← All selected work

SASE · Secure access

Replacing legacy VPN with SASE.

I selected and implemented a Secure Access Service Edge (SASE) platform to replace legacy VPN and protect off-network endpoints, from tender and costing through security configuration, identity integration and client rollout.

  • SASE
  • High availability
  • Firewall policy

My roleTechnical selection, commercial evaluation, hands-on implementation and operational handover

Define the requirement and select the service

The requirement combined remote access to internal services with internet traffic protection for endpoints away from the corporate network. The selection also had to account for identity, device deployment and ongoing administration.

I ran the invitation to tender, evaluated options against the requirements and brought together the costings. I selected the preferred solution and developed the commercial recommendation.

Implement connectivity and traffic protection

I implemented high-availability gateways and configured Internet and WAN firewall policies for web access and internal services. I enabled policy logging to support investigation and subsequent changes.

I migrated the existing web policies, configured intrusion prevention (IPS) and deployed the certificates required for TLS inspection of encrypted traffic.

Illustration of a single rack-mounted security appliance connected with red network cables.
Connectivity and traffic protection formed part of the secure-access rollout.AI-generated illustration inspired by project photography.

Connect identity and deploy the clients

I integrated single sign-on with organisational identity and multi-factor authentication, then configured directory synchronisation for users and security groups. Group-based policies managed web access and internal access exceptions.

I used managed software deployment to roll out the client, with installation steps appropriate to laptops and fixed workstations. I prepared device setup and remote-login instructions for users and the support team.

Equip the team to administer and troubleshoot

I documented the implemented configuration and how to create and maintain policies, change access and investigate permissions through group membership.

The handover and knowledge-base guidance covered client setup, authentication, connectivity and access to business applications, giving colleagues practical steps for administration and troubleshooting.

The result

Secure access beyond the office.

The legacy VPN was replaced by a SASE service combining remote access, traffic protection and organisational identity, with client deployment and administration handed over to operational support.

The support guidance also covered packet capture for investigations that needed deeper traffic evidence.