Understanding SSE and SASE within the Megaport network
SSE — The security component SSE is a set of cloud-delivered security services. It is designed to protect users and data regardless of where they are located.- Key services — , , and .
- Goal — Secure User-to-App and App-to-App traffic.
- The formula — SASE = SSE + SD-WAN
- Goal — Simplify management and improve performance by combining connectivity and security.
Summary of features provided by SSE and SASE
The following table summarizes SSE and SASE features.Implementing SSE using Megaport services
Architectural overview Some SSE platforms, including Cloudflare, Netskope, Cato, and Palo Alto Prisma Access, integrate with Megaport by providing private connectivity to Megaport-enabled data centers and cloud on-ramps. You can also implement SSE solutions with a Megaport Virtual Edge (MVE), which hosts virtualized network functions (VNFs) such as , CASB, SGW, and ZTNA, at the edge of Megaport’s global private network. The MVE also facilitates secure access from cloud-based SSE platforms to private applications hosted in data centers and CSPs. While SASE focuses on the convergence of SD-WAN and security, an SSE-centric MVE deployment prioritizes the security stack and serves as a private on-ramp to cloud security providers. Instead of sending sensitive corporate traffic solely over the unpredictable public internet, user traffic is directed to a localized MVE. Deployment workflow- Provision the MVE — Deploy an MVE instance in the metro area geographically closest to your users or branch offices to minimize latency.
- Appliance activation — Once the virtual appliance is active on the MVE, it is registered with your SSE vendor’s central management console (for example, Prisma Access Strata Cloud Manager, FortiSASE). This allows you to push granular security policies and identity-based access controls to the edge.
- Establish connectivity — To complete the path, you configure Virtual Cross Connects (VXCs) from the MVE directly to your Cloud Service Providers (CSPs) or your SSE vendor’s cloud points of presence (PoPs).
Implementing SASE using Megaport services
Architectural overview You can implement SASE SD-WAN with MVE, which hosts SD-WAN virtualized network functions (VNFs) directly on Megaport’s global private SDN. Instead of relying solely on the public internet, traffic from branch offices or remote users connects to a localized MVE. The MVE runs certified SASE or VNF appliances from partners such as Cisco, Fortinet, Palo Alto Networks, Versa, and so on, which integrate the SSE security stack with networking optimization (SD-WAN). Deployment workflow- Provision the MVE — Deploy an MVE instance in the metro area geographically closest to your users or branch offices to minimize latency.
- Configure security policies — Once the virtual appliance is active, it will automatically register and authenticate with the vendor’s central orchestrator to incorporate SD-WAN security policies. For example, Palo Alto Panorama and Fortinet FortiManager.
- Establish connectivity — Configure VXCs from the MVE to CSPs such as AWS, Azure, or Google Cloud. This creates a connectivity where traffic is secured at the edge and then transported across Megaport’s private backbone, bypassing internet congestion and reducing egress costs. A 100% private underlay to key locations, such as an enterprise headquarters office or a manufacturing facility, can be created through Megaport’s private data center interconnects globally.