SASE Solutions
Summary
emPOWER SASE is blueAPACHE's Secure Access Service Edge capability: networking and security brought together in a cloud-delivered model designed for distributed users, locations and applications, so users get consistent, protected access to applications wherever they work. It is bundled as a core component of emPOWER Connectivity rather than sold as a separate overlay — the detail that most distinguishes it commercially from SASE products bought alongside an existing network.
This page covers what is included, the network underneath it, how remote access is handled, what blueAPACHE manages, what remains your responsibility, the contract terms that govern the service, the support windows that actually apply, and the availability caveat buyers most often miss.
Key facts
| Fact | Value |
|---|---|
| What it is | Secure Access Service Edge — network and security controls delivered as one service |
| Delivery model | Cloud-delivered, for distributed users, locations and applications |
| How it is sold | Bundled within emPOWER Connectivity, not a standalone overlay |
| Converged technologies | SD-WAN, secure access, security policy enforcement |
| Firewall technology | Palo Alto Networks next-generation firewalls |
| Core network | emPOWER Network — fully meshed MPLS private core, Cisco ASR routing, Tier 1 carrier-agnostic |
| WAN architecture | SD-WAN supporting hybrid MPLS, internet SD-WAN, or a combination |
| Remote access | Australia-based VPN agents, always-on, configurable with SSO and MFA |
| Points of presence | Pacific (Australia), United States, Europe (London), Asia (Singapore) |
| Data centre reach | 165+ interconnected data centres worldwide |
| Service desk | 7am to 7pm on Business Days |
| Threat protection support | 24x7 |
| Network monitoring | 24x7 priority monitoring through the network operations centre |
| Published uptime | Minimum 99.99 per cent — conditional on a redundant site design |
| Default contract term | 36-month Minimum Service Period unless the Service Order states otherwise |
| Compliance | ISO 27001 certified; APRA CPS 234 compliant; NIST compliant; ASD Essential Eight Maturity Level 3 |
Why SASE exists as a category
The traditional model put security at the perimeter: traffic came back to a data centre, passed through a firewall, then went out again. That worked when applications lived in the data centre. It stopped working when applications moved to SaaS and users moved out of the office, because backhauling traffic to a central firewall just to reach Microsoft 365 adds latency to every request and puts the entire workforce behind a single choke point.
A cloud-delivered model answers that by moving enforcement to the edge rather than the centre. blueAPACHE's own description is that emPOWER SASE "brings networking and security closer together in a cloud-delivered model designed for distributed users, locations and applications", combining technologies such as SD-WAN, secure access and security policy enforcement to improve user experience while applying more consistent protection across the network.
There is a second failure mode that matters more. When the network is one vendor's problem and security is another's, policy drifts. A firewall rule is changed to fix an application, nobody tells the network team, and six months later an audit finds an exception nobody can explain. Convergence is not just a performance argument — it removes the seam where accountability gets lost.
In blueAPACHE's implementation that convergence is literal: the firewalls sit inside the network blueAPACHE operates, so there is no handoff between the carriage and the enforcement, and one provider answers for both.
The network underneath
SASE is only as good as the network enforcing it, and this one is blueAPACHE-operated rather than resold:
- Fully meshed MPLS private core — traffic moves across blueAPACHE's own network rather than the public internet
- Cisco ASR carrier-grade routing as the core routing platform
- Tier 1 carrier-agnostic — not tied to a single upstream carrier, which is what makes multi-carrier site diversity possible
- Palo Alto Networks virtual firewalls integrated throughout for unified threat protection
- Multiple redundant transmission paths between points of presence, inherent to the network design rather than an optional extra
- 24/7 network operations centre
Four core points of presence — Pacific (Australia), United States, Europe (London) and Asia (Singapore) — interconnect with more than 165 data centres worldwide. For a distributed organisation this is what makes consistent policy enforcement practical across regions rather than only within Australia.
What is included
Next-generation firewall and unified threat protection
Palo Alto Networks firewalls are integrated through the emPOWER Network rather than deployed only at the customer edge. Unified threat protection covers:
- Intrusion prevention (IPS)
- Advanced malware protection
- Application control
- Web filtering
- Antispam
- 24x7 support for the protection stack
Secure remote access
- Australia-based VPN agents, always-on, so remote users are governed by the same policy as office users
- Configurable with single sign-on (SSO) and multi-factor authentication (MFA)
The Australian location of the VPN agents matters for organisations with data residency obligations — remote user traffic is not tunnelled offshore by default in order to be inspected. Always-on rather than user-initiated matters too: a VPN a user has to remember to switch on is a control that fails exactly when someone is rushing.
