Home/Network Security & SASE

The perimeter didn’t disappear. It moved to wherever your people and workloads happen to be — and most organisations are now paying for both.

An unamortised firewall estate running alongside a SASE subscription, with overlapping capability nobody has reconciled. No vendor will write that sentence down, because every vendor is selling one side of it.

These four routes differ by one architectural fact: where enforcement happens — at your edge, in a provider’s cloud, at the application, or at DNS resolution. That is what you are actually choosing between.

Firewall & Network Security

You have sites, data centres and traffic to inspect at your own edge.

Enforcement at your edge
12 productsOpen the guide →
Often confused with SASE & SSE. The difference: one inspects traffic that comes to you; the other inspects traffic that never touches your network. SASE & SSE

SASE & SSE

Your people and apps left the building. Enforcement has to follow them.

Enforcement in a provider's cloud
16 productsOpen the guide →
Often confused with Firewall & Network Security. The difference: SASE includes the network (SD-WAN); SSE is the security half only — and most buyers who say SASE mean SSE. Firewall & Network Security

Zero Trust Access

The VPN is the problem. Users need apps, not the network.

Enforcement at the application
13 productsOpen the guide →
Often confused with SASE & SSE. The difference: a VPN puts a user on the network; ZTNA puts them on an application, and never the network. SASE & SSE

Secure Web & DNS

Stop bad destinations before anything reaches the endpoint.

Enforcement at DNS resolution
11 productsOpen the guide →
Often confused with SASE & SSE. The difference: DNS filtering is one control; SASE is a platform that includes it. SASE & SSE
Second entry axis

Something just happened?

Refresh quotes and incidents send people here more often than architecture diagrams do. If one of these is your week, it already names your route.

The firewall refresh quote arrived and it doubled

Firewall & Network Security

TLS inspection was switched on and throughput collapsed

Firewall & Network Security

Half the workforce never comes to the office any more

SASE & SSE

A regulator asked where inspected traffic and logs are stored

SASE & SSE

A VPN account was compromised and the attacker moved sideways

Zero Trust Access

Contractors need internal apps and cannot take an agent

Zero Trust Access

Something cheap needs to cover every site by next week

Secure Web & DNS

Users are on personal cloud tenants and nobody can tell

Secure Web & DNS

The overlaps

Why people pick the wrong door

Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:

FirewallvsSASE

Does the traffic come to you, or does it never touch your network?

Buy appliances for an estate whose people and applications have all left and you inspect the shrinking fraction of traffic that still comes home. Buy SASE for an estate with heavy site-to-site traffic and regulated inspection and you have paid a subscription for enforcement that still has to happen at your edge — usually while the appliances are still on the books.

SASEvsSSE

Is your WAN actually a problem?

Buy SASE when SSE was the requirement and you have paid for SD-WAN to replace a network that worked. Buy SSE when the WAN genuinely needed replacing and you run two vendors, two policy models and two support contracts across the same branches.

ZTNAvsVPN

Do users need an application, or the network?

Keep the VPN and every authenticated device can reach everything routable — which is what lateral movement is. Buy ZTNA without checking protocol reach and the VPN stays up for the one application that will not traverse it, so you now pay for both and the exposure is unchanged.

Secure Web & DNSvsSASE

Is this one control, or a platform?

Buy DNS filtering when the requirement was content inspection and you block domains while files move freely through allowed ones. Buy the platform when a resolver change would have done and you pay per user for a floor that costs a fraction of it — DNS filtering is already the base module of every SASE platform you are quoted.

Compare any two terms

vs
NGFWFirewall & Network Security

Identifies the application, not just the port — and inspects at your edge.

The Firewall & Network Security boundary section →
SASESASE & SSE

The security half plus the network half (SD-WAN), delivered from a provider's cloud.

The SASE & SSE boundary section →

The difference

The same controls at different enforcement locations. An NGFW inspects traffic that comes to your edge; SASE inspects traffic that never touches your network. Not a maturity ladder: the failure modes differ (appliance capacity versus PoP distance), the cost shape differs (refresh cycle versus subscription), and most estates end up running both — which is the double-spend this category opens with.

The vocabulary — one line each

Sixteen terms, one line each. The depth lives in each route’s guide.

These are not a maturity ladder. SASE is not “firewall, evolved” — it is a different enforcement location with different failure modes, different cost behaviour and a different renewal trap. Each route’s guide resolves only the terms its buyer confuses.

