{"id":29592,"date":"2022-10-04T00:37:46","date_gmt":"2022-10-04T00:37:46","guid":{"rendered":"https:\/\/zpesystems.com\/?p=29592"},"modified":"2022-11-04T22:22:18","modified_gmt":"2022-11-04T22:22:18","slug":"the-definitive-sd-wan-security-checklist-for-enterprise-networks","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/","title":{"rendered":"The Definitive SD-WAN Security Checklist for Enterprise Networks"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; theme_builder_area=&#8221;post_content&#8221; _builder_version=&#8221;4.18.0&#8243; _module_preset=&#8221;default&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221; da_disable_devices=&#8221;off|off|off&#8221;][et_pb_row _builder_version=&#8221;4.18.0&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column _builder_version=&#8221;4.18.0&#8243; _module_preset=&#8221;default&#8221; type=&#8221;4_4&#8243; theme_builder_area=&#8221;post_content&#8221;][et_pb_image _builder_version=&#8221;4.18.0&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; alt=&#8221; An SD-WAN security checklist with green checkmarks indicating successful implementation.&#8221; title_text=&#8221;sd wan security checklist&#8221; src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.18.0&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>Software-defined wide area networking, or SD-WAN, has made it possible to efficiently control highly distributed WAN architectures using software abstraction and automation. SD-WAN adoption is increasing, partially due to the rise in remote work during the pandemic, with experts predicting a compound annual growth rate (CAGR) of<a href=\"https:\/\/www.globenewswire.com\/news-release\/2022\/04\/04\/2415730\/0\/en\/SD-WAN-Market-Size-2022-2028-is-Projected-to-Reach-USD-5220-9-Million-with-26-2-CAGR-Growth-Rate-Share-Key-Players-Market-Dynamics-Trends-Challenges-Revenue-and-Forecast-Research-M.html\" target=\"_blank\" rel=\"noopener\"> 26.2%<\/a> between 2022 and 2028. However, while SD-WAN solves a lot of remote, edge, and branch networking problems, it also introduces security concerns that must be addressed. This definitive SD-WAN security checklist highlights the most important challenges and provides solutions for overcoming them.\u00a0<\/p>\n<h2>The definitive SD-WAN security checklist<\/h2>\n<p>Keeping an SD-WAN architecture secure requires several features to be successful. It\u2019s vital to consider this comprehensive list.\u00a0<\/p>\n<h3>1. Frequent security patching<\/h3>\n<p>Outdated operating systems create a significant security risk. According to a<a href=\"https:\/\/www.eweek.com\/security\/software-patches-could-prevent-most-breaches-study-finds\/\" target=\"_blank\" rel=\"noopener\"> 2016 Voke Media survey<\/a>, about 80% of breaches or failed audits could have been prevented by patching outdated software or updating device configurations. An SD-WAN router with an outdated OS is more likely to have vulnerabilities, and the longer it goes unpatched, the more likely a hacker is to find and exploit those vulnerabilities.<\/p>\n<p>However, SD-WAN architectures are often multi-vendor and highly distributed, making it challenging for administrators to monitor for vulnerabilities and stay on top of patch schedules. There are two primary ways to overcome this difficulty:<\/p>\n<ul>\n<li aria-level=\"1\"><b>Centralized SD-WAN management platforms<\/b> provide a single pane of glass from which to monitor and update device software. The right platform is vendor-agnostic, so administrators can easily patch any and all vendor devices from one common interface.<\/li>\n<li aria-level=\"1\"><b>Automated patch management software<\/b> helps keep OSes up to date by automatically applying new updates based on a predetermined schedule. Some solutions even perform automatic vulnerability scans or can monitor environments for missing patches and apply new updates that fall outside of the usual patch schedule.<\/li>\n<\/ul>\n<p>Your ability to keep SD-WAN device software secure ultimately depends on the vendor\u2019s patch schedule. Some providers are sluggish to patch known vulnerabilities in their software, either because they think they can keep said vulnerabilities a secret or because they don\u2019t want to dedicate the time and resources needed to keep the OS up to date. That\u2019s why you should look for SD-WAN hardware and software vendors who are transparent about vulnerabilities and who work diligently to release frequent patches and updates.\u00a0<\/p>\n<h3>2. Zero Trust Provisioning<\/h3>\n<p>SD-WAN platforms are software-based, but they still require underlying networking hardware at each remote site for connecting to the enterprise network. Deploying this hardware can be difficult, especially when SD-WAN sites are in hard-to-reach locations such as offshore oil rigs, remote weather stations, or nations experiencing disasters or active conflicts. Often, organizations opt to pre-stage devices in their home office and then ship them to remote sites so they can avoid costly or dangerous travel.