledge is an essential tool for today’s employees. Unfortunately, it also constitutes an endless attack surface. An unsuspecting visit to a compromised website can easily become the vehicle by which malware can compromise an employee’s device. From there, the entire corporate network is at risk, and the potential damage is immense. While this scenario is by no means new, the magnitude, sophistication, and devastation of today’s breaches are unprecedented.

Internet Access (IA) security—also referred to as Secure Web Gateway (SWG)— is traditionally of- fered as an on-prem appliance but is more commonly served via the cloud. But which IA solution is the right one for you?

The IA Dilemma Cloud-based IA security might seem like the obvious choice. Delivered as a SaaS, it means there are no on-premises deployments, no ongoing appliance maintenance (software updates, security patches, etc.), a centralized management system, and better cross-company visibility into security events. The downside of cloud-based IA, however, is that all traffic needs to be routed through it.

For a unified solution that combines remote access (ZTNA, VPN) with IA, and possibly other secu- rity services, this means all traffic, including web browsing, must pass through the secure remote access tunnel. This can cause congestion and affect performance of critical internal business applications.

To avoid this, many companies bypass part of (or all) web traffic from the secure tunnel and send it directly to the Internet—also called split tunneling. This means bypassed traffic will not be routed through the cloud service and will therefore not be protected by an IA solution, leaving an exposed attack surface.

"SWG is a common secure Internet Access solution"

3THE HYBRID SASE APPROACH

Office 2©2023 Check Point Software Technologies Ltd.

IA

Remote

Web

1©2023 Check Point Software Technologies Ltd.

Bypassed traffic is not protected.

Office

Remote

IA

WebWeb

An additional downside of cloud-based IA solutions is that they perform TLS decryption in an un- controlled environment, essentially performing a man-in-the-middle attack in a potentially insecure datacenter and/or unknown geographic location.

On-prem IA solutions don’t suffer from this blind spot as all traffic is scanned locally, regardless of destination. They do, however, have their drawbacks. Besides the time, cost and effort needed to deploy, manage, and maintain them, they require backhauling remote user traffic through an on- prem office or other location where the IA solution is deployed. This creates the so-called “trom- bone effect” which adds latency, impacting user experience and productivity.

Cloud-based IA

The downsides of on-prem solutions are fueling the SaaS revolution and cloud-first strategy that many companies are adopting. But with the shortcomings of cloud-based IA, it seems there is no perfect option, just a more tolerable compromise. Both cloud-based and on-prem IA implementa- tions have significant shortcomings. There’s a need for a better way.

On-Prem IA

4THE HYBRID SASE APPROACH

3©2023 Check Point Software Technologies Ltd.

IA

IA

IA

IA

Remote

Office

Web

Introducing the Hybrid SASE Approach A hybrid solution combines the advantages of cloud-based and on-prem IA. It consists of a cloud- based solution working in concert with an on-device agent.

Device-Side IA Instead of deploying stand-alone appliances in office locations, the IA agent deploys on the employ- ee’s device. This means employees are always protected, no matter where they connect from—of- fice, home, coffee shop or anywhere else—without the need to backhaul traffic through an on-prem location.

It also means employees are protected even when not connected to the corporate network or when traffic is bypassed (split tunnel). Device-side IA doesn’t require any on-prem hardware or virtual machine installations. The agent is easily deployed on employee devices and is centrally managed across the entire workforce. Additionally, it performs SSL inspection on the device itself, without the need to decrypt traffic at a remote, uncontrolled location, maintaining privacy.

Cloud-Side IA Cloud-side IA provides all the benefits of a typical SaaS solution. It requires no hardware deployment or maintenance and is managed via a single-pane-of-glass console. The cloud-side IA acts as an additional layer of protection for traffic passing through the corporate network. It enables enforce- ment of consistent, network-wide policies which do not depend on specific user or group definitions— blocking access to known malicious sites, for example. When defined on the cloud-side IA, this rule will always be applied regardless of the device-side settings.

The cloud-side IA enables organizations to apply stricter policies for when users are “at work” (i.e. connected to the corporate network). This can include blocking access to social networks (e.g. Facebook) to improve productivity.

5THE HYBRID SASE APPROACH

Another common use case would be blocking access to gambling or hate websites to reduce the risk of employee misconduct and possible liability for the organization. A cloud-side IA solution also adds public Wi-Fi protection since it can encrypt all communication between it and the user device. In cases where the device-side agent is not used, cloud-side IA becomes the primary layer of protection. This can happen when an organization prefers cloud routing, for example, or if an unsupported legacy device cannot run the agent. As long as a user is connected to the corporate network, they are protected. Organizations can also choose not to work with the cloud-side IA at all, and only use the client-side. The Hybrid approach provides complete flexibility in deploying either option or both in tandem.

Hybrid SASE — The Best of All Worlds Hybrid SASE is a unique approach from Check Point. It is the result of feedback from IT profes- sionals across the industry about the limitations of existing secure internet solutions and the pain points they create.

It eliminates all the major drawbacks that traditional cloud and on-prem IA solutions suffer from. Organizations also benefit from a higher level of security, improved compliance, better perfor- mance, and simplified operations.

Check Point SASE’s Hybrid advantages:

• Protects user traffic, even when not connected to the corporate network • Protects bypassed traffic (split tunneling) • Managed from a single-pane-of-glass (both agent and cloud IA instances) • No traffic decryption outside the user’s device • Enables secure and fast direct-to-Internet connectivity • Flexible policy settings (e.g. “at work”) • Flexible deployment models (device and/or cloud-side) • Enables multiple network deployments with network-specific IA policies • No on-prem deployment, management or maintenance • Secures public Wi-Fi connections

Check Point SASE puts an end to the cloud versus on-prem dilemma. It delivers a solution that doesn’t require organizations to compromise on security or performance and is simple to deploy and manage. It can be deployed as a stand-alone solution or as part of Check Point SASE’s unified network security solution, which includes additional services such as Zero Trust Network Access (ZTNA), SaaS Security, and Firewall-as-a-Service (FWaaS). Check Point SASE is also built into the Check Point Infinity Portal, allowing organizations to manage cybersecurity from a single platform.

6THE HYBRID SASE APPROACH

Internet Access Deployment Comparison

On-prem IA Cloud-based IA Check Point SASE

No on-prem appliance deployment and maintenance

Avoids backhauling remote user traffic

Centrally managed from a single console

Direct-to-website connection

Protects bypassed traffic (split tunnel)

Performs TLS decryption in trusted locations

Protects users when not connected to the corporate network

Differentiated policies for "at work" vs "off work"

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599 U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391 www.checkpoint.com

Book a Demo

https://sase.checkpoint.com/demo


Item Type: pdf