  • NGFWidentifies the application, not just the port — and inspects at your edge
  • UTMmany functions in one box for an estate that cannot run five — the same engineering, pointed at smaller sites
  • SD-WANsoftware steering traffic across whatever links you have — it replaces the circuit, not the inspection
  • MPLSa carrier circuit with guaranteed behaviour and a long contract — what SD-WAN usually replaces
  • SASEthe security half plus the network half (SD-WAN), delivered from a provider's cloud
  • SSEthe security half alone — what most buyers who say SASE actually need
  • FWaaSfirewall-as-a-service: non-web traffic inspected in the provider's cloud rather than your rack
  • PoPthe point of presence traffic is enforced at — and distance from it is the user experience
  • ZTNAa broker connecting a user to one application, never to the network
  • VPNauthenticates once and puts the device on the network, where everything routable is reachable
  • Agentless ZTNAbrowser-delivered access for unmanaged devices — web apps only, and shallow device posture
  • Device posturewhat can be verified about the machine before access: deep with an agent, minimal in a browser
  • SWGa proxy that terminates, decrypts and inspects web traffic by content rather than destination
  • DNS filteringthe domain never resolves — cheapest control there is, and bypassed by DoH or a personal VPN
  • CASB inlinein the traffic path: can block an upload as it happens, sees only what traverses it
  • CASB APIout of band: finds what is already sitting in the cloud application, blocks nothing in real time
Ground truths

What holds whichever route you take

Almost everyone is paying twice

The refresh cycle and the subscription decision are made by different people at different times. The result is an appliance estate that has not finished depreciating running alongside a per-user cloud subscription, with web filtering, DNS security and application control frequently active in both. Nobody reconciles it because no vendor is incentivised to raise it. Audit the overlap, switch duplicates off deliberately, and put the parallel-run quarters in the business case as a line rather than a surprise.

Capex and opex behave differently, and finance notices

An appliance is capital spend amortised over five years with a subscription attached that usually exceeds it. SASE is operating spend per user per month that grows with headcount and reprices at renewal. Neither is cheaper in the abstract — the honest comparison is five years of both shapes against your own site count, user count and growth, and it is a comparison most estates have never actually run.

In India, the map is the product

Point-of-presence distance decides user experience more than any feature comparison, and it is the thing global reviews never cover. Documented here from vendor sources: Netskope operates eight data centres in India with a NewEdge management plane in Mumbai; Cloudflare’s PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto has documented a Mumbai cloud location since 2021. Several major vendors publish no named Indian city list at all — flagged on every guide, never assumed. Ask for the cities and test the latency from your own offices.

Every throughput number needs a footnote

Firewall datasheets lead with a figure measured with inspection switched off. The only number worth sizing against is the threat-prevention-enabled one, with the engines named — Palo Alto publishes 7.5–20 Gbps across the PA-3400 series and lists all eight engines; Check Point publishes 6.5 Gbps on the Force 9100 rising to 75 Gbps on the 29200; Fortinet publishes 1.6 Gbps threat protection on the 100F. Where a vendor publishes no inspected figure, these guides mark it unknown rather than deriving one.

Enforcement location is the decision. The double-spend is what happens when nobody makes it.
TechBag
Where it's heading

The seams are moving

SD-WAN has been absorbed into SASE — it is rarely a separate purchase now, and at Fortinet it is not even a separate licence. Firewall vendors have become SASE vendors, selling the same policy model enforced in someone else’s cloud, which is what makes a same-vendor migration commercially easy and a same-vendor lock-in deeper. And browser-based enforcement is emerging as a fifth model: the control point moving into the browsing session itself, for contractors and unmanaged devices no agent can reach. Buying two of these today often means buying one thing twice.

What you used to buyWhat you buy now
Firewall & SD-WAN
your edge
SASE & SSE
a provider's cloud
Zero trust access
the application
Secure web & DNS
DNS resolution
One direction
SD-WAN absorbed into SASE
the network half stops being a separate purchase
FortinetPalo AltoVersaCheck Point
One direction
Firewall vendors becoming SASE vendors
the same policy, enforced in someone else's cloud
Palo AltoFortinetCheck PointCisco
One direction
Browser-based enforcement, the fifth model
the control point moves into the browsing session
Palo AltoCloudflareInstaSafe

Buy for the seam that is moving, not last year’s org chart — and buy the enforcement location, not the brand.

Check what you already own

This is the category where duplicate capability is most likely to already be on your invoice — frequently switched off, occasionally paid for twice.

  • Your existing NGFW subscription web filtering, DNS security, application control and sometimes SD-WAN are often already in the bundle you renew each year — unused because nobody switched them on. Audit it before buying the same capability from the cloud.
  • Microsoft Entra ID P1 / P2 conditional access decides whether a sign-in proceeds, and application proxy publishes internal web applications. Real coverage for web apps and identity; no traffic inspection, no desktop applications.
  • Cloudflare's free tier the public resolver is free and Zero Trust is free to 50 users, with genuine per-application access and DNS filtering on six documented Indian cities. A real starting point, not an enterprise platform.
  • Your endpoint vendor's web filtering many endpoint agents filter web traffic on the device and travel with the user. Thinner than a cloud gateway on inspection, CASB and reporting — and it may be enough.
  • Your SASE or SSE subscription secure web gateway is the base module of every platform, and ZTNA is bundled into the base tier at Palo Alto, Fortinet, Check Point, Cisco and Versa. Check before buying access or filtering twice.
  • Your carrier's managed service many Indian carriers deliver SD-WAN and basic security as a managed service, often on Versa or Fortinet. Real capability — ask who holds the policy and how fast a change request moves.