<\/p>\n<p>Pre-staging creates a security risk because a pre-configured device could be intercepted by hackers and used to access the enterprise network.<a href=\"https:\/\/zpesystems.com\/what-is-zero-touch-provisioning\/\"> Zero Touch Provisioning (ZTP)<\/a> reduces the need for pre-staging by deploying new device configurations over the network. ZTP-enabled devices provision themselves by using DHCP or TFTP to find and download configuration files, which means administrators can ship factory-default hardware that doesn\u2019t contain any exploitable information about the enterprise network.<\/p>\n<p>However, ZTP also introduces some additional security challenges. Once they\u2019ve created the configuration file, administrators generally don\u2019t monitor the entire automatic provisioning process, so there\u2019s a chance that a mistake in the configuration file could create a security vulnerability that goes unnoticed. And, since one ZTP configuration file is usually applied to multiple devices, a potential security vulnerability could affect several systems or locations without anyone knowing. In addition, hackers could intercept the transmission of the configuration file over the network if the connection isn\u2019t strongly encrypted.<\/p>\n<p>These challenges are overcome with a secure ZTP solution that follows<a href=\"https:\/\/zpesystems.com\/zero-trust-security-principles-zs\/\"> zero trust security principles<\/a>. This type of solution is often referred to as \u201cZero Trust Provisioning,\u201d and it includes hardware-based security like TPM, BIOS protection, encryption modules, and an onboard firewall which protects the software layer (secure boot) and management layer (two-factor authentication). In addition, the ideal Zero Trust Provisioning solution supports integrations with automated configuration management tools like Chef and Ansible which can be set up to test and monitor ZTP configurations for mistakes and security vulnerabilities.<\/p>\n<p>Zero Trust Provisioning is a key part of the SD-WAN security checklist because it prevents branch networking hardware from being intercepted and used in a cyberattack. It also ensures that automatic provisioning occurs over a secure, encrypted network connection, and allows integration with configuration management tools to prevent errors from introducing additional vulnerabilities.\u00a0<\/p>\n<h3>3. Secure out-of-band access<\/h3>\n<p>Many organizations use out-of-band (OOB) management to configure, control, and troubleshoot remote network infrastructure. OOB management uses a separate management plane, so resource-intensive network management and orchestration workflows don\u2019t affect the performance or reliability of the production network. This may involve using a jump box to access an<a href=\"https:\/\/zpesystems.com\/defining-oob-network-and-oob-management\/\"> OOB network<\/a>, which is an entirely separate management network architecture that runs parallel to the production network. However, a simpler solution is to use an<a href=\"https:\/\/zpesystems.com\/oob-console-server-zs\/\"> OOB console server<\/a> to achieve the same goal without the hassle of deploying a separate architecture.<\/p>\n<p>OOB management improves the performance and reliability of production networks, and provides an alternative path to remote infrastructure (typically via cellular modem) in the event of an ISP outage or a network device failure. The issue with OOB management is that jump boxes and console servers are attractive targets to hackers. If a malicious actor manages to compromise the OOB network, they\u2019ll gain complete control over the remote infrastructure.<\/p>\n<p>To keep SD-WAN devices and other remote infrastructure secure, it\u2019s best to use an OOB console server with advanced encryption for both the hardware and the management connections. In addition, the OOB solution should include Zero Trust features like MFA (multi-factor authentication) and RBAC (role-based access control). Just like the SD-WAN hardware, the OOB device(s) should run a fully patched OS and support Zero Trust Provisioning. For even greater protection, choose an OOB solution that supports integrations with third-party security solutions like next-generation firewalls (NGFW).<\/p>\n<p>A secure out-of-band management solution gives network administrators 24\/7 access to remote infrastructure on a dedicated, encrypted network connection using hardened OOB console server devices. This ensures that hackers can\u2019t use the OOB network to hijack production infrastructure while also giving administrators the ability to quickly recover from outages, hardware failures, and cyberattacks.