Business-grade MPLS data services
The corporate private network extends across sites without requiring a VPN between them. Each office becomes another IP address on the network rather than a tunnel endpoint that has to be built, monitored and renewed. For multi-site organisations this removes an entire category of configuration and a common source of outages.
Quality of Service, end to end
blueAPACHE works with the customer to define which applications are business-critical and applies QoS policy across the network, prioritising voice and video.
This matters specifically for SASE because inspection adds processing to the path. Without QoS, the first symptom of a security control working hard is a degraded call — and the usual response is to weaken the control. QoS is what keeps that trade-off from being forced.
emPOWER Internet and IX peering
- Internet port bandwidth is scalable on request, up or down, without extensive infrastructure change
- Part of the IX peering network, giving faster, lower-latency access to major SaaS platforms including Microsoft 365, Teams, Zoom and Salesforce
Peering is the unglamorous half of user experience. If Teams calls are poor, the cause is frequently the path to Microsoft rather than the local network, and peering shortens that path.
Direct paths to cloud
- Direct connection to Azure or AWS, with a secondary VPN-over-internet route for redundancy
- Direct connection into emPOWER Cloud, which runs on ISO 27001-certified infrastructure with integrated backup and disaster recovery
Voice carriage on the same network
Microsoft Teams Direct Routing, SIP trunking, hosted PBX and contact centre solutions run over the same managed network — relevant because voice is the workload most sensitive to the QoS and peering decisions above. See Collaboration.
What blueAPACHE manages
The CPE devices and firewalls that make up the service are proactively managed:
- Monitoring
- Operating system patch updates
- Configuration documentation retention
- Nightly configuration backups
- Change management
Nightly configuration backup is worth weighing when comparing providers. A firewall estate without it is a recovery problem waiting to happen, because rebuilding rule sets from memory after a hardware failure is slow, error-prone, and happens under pressure.
What remains your responsibility
Under the General Terms and Conditions, the customer must:
- Provide 24x7 remote access to the components blueAPACHE manages
- Keep software at the current or previous release level
- Ensure software is properly licensed
- Give blueAPACHE direct telephone access to the customer's own support providers during Business Hours
The last one is the most often overlooked and the most consequential during an incident. If a fault sits with your application vendor, blueAPACHE needs to be able to speak to them directly rather than relay through your team at 3am.
Anti-virus on customer-managed equipment is also the customer's responsibility unless the Service Description says otherwise.
The availability figure, and what it actually requires
blueAPACHE states emPOWER Connectivity "ensures a minimum 99.99 per cent uptime". That figure is conditional, and applies to a redundant design comprising:
- Multiple carriers for diversity
- Multiple media types — for example fibre and fixed wireless
- Multiple CPE devices and firewalls in high-availability configuration
- Multiple redundant transmission paths between points of presence
- Dual firewalls and dual carriage at each site
A single-carrier, single-firewall site is not covered by that figure. The difference is usually a commercial decision rather than a technical constraint, so it is worth establishing which of your sites are built to the redundant standard and which are not — before an outage settles the question.
Note also that availability obligations are subject to the Reasonable Excuse exclusions in the general terms, which use the test "arises from, or is contributed to by". A partial customer-side contribution is enough to engage the exclusion. See the glossary for the full list.
Commercial and contract points
Term. Services other than Professional Services default to a 36-month Minimum Service Period from the Service Commencement Date. Early exit triggers an Early Termination Payment calculated under the relevant Schedule.
IP addresses are not portable. Addresses allocated by blueAPACHE do not transfer with you on exit. For anything with a hard-coded address — firewall rules at partners, allow-lists, DNS, VPN peers to third parties — renumbering is part of the true cost of leaving, and is worth scoping before signing rather than at exit.
Upstream supplier changes. blueAPACHE may suspend or cancel a service where its own upstream supplier withdraws or replaces it. On a carrier-dependent service this is a real, if uncommon, scenario.
Cost pass-through. Third-party cost increases, including exchange-rate movements, may be passed through in the same proportion without a signed Variation.