If the capability you need is already inside something you renew, we say so. It costs us a sale and saves you one.

Budget shape

What it costs, roughly

Four meters live in this category, and they are not comparable to one another. Which one you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.

Firewall & Network Security
Appliance + subscription + support
Three lines over five years, and the subscription is usually the largest. Central management is a separate product at Palo Alto, Fortinet and Cisco; included at Check Point, Versa and Sophos.
SASE & SSE
Per user per month
Cloudflare $7 published; Coro $10.50; FortiSASE $8–18 list; Zscaler ZIA ~$6–12 and ZPA ~$6–11 reported separately; Netskope ~$15+ fully bundled. Plus the parallel run.
Zero Trust Access
Per user per month
Cloudflare $7; InstaSafe ~$8 published with a managed service; Check Point Harmony SASE from ~$10; Zscaler ZPA ~$6–11 reported. Often already inside an SSE subscription.
Secure Web & DNS
Per user, DNS or proxy tier
Cisco DNS Essentials ~$30–40 per user / year rising to SIG Advantage ~$95–135; Cloudflare free to 50 users then $7 per user / month. The DNS-to-proxy gap is roughly threefold.
Appendix — every vendor in the category, tagged by route
  • Palo Alto NetworksStrata NGFW (7.5–20 Gbps threat prevention on the PA-3400 series, engines named), Prisma Access, Prisma SASE, Prisma Access Browser, CDSS subscriptions; documented Mumbai cloud location since 2021FirewallSASEZTNAWeb
  • FortinetFortiGate (1.6 Gbps threat protection on the 100F), Secure SD-WAN in the same licence, FortiSASE ($8–18 per user / month list with Fabric pricing for FortiGate customers), FortiWebFirewallSASEZTNAWeb
  • Check PointQuantum Force (6.5 Gbps threat prevention on the 9100 to 75 Gbps on the 29200), Maestro scale-out, Quantum SD-WAN, Harmony SASE (the former Perimeter 81, from ~$10 per user / month)FirewallSASEZTNA
  • ZscalerThe reference proxy: ZIA (~$6–12 per user / month reported), ZPA (~$6–11, a separate subscription), ZDX for digital experience, Zero Trust Exchange as the platform bundleSASEZTNAWeb
  • NetskopeSSE platform with CASB and DLP in its DNA, Next Gen SWG with application-instance awareness, Private Access documenting SSH, RDP and server-initiated traffic; eight India data centres and a Mumbai management planeSASEZTNAWeb
  • CiscoSecure Firewall, Umbrella (DNS tiers from ~$2.25 per user / month up to SIG), Secure Access as the platform successor, Duo for device trustFirewallSASEZTNAWeb
  • CloudflareCloudflare One / Zero Trust (free to 50 users, then $7 per user / month), Gateway, Access, DNS; Indian PoPs in Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and NagpurSASEZTNAWeb
  • Versa NetworksSoftware-first from branch to cloud: NGFW, Secure SD-WAN, SASE and SSE on one stack, frequently delivered in India through carrier-managed servicesFirewallSASEZTNA
  • SophosFirewall (XGS) with endpoint security heartbeat, ZTNA, Network Access as the honest fallback, NDR for east-west visibilityFirewallZTNAWeb
  • BarracudaNetwork Protection / SecureEdge — firewall per site and access per user on one platform for distributed mid-market estatesFirewallSASEWeb
  • InstaSafeIndia-built and India-hosted zero trust access (~$8 per user / month published, with a managed service), ZTAA for agentless contractor access; available on GeMZTNA
  • SeqriteIndia-built ZTNA from Quick Heal with local data handling, commonly bought alongside Seqrite endpoint protectionZTNA
  • Trend MicroNetwork Security and Zero Trust Secure Access inside Vision One, with access decisions informed by endpoint and email risk; billed in creditsSASEZTNA
  • CoroModular mid-market platform — Network & SASE published at $10.50 per user / month, modules from $4SASE

Nine vendors span three or four routes; every product on the guides is mapped by SKU, not by vendor. Cloud workload protection (CNAPP, CSPM) is a route under Security and is deliberately not duplicated here. Cato Networks, Aryaka and Skyhigh Security are named in the guides where relevant but have no TechBag intel pages yet, so they are not ranked.

Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.

Talk to an advisor

Vendor-neutral · no gated content