<\/p>\n<h3>4. Cloud-based security technology<\/h3>\n<p>As we\u2019ve discussed above, it\u2019s possible to run SD-WAN solutions on hardware with onboard firewall features. However, these basic firewalls often lack the advanced functionality needed to protect enterprise networks from sophisticated cyberattacks, which is why most organizations also use some form of stateful firewall or NGFW that resides in a central data center. This works well for a single, centralized enterprise network, but the addition of remote sites can create performance issues.<img decoding=\"async\" class=\"wp-image-16256 size-medium alignright\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2020\/11\/SASEText-198x300.png\" alt=\"\" width=\"198\" height=\"300\" \/><\/p>\n<p>For the centralized firewall to inspect and protect SD-WAN traffic, that traffic must be backhauled through the central data center, even if the request is ultimately destined for the web. This inefficient routing causes bottlenecks, performance issues, and even dropped connections for on-premises and remote users alike. The obvious solution to this problem would be installing physical or virtual firewalls in each remote location, but this is expensive and disruptive and creates more management complexity for network administrators.<\/p>\n<p>A better way to protect remote traffic while improving performance is through the use of cloud-based security solutions, such as<a href=\"https:\/\/zpesystems.com\/what-is-security-service-edge-sse-everything-you-need-to-know-zp\/\"> Security Service Edge (SSE)<\/a>. SSE relies on SD-WAN\u2019s intelligent routing capabilities to separate remote traffic that\u2019s destined for web, cloud, and SaaS resources. This traffic bypasses the firewall and is instead routed through a cloud-based security stack, reducing the load on the enterprise network.<\/p>\n<p>Ideally, the SD-WAN solution will tightly integrate with the SSE platform. This combination of SSE security with an SD-WAN on-ramp creates what\u2019s known as<a href=\"https:\/\/zpesystems.com\/sase-components-zs\/\"> SASE, or Secure Access Service Edge<\/a>. This is most easily achieved using vendor-neutral branch networking platforms which can host or integrate with a wide variety of SD-WAN and SSE solutions. An integrated SASE architecture ensures comprehensive security while providing remote users and systems with fast, reliable access to cloud resources.<\/p>\n<h2>Nodegrid checks every box on your SD-WAN security checklist<\/h2>\n<p>Only one remote network management solution provides everything you need to keep your SD-WAN architecture secure: the Nodegrid platform from ZPE Systems. Nodegrid\u2019s vendor-neutral routers, such as the<a href=\"https:\/\/zpesystems.com\/products\/branch-solutions\/branch-gateway-zs\/\"> 5-in-1 Hive SR branch gateway<\/a>, can directly host or integrate with your chosen SD-WAN solution. Whether you enable SD-WAN with a Nodegrid device or by using ZPE Cloud\u2019s SD-WAN application, you\u2019ll get seamless access, centralized management, and state-of-the-art security.<\/p>\n<h3>1. Secure, up-to-date SD-WAN device OS<\/h3>\n<p>Nodegrid\u2019s<a href=\"https:\/\/zpesystems.com\/products\/branch-solutions\/\"> branch gateway routers<\/a> run on the vendor-neutral, x86 Linux-based Nodegrid OS, which is constantly monitored for vulnerabilities and frequently patched to ensure security. Plus, with the ZPE Cloud orchestration platform, you can monitor and update all your SD-WAN devices from one convenient management portal\u2014even if that hardware comes from another vendor.<\/p>\n<h3>2. Zero Trust Provisioning for branch networks<\/h3>\n<p>All Nodegrid devices support Zero Trust Provisioning, and they can extend this capability to any third-party devices managed by Nodegrid. That means administrators can securely configure all the multi-vendor devices in a remote branch network without the need for travel or pre-staging. Nodegrid ZTP is considered Zero Trust because it protects the hardware, software, and management layers with advanced security features like:<\/p>\n<ul>\n<li aria-level=\"1\">Password-protected BIOS<\/li>\n<li aria-level=\"1\">Current cryptographic modules<\/li>\n<li aria-level=\"1\">SSO with SAML (Duo, Okta, Ping, and ADFS), MFA, and remote authentication<\/li>\n<li aria-level=\"1\">Geofence perimeter crossing detection<\/li>\n<li aria-level=\"1\">Onboard firewall, IPSec, and Fail2Ban intrusion protection<\/li>\n<li aria-level=\"1\">Fine grain RBAC with strong password enforcement<\/li>\n<\/ul>\n<p>Nodegrid also supports integrations with automated configuration management solutions like Ansible, Chef, and Puppet, so you can ensure every device is provisioned correctly.<\/p>\n<h3>3. Gen 3 secure out-of-band management<\/h3>\n<p>Nodegrid services routers provide reliable,<a href=\"https:\/\/zpesystems.com\/solutions\/remote-network-management\/out-of-band-serial-console-zs\/\"> Gen 3 OOB management<\/a> access to any connected devices, including those from other vendors. This access is protected by a patched OS, onboard hardware security features, and current encryption modules. Plus, Nodegrid\u2019s hardware and software can host or integrate with third-party security solutions like NGFWs for comprehensive OOB security.