When it comes to network security, there should be no disconnect between the corporate and the distributed locations
Background: I have a number of customers in the retail industry. Usually, they have a large number of remote locations (restaurants, brick and mortar stores, and kiosks). Before the cheap/high-speed Internet connections being used for enterprise connectivity (IPsec tunnels over these connections) and before the SD-WAN revolution, all of these remote locations’ traffic traversed private connections such as MPLS or frame relay connections to one or two centralized data centers to reach corporate resources or the Internet. Securing these types of set up were rather less complicated because you had one or two centralized points to secure (mostly at the edge where Internet was accessed). We are now faced with every remote location acting as an “Internet PoP” (point-of-presence). These locations will use an IPsec tunnel over the Internet connection to reach corporate resources. The Internet traffic is locally routed using their existing high speed connection but wit...