Home     Fortinet       SASE Architecture Explained: When Is It Time to Modernise Your Network?

SASE Architecture Explained: When Is It Time to Modernise Your Network?

SASE architecture, or Secure Access Service Edge, combines networking and cloud delivered security into a single platform so that users get secure access to applications from anywhere, managed through one policy framework. It replaces the older model of a central office firewall with a VPN bolted on.

That older model still runs most Australian networks, and it was designed for a different set of assumptions. Staff now work across offices, homes and customer sites, and the applications they use all day sit in Microsoft 365 and Azure rather than in a server room. At A1 Technologies we design and manage Fortinet SASE solutions for organisations across Australia and New Zealand that need to simplify networking and security while supporting hybrid work and growth.

What is SASE architecture?

Fortinet’s technical documentation describes SASE as achieving secure network access by combining firewall as a service, secure web gateway, zero trust network access and cloud access security broker capabilities with wide area network technologies such as SD-WAN.

In practice, a SASE platform brings together five core services:

  • Software Defined Wide Area Networking (SD-WAN): application aware routing across broadband, fibre and mobile links so critical traffic takes the best available path.
  • Secure Web Gateway (SWG): inspection and filtering of user web traffic, including DNS filtering.
  • Zero Trust Network Access (ZTNA): per session access to individual applications based on verified identity and device posture, rather than broad network access.
  • Cloud Access Security Broker (CASB): visibility and control over how staff use SaaS applications, sanctioned and unsanctioned.
  • Firewall as a Service (FWaaS): next generation firewall inspection delivered as a service, including intrusion prevention.

Mature platforms add data loss prevention, SaaS security posture management and digital experience monitoring on top of those five.

Why traditional network security is no longer enough

Most of the environments we assess were not badly designed. They were built correctly for the problem in front of them, then extended year after year as requirements arrived. A VPN concentrator for remote access. A cloud web filter when staff started working from home. A separate SaaS security tool as Microsoft 365 adoption accelerated. A second firewall vendor after an acquisition.

Each product solves its own problem. Together they create three issues we see in almost every assessment: policies that differ depending on where a user connects from, administration effort that scales with the number of consoles rather than the size of the business, and no single view of what is happening across the environment.

Five signs it is time to consider SASE

Not every organisation needs to modernise immediately. These are the indicators that current architecture is working against the business.

1. Your VPN has become a bottleneck

VPNs were built for occasional remote access, not for an entire hybrid workforce connecting daily. Slow connections are the visible symptom. The bigger issue is that VPN access usually grants far broader network access than any single role requires.

2. You are managing too many security products

Separate firewalls, VPN infrastructure, web gateways and cloud security platforms mean separate policies, separate updates and separate skill sets. Consolidation reduces administrative load without reducing control.

3. Your business runs on cloud applications

When the applications people use all day sit in Microsoft 365 and Azure, routing that traffic through head office first adds latency for no security benefit.

4. Security policies differ across locations

As organisations grow, individual sites accumulate their own configurations. Centralised policy removes that drift and makes compliance evidence easier to produce.

5. You are planning for growth

New sites, acquisitions and more flexible working all put pressure on architecture. Extending a policy framework to a new location is a very different exercise to procuring and configuring another set of appliances.

Where inspection happens: cloud, branch or your own infrastructure

This question decides whether a SASE design suits your organisation, and most SASE content skips it. There are three options.

Cloud inspection. Users connect to the nearest vendor point of presence, where traffic is inspected and policy is applied. Fortinet operates more than 200 points of presence on its own infrastructure. This is the simplest model to operate and scale.

Local inspection at the branch. Traffic is inspected on the FortiGate already deployed at the site, which suits locations with latency sensitive or high volume local traffic.

Private inspection, also called Sovereign SASE. All traffic inspection and logging happens within infrastructure you control, in your own data centre or a colocation facility, with only orchestration centralised. Fortinet describes its sovereign offering as a turnkey solution including SWG, FWaaS, ZTNA and CASB deployed in the customer’s own data centres, supporting compliance with regional data residency requirements.

Government, healthcare and financial services organisations frequently have data residency obligations that rule out the first option. The third means the answer is no longer that SASE will not work for them.

The benefits organisations report

  • Simplified management: one policy framework and one console instead of several.
  • Stronger access control: access to individual applications based on identity and device posture reduces the damage a compromised credential can do, because a user session no longer implies network level access.
  • Better performance for hybrid staff: inspecting traffic close to the user removes the latency penalty of backhauling cloud traffic to head office.
  • A practical foundation for Zero Trust: access decisions based on verified identity and context rather than network location.

Why we recommend Fortinet SASE

Choosing the platform matters as much as choosing the architecture. A1 Technologies delivers Fortinet SASE because it is one platform rather than several products under one brand, merging FortiSASE with Fortinet Secure SD-WAN and running on one operating system with one agent.

The analyst view supports that. Fortinet was recognised as a Leader in the 2025 Gartner Magic Quadrant for SASE Platforms and ranked first in the Secure Branch Network Modernisation use case in the accompanying Gartner Critical Capabilities report.

As a Fortinet Engage Partner, A1 Technologies holds five Fortinet Partner Specialisations: SASE, SD-WAN, Cloud Security, Secure Networking Firewall and Secure Networking LAN. That expertise sits behind every SASE design we deliver.

Planning a SASE implementation

Every implementation we deliver starts with an assessment of the current environment: network and links, application inventory, users and devices, existing security controls and licensing already owned. That last point matters, because organisations regularly hold entitlements they are not using.

Implementation is then staged rather than switched over. A typical sequence is:

  1. Establish policy and identity integration, usually with Microsoft Entra ID.
  2. Move remote access from VPN to ZTNA for a pilot group, then by department.
  3. Move branch internet traffic to direct, inspected access.
  4. Consolidate remaining point products as their renewals fall due.
  5. Hand over to ongoing monitoring and optimisation.

Many organisations bring in our managed IT services for that final stage, so policy, licensing and performance keep being reviewed as the business changes.

Is SASE architecture right for your organisation?

If managing networking and security across offices, remote users and cloud services is getting harder rather than easier, it is worth assessing whether SASE would simplify it.

A1 Technologies helps Australian and New Zealand organisations assess their current environment, design a practical secure networking approach and implement Fortinet SASE in stages that fit the business. Talk to us about a network and security assessment today.

Subscribe to our newsletter

Enter your email and stay in touch with the latest updates from A1.

[mc4wp_form id="1436"]