\u00a0<\/p>\n<h3>4. An SD-WAN onramp to SSE<\/h3>\n<p>The Nodegrid branch networking solution provides the ideal SD-WAN on-ramp to leading Security Service Edge providers. That\u2019s because Nodegrid is a completely open platform that can host or integrate with any SSE and SD-WAN offering to provide a single, <a href=\"https:\/\/zpesystems.com\/solutions\/sase-zs\/\">unified SASE solution<\/a>. This gives administrators complete control over every aspect of branch network management and SD-WAN security from one convenient portal, reducing complexity and improving your security posture at the same time.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.18.0&#8243; _module_preset=&#8221;default&#8221; text_text_color=&#8221;#FFFFFF&#8221; background_color=&#8221;#358AAF&#8221; custom_margin=&#8221;||||true|false&#8221; custom_padding=&#8221;30px|30px|30px|30px|true|true&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2>Wondering how ZPE\u2019s Nodegrid solution checks all the boxes on your SD-WAN security checklist?<\/h2>\n<p>Contact ZPE Systems today to learn more<\/p>\n<p><a class=\"HSSTYLEDCTA\" href=\"https:\/\/zpesystems.com\/contact\/\">Learn More<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Software-defined wide area networking, or SD-WAN, has made it possible to efficiently control highly distributed WAN architectures using software abstraction and automation. SD-WAN adoption is increasing, partially due to the rise in remote work during the pandemic, with experts predicting a compound annual growth rate (CAGR) of 26.2% between 2022 and 2028. However, while SD-WAN [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":29595,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[86,96,35,158,80,1,134],"tags":[],"class_list":["post-29592","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modernize-legacy-environments","category-sd-wan","category-sase","category-security-service-edge-sse","category-simplify-branch-infrastructure","category-uncategorized","category-zero-trust-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Definitive SD-WAN Security Checklist | ZPE Systems<\/title>\n<meta name=\"description\" content=\"This SD-WAN security checklist highlights the most important challenges in securing SD-WAN architectures and provides advice for overcoming these hurdles.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Definitive SD-WAN Security Checklist for Enterprise Networks\" \/>\n<meta property=\"og:description\" content=\"This SD-WAN security checklist highlights the most important challenges in securing SD-WAN architectures and provides advice for overcoming these hurdles.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2022-10-04T00:37:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-11-04T22:22:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1836\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Baker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Baker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/\",\"url\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/\",\"name\":\"The Definitive SD-WAN Security Checklist | ZPE Systems\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg\",\"datePublished\":\"2022-10-04T00:37:46+00:00\",\"dateModified\":\"2022-11-04T22:22:18+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\"},\"description\":\"This SD-WAN security checklist highlights the most important challenges in securing SD-WAN architectures and provides advice for overcoming these hurdles.\",\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg\",\"width\":1506,\"height\":1080,\"caption\":\"An SD-WAN security checklist with green checkmarks indicating successful implementation.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Streamline Deployments\",\"item\":\"https:\/\/zpesystems.com\/category\/streamline-deployments\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Modernize Legacy Environments\",\"item\":\"https:\/\/zpesystems.com\/category\/streamline-deployments\/modernize-legacy-environments\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"The Definitive SD-WAN Security Checklist for Enterprise Networks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\",\"name\":\"Jordan Baker\",\"url\":\"https:\/\/zpesystems.com\/author\/jordan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Definitive SD-WAN Security Checklist | ZPE Systems","description":"This SD-WAN security checklist highlights the most important challenges in securing SD-WAN architectures and provides advice for overcoming these hurdles.