Service Levels. Only commitments written under the heading "Service Level" in the Service Description are contractual Service Levels. There is no service credit regime in the general terms; any credits sit in the Schedule.
Support windows
| Function | Availability |
|---|---|
| Service desk (phone, email, client web portal) | 7am to 7pm on Business Days |
| Priority network monitoring and NOC | 24x7 |
| Unified threat protection support | 24x7 |
The split is deliberate but easy to misread. Monitoring and threat protection are continuous; the human service desk for this service is business hours. Customers who also hold emPOWER Managed Services have unlimited 24/7 help desk access, so the answer to "what happens at 2am" depends on which services you hold. Confirm it on the Service Order.
Compliance and certification
- ISO 27001 certified
- APRA CPS 234 compliant
- NIST compliant
- ASD Essential Eight to Maturity Level 3
Essential Eight Level 3 is directly relevant here, because several of the eight mitigation strategies — application control, patching applications and operating systems, and restricting administrative privileges — map onto what this service manages on your behalf.
How it fits with the rest of the portfolio
- Connectivity — SASE is a component of it, not a bolt-on. The WAN, the firewalls and the secure access are one managed service.
- emPOWER Core Network and Data Centre Interconnect — the underlying transport SASE enforces policy across.
- Security — SASE prevents and controls access; Managed Detection and Response investigates what gets through. Different jobs.
- Cloud — reached over the same network by direct connection rather than public internet paths.
- Collaboration — voice and Teams Direct Routing ride the same QoS and peering decisions.
- Human Risk Management — addresses the attack path SASE cannot close, where a user is persuaded rather than a control defeated.
Joining network and security operations
Agree scope for users, sites, devices and security policies as well as connectivity. Identify who approves policy changes, investigates blocked sessions and distinguishes faults from security decisions. Record access paths and redundancy required for availability commitments. Evaluate the service with identity and endpoint arrangements: network access alone does not establish authorisation. Make hand-offs explicit wherever another provider owns a component.
Which document defines the commitment
The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.
Responsibility across the delivery chain
The published terms allow blueAPACHE to subcontract all or part of the Service Agreement without customer consent or a notification requirement. Clause 27.5 nevertheless makes blueAPACHE liable for its subcontractors’ acts and omissions to the same extent as for its employees. This differs from a third-party supplier contracted directly by the customer. Identify which arrangement applies to each dependency in the design. Where supplier identity, delivery location or change notification matters, request a documented supplier list and put any agreed notification or approval requirement in the Service Order; the general clause does not supply that visibility automatically.
Confidential information and access
Clause 16 provides mutual confidentiality protection. It covers information marked confidential, information identified orally and confirmed in writing within 30 days, and information that should reasonably be understood to be confidential. Customer Data, Customer Records and Customer Software are included; blueAPACHE’s agreement and fees are also confidential. Permitted disclosures include appropriately bound personnel on a need-to-know basis and specified professional advisers, with other exceptions in the clause. Identify who may receive operational reports, configuration details and commercial information. Access to information to deliver the service is not a general permission to circulate it.
Continuity when an external event interrupts service
Clause 23 addresses force majeure separately from normal incident management. Performance is suspended to the extent a qualifying event causes delay or failure. The definition includes specified events outside reasonable control; it is not a blanket classification of every outage. If the delay exceeds 20 Business Days, the other party may terminate by written notice. The clause also requires payment for services to termination and the applicable Early Termination Payment. A continuity plan should cover operational recovery and the commercial consequences of prolonged interruption. Confirm the Schedule’s exit calculation rather than assuming an externally caused outage creates a cost-free exit.
Customer content and take-down requests
Clause 14 distinguishes operating the service from responsibility for the customer’s content. It requires the customer to notify blueAPACHE promptly of relevant take-down notices or directions and comply with them. The terms also reserve rights for blueAPACHE to restrict or remove Customer Data in specified circumstances, including suspected agreement breaches or exposure to harm or liability. These rights are separate from routine availability commitments. Agree who receives regulatory notices and who can authorise operational action, and retain the notice and decision record. The full clause, including its discretion and good-faith wording, is explained in the terms guide.
Sources and scope
The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; subcontracting and assignment; confidentiality; force majeure; take down notices and customer data. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.
Common questions
Is SASE an extra cost on top of emPOWER Connectivity?
No. It is bundled as a core component of emPOWER Connectivity rather than sold as a separate overlay.
