Strengthen Branch and WAN Security
Enterprises are becoming more decentralized and distributed; with multiple cloud apps, a myriad of user devices, and deployments of broadband and wireless networks. All of these technologies help enterprises become more competitive, productive and cost-efficient. However, they also bring new challenges, as they increase the attack surface, and obscure visibility into potential security exposure.
End-to-end Control of Security
Mosaic SoftWave SD-WAN supports a variety of deployment architectures to control and secure traffic and data. Mosaic provides end-to-end visibility for corporate data center, cloud and SaaS applications, applying network-wide business and security policies. Our flexible SD-WAN platform makes it easy to use built-in security services, and also service chain third-party cloud security services to support your extended WAN perimeter – from the branch to the cloud.
Mosaic SoftWave SD-WAN as-a-Service security features help thwart attacks on your enterprise WAN:
- Public Key Infrastructure (PKI) – Uses a Certificate Authority (CA) to distribute certificates for authentication in VPN deployments.
- Unique Keys per Tunnel – Using unique keys per VPN tunnel results in a more secure solution than when the same set of keys is shared by more than two sites.
- Secure Onboarding – Ensures new sites connecting to an existing VPN are authenticated and authorized before they are allowed to connect.
- Integrated Certificate Server – While PKI is recommended for authentication because it offers a more secure and scalable solution than pre-shared key authentication, PKI requires a certificate server for certificate management and distribution.
- Tunnel Integrity Check – If an existing branch or hub site in a VPN is compromised, the site’s certificate is immediately revoked and all tunnels to that site are deleted.
- Management Plane Security, Secure Onboarding and Activation – Once connected to the Internet in a zero-touch deployment, SD-WAN Edge appliances automatically authenticate, connect, and receive configuration instructions.
- SD-WAN Orchestrator – Supports Two Factor Authentication.
- Compliance – Every component of the Mosaic SoftWave SD-WAN platform is certified PCI compliant.