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/","og_locale":"en_US","og_type":"article","og_title":"The Definitive SD-WAN Security Checklist for Enterprise Networks","og_description":"This SD-WAN security checklist highlights the most important challenges in securing SD-WAN architectures and provides advice for overcoming these hurdles.","og_url":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/","og_site_name":"ZPE Systems","article_published_time":"2022-10-04T00:37:46+00:00","article_modified_time":"2022-11-04T22:22:18+00:00","og_image":[{"width":2560,"height":1836,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg","type":"image\/jpeg"}],"author":"Jordan Baker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jordan Baker","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/","url":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/","name":"The Definitive SD-WAN Security Checklist | ZPE Systems","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg","datePublished":"2022-10-04T00:37:46+00:00","dateModified":"2022-11-04T22:22:18+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567"},"description":"This SD-WAN security checklist highlights the most important challenges in securing SD-WAN architectures and provides advice for overcoming these hurdles.","breadcrumb":{"@id":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg","width":1506,"height":1080,"caption":"An SD-WAN security checklist with green checkmarks indicating successful implementation."},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/the-definitive-sd-wan-security-checklist-for-enterprise-networks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"Streamline Deployments","item":"https:\/\/zpesystems.com\/category\/streamline-deployments\/"},{"@type":"ListItem","position":3,"name":"Modernize Legacy Environments","item":"https:\/\/zpesystems.com\/category\/streamline-deployments\/modernize-legacy-environments\/"},{"@type":"ListItem","position":4,"name":"The Definitive SD-WAN Security Checklist for Enterprise Networks"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567","name":"Jordan Baker","url":"https:\/\/zpesystems.com\/author\/jordan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg",1506,1080,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg",1506,1080,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1.jpg",1506,1080,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-150x150.jpg",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-300x215.jpg",300,215,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-1024x734.jpg",1024,734,true],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-1536x1102.jpg",1536,1102,true],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-2048x1469.jpg",2048,1469,true],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-1080x675.jpg",1080,675,true],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-1080x775.jpg",1080,775,true],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-2560x1800.jpg",2560,1800,true],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-1280x918.jpg",1004,720,true],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-980x703.jpg",768,551,true],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/10\/sd-wan-security-checklist-scaled-1-480x344.jpg",377,270,true]},"rttpg_author":{"display_name":"Jordan Baker","author_link":"https:\/\/zpesystems.com\/author\/jordan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/streamline-deployments\/modernize-legacy-environments\/\" rel=\"category tag\">Modernize Legacy Environments<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/sd-wan\/\" rel=\"category tag\">SD-WAN<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/sase\/\" rel=\"category tag\">Secure Access Service Edge (SASE)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/security-service-edge-sse\/\" rel=\"category tag\">Security Service Edge (SSE)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/simplify-branch-infrastructure\/\" rel=\"category tag\">Simplify Branch Infrastructure<\/a> <a href=\"https:\/\/zpesystems.com\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a> <a href=\"https:\/\/zpesystems.com\/category\/zero-trust-security\/\" rel=\"category tag\">Zero Trust Security<\/a>","rttpg_excerpt":"Software-defined wide area networking, or SD-WAN, has made it possible to efficiently control highly distributed WAN architectures using software abstraction and automation. SD-WAN adoption is increasing, partially due to the rise in remote work during the pandemic, with experts predicting a compound annual growth rate (CAGR) of 26.2% between 2022 and 2028. However, while SD-WAN&hellip;","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/29592","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=29592"}],"version-history":[{"count":3,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/29592\/revisions"}],"predecessor-version":[{"id":32115,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/29592\/revisions\/32115"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/29595"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=29592"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=29592"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=29592"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}