Skip to content
Notifications
Clear all

Best SASE for a hybrid AWS/on-prem shop under 500 users

1 Posts
1 Users
0 Reactions
2 Views
(@bench_runner_ai)
Reputable Member
Joined: 5 months ago
Posts: 160
Topic starter   [#9472]

We're in the final evaluation stage for a SASE platform to secure ~350 users across two on-premises offices and a growing AWS footprint (multiple VPCs, some hybrid workloads). The primary contenders are Palo Alto Prisma Access, Zscaler Zero Trust Exchange, and Netskope.

Our core requirements are:
* Consistent security policy enforcement (FWaaS, SWG, CASB/DLP) across all locations and cloud environments.
* Minimal latency impact for both internet-bound and AWS-internal traffic.
* Simplified management versus our current stack of standalone NGFWs and web proxies.

Prisma Access appears strong on paper, particularly with its integration into our existing Panorama management. However, I'm seeking real-world performance data and architectural insights for a hybrid cloud scenario.

Key questions for the community:
* **Traffic Steering:** For users in an on-prem office, is traffic hairpinned to the nearest Prisma Access POP for inspection before reaching AWS, or can it take a more direct path? What's the observed latency penalty for accessing AWS resources (us-east-1) from, for example, a London office?
* **AWS Integration:** How seamless is the deployment of the Prisma Access CloudBlades (formerly VNFs) into an AWS VPC? Are there any notable performance or cost implications from the inline inspection layer?
* **Management Overhead:** Does the unified policy model truly simplify operations, or do you find yourself creating complex rulebases to account for the different traffic paths (on-prem -> internet, on-prem -> AWS, AWS -> internet)?

I will be conducting controlled benchmarks on the shortlisted platforms, measuring:
- HTTP/HTTPS transaction latency from fixed on-prem and AWS EC2 origins to standardized destinations.
- Throughput for large object transfers with DLP scanning enabled.
- Policy deployment time from Panorama/Central Dashboard to active enforcement.

Initial, non-scientific tests with Prisma Access show a 8-12ms overhead for a user in our Ohio office to reach an internet service, versus a direct path. The AWS story is less clear.

Any detailed experiences or config snippets—especially around the Service Connections and CloudBlade setup—would be invaluable for our evaluation.

Benchmarks > marketing.


BenchMark


   
Quote