Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
An unamortised firewall estate running alongside a SASE subscription, with overlapping capability nobody has reconciled. No vendor will write that sentence down, because every vendor is selling one side of it.
These four routes differ by one architectural fact: where enforcement happens — at your edge, in a provider’s cloud, at the application, or at DNS resolution. That is what you are actually choosing between.
You have sites, data centres and traffic to inspect at your own edge.
Your people and apps left the building. Enforcement has to follow them.
The VPN is the problem. Users need apps, not the network.
Stop bad destinations before anything reaches the endpoint.
Refresh quotes and incidents send people here more often than architecture diagrams do. If one of these is your week, it already names your route.
The firewall refresh quote arrived and it doubled
Firewall & Network Security
TLS inspection was switched on and throughput collapsed
Firewall & Network Security
Half the workforce never comes to the office any more
SASE & SSE
A regulator asked where inspected traffic and logs are stored
SASE & SSE
A VPN account was compromised and the attacker moved sideways
Zero Trust Access
Contractors need internal apps and cannot take an agent
Zero Trust Access
Something cheap needs to cover every site by next week
Secure Web & DNS
Users are on personal cloud tenants and nobody can tell
Secure Web & DNS
Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:
Does the traffic come to you, or does it never touch your network?
Buy appliances for an estate whose people and applications have all left and you inspect the shrinking fraction of traffic that still comes home. Buy SASE for an estate with heavy site-to-site traffic and regulated inspection and you have paid a subscription for enforcement that still has to happen at your edge — usually while the appliances are still on the books.
Is your WAN actually a problem?
Buy SASE when SSE was the requirement and you have paid for SD-WAN to replace a network that worked. Buy SSE when the WAN genuinely needed replacing and you run two vendors, two policy models and two support contracts across the same branches.
Do users need an application, or the network?
Keep the VPN and every authenticated device can reach everything routable — which is what lateral movement is. Buy ZTNA without checking protocol reach and the VPN stays up for the one application that will not traverse it, so you now pay for both and the exposure is unchanged.
Is this one control, or a platform?
Buy DNS filtering when the requirement was content inspection and you block domains while files move freely through allowed ones. Buy the platform when a resolver change would have done and you pay per user for a floor that costs a fraction of it — DNS filtering is already the base module of every SASE platform you are quoted.
Compare any two terms
Identifies the application, not just the port — and inspects at your edge.
The Firewall & Network Security boundary section →The security half plus the network half (SD-WAN), delivered from a provider's cloud.
The SASE & SSE boundary section →The difference
The same controls at different enforcement locations. An NGFW inspects traffic that comes to your edge; SASE inspects traffic that never touches your network. Not a maturity ladder: the failure modes differ (appliance capacity versus PoP distance), the cost shape differs (refresh cycle versus subscription), and most estates end up running both — which is the double-spend this category opens with.
These are not a maturity ladder. SASE is not “firewall, evolved” — it is a different enforcement location with different failure modes, different cost behaviour and a different renewal trap. Each route’s guide resolves only the terms its buyer confuses.
The refresh cycle and the subscription decision are made by different people at different times. The result is an appliance estate that has not finished depreciating running alongside a per-user cloud subscription, with web filtering, DNS security and application control frequently active in both. Nobody reconciles it because no vendor is incentivised to raise it. Audit the overlap, switch duplicates off deliberately, and put the parallel-run quarters in the business case as a line rather than a surprise.
An appliance is capital spend amortised over five years with a subscription attached that usually exceeds it. SASE is operating spend per user per month that grows with headcount and reprices at renewal. Neither is cheaper in the abstract — the honest comparison is five years of both shapes against your own site count, user count and growth, and it is a comparison most estates have never actually run.
Point-of-presence distance decides user experience more than any feature comparison, and it is the thing global reviews never cover. Documented here from vendor sources: Netskope operates eight data centres in India with a NewEdge management plane in Mumbai; Cloudflare’s PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto has documented a Mumbai cloud location since 2021. Several major vendors publish no named Indian city list at all — flagged on every guide, never assumed. Ask for the cities and test the latency from your own offices.
Firewall datasheets lead with a figure measured with inspection switched off. The only number worth sizing against is the threat-prevention-enabled one, with the engines named — Palo Alto publishes 7.5–20 Gbps across the PA-3400 series and lists all eight engines; Check Point publishes 6.5 Gbps on the Force 9100 rising to 75 Gbps on the 29200; Fortinet publishes 1.6 Gbps threat protection on the 100F. Where a vendor publishes no inspected figure, these guides mark it unknown rather than deriving one.
Enforcement location is the decision. The double-spend is what happens when nobody makes it.
SD-WAN has been absorbed into SASE — it is rarely a separate purchase now, and at Fortinet it is not even a separate licence. Firewall vendors have become SASE vendors, selling the same policy model enforced in someone else’s cloud, which is what makes a same-vendor migration commercially easy and a same-vendor lock-in deeper. And browser-based enforcement is emerging as a fifth model: the control point moving into the browsing session itself, for contractors and unmanaged devices no agent can reach. Buying two of these today often means buying one thing twice.
Buy for the seam that is moving, not last year’s org chart — and buy the enforcement location, not the brand.
This is the category where duplicate capability is most likely to already be on your invoice — frequently switched off, occasionally paid for twice.
If the capability you need is already inside something you renew, we say so. It costs us a sale and saves you one.
Four meters live in this category, and they are not comparable to one another. Which one you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.
Nine vendors span three or four routes; every product on the guides is mapped by SKU, not by vendor. Cloud workload protection (CNAPP, CSPM) is a route under Security and is deliberately not duplicated here. Cato Networks, Aryaka and Skyhigh Security are named in the guides where relevant but have no TechBag intel pages yet, so they are not ranked.
Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.
Talk to an advisorVendor-neutral · no gated content