Why the future of network security is the convergence of SASE and firewalls

News Analysis
Jul 29, 20267 mins

As compute moves closer to the user and the edge becomes the epicenter of business innovation, physical and cloud security must converge.

Security Decision 16z9
Credit: Gorodenkoff | shutterstock.com

In technology, the pendulum rarely stays at one extreme for long. When Secure Access Service Edge (SASE) entered the enterprise networking lexicon a few years ago, the industry quickly pivoted to it. The prevailing consensus held that traditional on-premises security hardware was headed for extinction. Industry watchers envisioned a world where even corporate headquarters and massive branch offices would shed their physical appliances, plugging directly into cloud-delivered SASE POPs. It was a clean, compelling story: Offload processing to the cloud, eliminate local box management, and let security follow the user wherever they go.

Except, like many tech hype cycles, reality intervened. This is a movie we’ve all seen before. The cloud was supposed to eradicate on-premises workloads, but that didn’t happen. Voice was declared dead at one point, but it’s alive and kicking. And software was going to eat the world, and all that would remain is commodity hardware.

We are now seeing the SASE pendulum swing in a different direction. As enterprises aggressively roll out edge computing architectures, IoT deployments, and, in particular, real-time and agentic AI applications, the physical edge isn’t disappearing—it’s becoming dramatically more complex. Today, we are seeing a clear course correction in network security strategy. The debate is no longer about choosing between a SASE-first cloud architecture and an on-premises firewall model. Instead, we are entering an era driven by the unavoidable convergence of firewalls and SASE into a single, cohesive framework.

The AI and edge reality check

Why is the cloud-only SASE model showing its limitations at the physical site? The answer largely boils down to the physics and economics of data traffic, especially in the age of edge computing and AI.

As executive voices across the tech industry, most notably Nvidia’s Jensen Huang, have repeatedly emphasized, we are moving into the era of inference. The massive models trained in data centers are now being deployed at the edge to drive real-time decisions, whether that’s computer vision on a manufacturing floor, localized customer analytics in retail, or autonomous agents interacting across a branch network.

When you move compute to the edge, you inevitably increase east-west traffic. That is the data moving laterally among local devices, local servers, and on-site AI agents. If a company relies entirely on a cloud-delivered SASE model to secure these locations, every piece of east-west traffic generated at the local branch must be hairpinned back up to a cloud security POP for inspection, only to be routed back down to the local network.

This approach creates two immediate friction points:

  • Unacceptable latency: Real-time AI processing cannot tolerate the latency introduced by routing local traffic to and from the cloud.
  • Prohibitive bandwidth costs: Paying cloud egress fees and consuming massive WAN bandwidth to inspect internal traffic at a single physical location is economically unsustainable.

Logically, security must reside where the compute resides. If high-performance compute is at the edge, high performance, low-latency security enforcement must be physically present right beside it.

Moving beyond “either-or” architecture

The rise of SASE and much of the early marketing around it created a false dichotomy: You were either a “firewall shop” tied to legacy hardware or a modern “SASE shop” moving everything to the cloud. The market reality is that enterprises need both working together.

On-site security enforcement (which, pragmatically speaking, still resembles a physical or virtual firewall box) is required to inspect heavy east-west traffic, enforce local segmentation, and maintain low latency for edge compute. Meanwhile, cloud SASE remains the gold standard for securing remote workers, protecting access to SaaS applications, and delivering scalable, distributed threat protection. The challenge enterprise IT leaders face today isn’t choosing one over the other; it’s integrating them so they don’t operate as isolated silos.

The value of a common fabric

Deploying standalone firewalls at physical sites while using a separate cloud SASE vendor creates massive operational overhead. IT teams end up managing duplicate security policies, fragmented context, and telemetry across disparate consoles. This operational friction is driving the market toward converged platforms.

To make a hybrid firewall-SASE model work effectively, the underlying OS and management layer must be shared across both environments. When a local branch firewall and a cloud-delivered SASE POP run on the same operating engine—a model long championed by vendors like Fortinet with its unified single-OS approach (FortiOS)—the benefits become immediately apparent:

  • Unified context and telemetry: Security policies defined in the cloud seamlessly extend to on-premises hardware, and vice versa.
  • Dynamic threat sharing: A threat detected at a physical branch firewall immediately updates the cloud SASE engine’s threat intelligence, protecting mobile users instantly.
  • Simplified operations: NetOps and SecOps teams manage one continuous fabric rather than stitching together APIs across disparate point solutions.

When physical appliances and cloud engines share a single codebase, the distinction between “firewall” and “SASE” ceases to be a debate about infrastructure and becomes a fluid deployment choice.

Nader Lghachi, chief digital officer of French building materials company SMAC, discussed this topic: “The integration of Fortinet’s SASE with our existing SD-WAN was surprisingly simple. In just a few minutes, by deploying the FortiSASE agent software, we gained a wide range of SSE capabilities, including firewall-as-a-service, secure web gateway, ZTNA, CASB, DLP, remote browser isolation and more.” He said of the benefits for SMAC workers: “Our users now have exactly the same access experience whether they are in the office, at home or on the road.”

What this means for enterprise infrastructure teams

As we look toward the next cycle of network refreshes, IT leaders should evaluate their architecture through the lens of convergence rather than replacement.

  1. Audit your edge compute trajectory: If your organization plans to deploy localized AI, IoT, or edge analytics, evaluate how much east-west traffic they will generate. Relying solely on cloud hairpins will quickly become a performance bottleneck.
  2. Prioritize single-OS vendors: When evaluating SASE and next-gen firewall (NGFW) platforms, look beyond feature checklists. Ask vendors how natively their physical appliances and cloud SASE POPs communicate. Do they share a single codebase, or are they a stitched-together portfolio of acquired tools?
  3. Design for flexibility: Your branch’s needs today will change as edge computing evolves. A converged platform lets you scale cloud security or local hardware enforcement as application demands dictate, without redesigning your security architecture from scratch.

Final thoughts

The narrative that cloud security would render physical network security hardware obsolete was a classic case of technological oversimplification. SASE is a vital, transformative architecture, but it was never meant to operate in a vacuum.

As compute moves closer to the user and the edge becomes the epicenter of business innovation, physical and cloud security must converge. Vendors and IT organizations that recognize this convergence, treating firewalls and SASE as two sides of the same operational coin, will be best positioned to run fast, secure networks in the AI era.

Zeus Kerravala

Zeus Kerravala is the founder and principal analyst with ZK Research, and provides a mix of tactical advice to help his clients in the current business climate and long-term strategic advice. Kerravala provides research and advice to end-user IT and network managers, vendors of IT hardware, software and services and the financial community looking to invest in the companies that he covers.

Prior to ZK Research, Kerravala spent 10 years as an analyst at Yankee Group. Earlier in his career, he held a number of technical roles, including as VP of IT and Deputy CIO.

Kerravala holds a Bachelor of Science in Physics and Mathematics from the University of Victoria in British Columbia, Canada.

He currently resides in Acton, Massachusetts.

More from this author