SABAG: Focus on Network Security, Scalability and Flexibility
BNC Secure Access Service has improved efficiency and security for the SABAG Group
The SABAG Group has successfully implemented the BNC Secure Access Service, which has led to the creation of an optimized and location-independent IT infrastructure. This improvement includes the consolidation and central management of a firewall and SD-WAN technology, providing enhanced control over data traffic, increased service availability, and seamless integration with cloud infrastructures. The system offers real-time network monitoring and control, fostering scalability for business growth, and ensuring a secure user environment through a Zero-Trust approach. As a result, the SABAG team can now securely access all applications from any location.
SABAG Group
The SABAG Group, headquartered in Biel, is the largest Swiss family-owned company in the building materials trade, with a legacy of constructive innovation since 1913 in kitchens, bathrooms, ceramic tiles, wood, and building materials.
SCALABLE SOLUTIONS FOR COMPLEX IT CHALLENGE
Currently, SABAG employs over 1,000 individuals and operates a network of 38 branches across German- and French-speaking Switzerland. However, this expansive corporate structure, combined with the need for modern location- and device-independent employee and customer management, presents significant challenges for the SABAG Group's IT infrastructure. These challenges include ensuring network availability and stability, data security, scalability, interoperability, support, and cost management.
«Initially, we were only looking for a replacement for our previous SD-WAN. We had built our network concept with BNC, unfortunately after the introduction of the old SD-WAN, so with limitations in terms of feasibility. So we initiated discussions about alternatives, with BNC and with other providers. The high-level expert discussion with BNC then led to us opening our horizons further and throwing more aspects into the discussion that we also had to solve. As a result, a completely different conversation developed and we were presented with a solution approach that addressed several challenges at the same time and was not even very much more expensive in comparison.» Peter Weibel, Head of IT SABAG Group
Project Overview
-
Objectives
Our shared objective was to safeguard the IT infrastructure of the SABAG Group, ensuring protection from potential damage regardless of the location, with special consideration for home office users. We also emphasized scalability and cost-efficiency as essential criteria during the implementation process:
- Consolidating technologies such as SD-WAN and Next Generation Firewall and managing them centrally to achieve better control over the infrastructure.
- Improve service availability and create greater efficiency through redundant internet connections and direct connection of SaaS services
- Get more flexibility and agility through the possibility of integrating cloud infrastructures (Azure)
- Enable intelligent and automated control of network traffic through traffic steering
- It should be possible to control and prioritise data traffic based on predefined rules and priorities (traffic shaping).
- Implementation of various tools to monitor traffic in real time and to quickly identify and prevent threats (traffic visibility).
- Secure direct web access from the Branch Offices with minimal delay
- Secure remote access for internal and external users
- Scalability of the solution must be given in order to accompany the growth of the company.
- The operation, maintenance and support of the entire firewall and network infrastructure is to be taken over by the BNC.
-
Solution
With the successful implementation of the BNC Secure Access Service, employees of the SABAG Group now enjoy seamless access to all applications, regardless of their location, be it the home office or while traveling. The adoption of the zero-trust approach ensures comprehensive security by thoroughly verifying users, devices, and applications, thereby creating a secure environment. Moreover, the Secure Access Service facilitates site networking and local network segmentation, allowing for the integration of IoT devices and on-prem servers, all managed through firewalls and SD-WAN technology. Centralized control ensures user-based access rights to applications, while the SD-WAN functionality automatically optimizes data traffic to meet the requirements of each application.
-
Implementation
During the design and concept phase, we meticulously develop the target design and detailed procedures. Our team creates comprehensive concepts and designs to ensure a solid foundation for the project. We take into account various aspects, including:
- Migration concept
- SD-WAN High Level Design
- SD-WAN Low Level Design
- Data centre firewall
- Branch Firewall
- Identity-based rules
Commissioning Panorama and DC Firewall, and Preparations for Branch Firewall:
During this phase, we focus on setting up the components required for the migration of sites. The process is executed in parallel with the current SD-WAN environment. We prepare the branch firewalls for the rollout, and the Remote Access Service (RAS) solution is made operational.
Migration of DC Firewall:
The next step involves the replacement of existing firewalls in the Rothenburg data centre. After the successful migration, we proceed with dismantling the previous environment.
Migration of Branches:
With the existing SD-WAN solution scheduled for replacement by mid-September, we commence the migration of the sites. To ensure a smooth transition, each site is supported by a team consisting of a BNC engineer and an employee from the SABAG Group. Once the site migration is completed, the existing SD-WAN solution is no longer required and can be dismantled.
Conclusion
Through the implementation of a comprehensive firewall and network infrastructure, SABAG ensures the security of its infrastructure across all 38 locations, including the home office area. By consolidating technologies through SD-WAN and firewall, a unified and simplified security environment is created, resulting in higher network performance and stability through local break-outs. Additionally, redundant connections are in place to ensure higher availability and reliability.
«IT operations rarely run smoothly, which is how we had to adjust to BNC at first. In the meantime, however, we receive meaningful statistics in the quarterly mandate meetings, where we can have outliers investigated or justified. The cause of outages, abnormal behaviour or traffic jams can be many and varied, ranging from the internet communication we rely on to server behaviour that we had not set up properly. With the BNC, we have a provider that tackles the issues in partnership and competently with us and exerts pressure in our interest to solve the existing problems.» Peter Weibel, Head of IT SABAG Group Gruppe
YOU MIGHT ALSO BE INTERESTED IN...
Video: Panel discussion with Peter Weibel
Secure and Agile Management of Your Modern Network and Security Architecture: Is SASE the Future? We're discussing the client case SABAG together with Peter Weibel.
Blog: BNC Secure Access Service
We show how our on-premise solution revolutionises this point and frees companies from cloud dependency. Find out how we make SASE the new standard without the "E" and exploit the full range of potentials!
Blog: SASE - Potential and Limits
Learn more about the advantages and disadvantages of SASE (Secure Access Service Edge) and how companies can deal with the limitations of the technology.
Case: Enhancing VDI Performance and Efficiency at SABAG
Discover how SABAG harnessed the power of Pure Storage All-Flash technology to elevate VDI infrastructure performance and availability.