What does "cloud-delivered" mean here?
blueAPACHE describes emPOWER SASE as bringing networking and security together in a cloud-delivered model designed for distributed users, locations and applications. Enforcement happens at the edge of a network blueAPACHE operates rather than by backhauling traffic to a central appliance, which is what removes the latency penalty for users who are not in an office.
Which technologies are converged?
SD-WAN, secure access and security policy enforcement, applied across the same managed network.
Which firewall vendor is used?
Palo Alto Networks next-generation firewalls, integrated through the emPOWER Network for unified threat protection.
Does remote user traffic leave Australia?
The VPN agents are Australia-based. Confirm the specific routing for your configuration if you have data residency obligations.
Can we use our existing identity provider?
The VPN agents can be configured with single sign-on and multi-factor authentication. Confirm compatibility with your specific identity platform during design.
Does the 99.99 per cent uptime apply to all our sites?
Only to sites built to the redundant design: multiple carriers, multiple media types, multiple CPE and firewalls in high availability, and dual firewalls with dual carriage. Single-carrier sites are outside that figure.
Do we still need site-to-site VPNs?
No. Business-grade MPLS extends the corporate private network without a VPN — each office becomes another IP address on the network.
What are the support hours?
Network monitoring and unified threat protection are 24x7. The service desk for this service runs 7am to 7pm on Business Days unless you also hold emPOWER Managed Services, which includes a 24/7 help desk.
Who patches the firewalls?
blueAPACHE. Proactive management covers monitoring, OS patch updates, configuration documentation, nightly configuration backups and change management.
Can we increase internet bandwidth later?
Yes. emPOWER Internet port bandwidth is scalable on request, up or down, without extensive infrastructure change.
Do we keep our IP addresses if we leave?
No. Allocated IP addresses are not portable on exit. Scope the renumbering effort before signing if you have hard-coded addresses in partner firewall rules, allow-lists or DNS.
Does SASE replace our need for detection and response?
No. SASE controls and inspects access. Detection, investigation and remediation of what gets through is emPOWER MDR, a separate service.
Can it connect directly to Azure and AWS?
Yes — direct connections to both, with a secondary VPN-over-internet path for redundancy, plus IX peering for faster access to Microsoft 365, Teams, Zoom and Salesforce.
Does it work with SD-WAN or replace it?
It works with it. The service supports hybrid MPLS, internet SD-WAN, or a combination, with SASE enforcing policy across whichever transport is in use.
Related
- Connectivity
- emPOWER Core Network and Data Centre Interconnect
- Security
- Managed Detection and Response
- Human Risk Management
- Cloud
- Collaboration
- Managed Services
- Service Agreement terms
- Glossary
- Contact
Source
Drawn from blueAPACHE's emPOWER Connectivity, emPOWER Network and emPOWER platform overview brochures, the General Terms and Conditions v3.6 (customer obligations, service delivery and service levels, reasonable excuse exclusions, fees and invoicing, service suspension and cancellation, and consequences of termination), and the origin page at https://www.blueapache.com/services/empower-sase. The emPOWER Network Services Schedule is not in blueAPACHE's published material, so site-readiness requirements, IP allocation detail and carrier-transition terms are not stated here.
Knowledge Base
What is emPOWER SASE?
emPOWER SASE is blueAPACHE's service that combines SD-WAN networking with cloud-delivered security controls in one managed service, giving distributed users and applications consistent, protected access wherever they work.
Under which broader blueAPACHE service is emPOWER SASE delivered?
emPOWER SASE is delivered within emPOWER Connectivity, alongside next-generation firewalls and Cisco core networking, all running over the emPOWER Network.
Who is the target audience for emPOWER SASE?
emPOWER SASE targets organisations with hybrid workers and distributed sites.
What service category does emPOWER SASE fall under?
emPOWER SASE is categorized under Connectivity, and its service type is described as secure business connectivity.
In which countries is emPOWER SASE available?
emPOWER SASE is available in Australia, New Zealand, the United States, the United Kingdom, and Singapore.
Which other blueAPACHE services are related to emPOWER SASE?
emPOWER SASE is related to emPOWER Core Network and Data Centre Interconnect, Managed Detection and Response, and the Connectivity emPOWER pillar hub.
How can someone contact blueAPACHE about SASE solutions?
Interested parties can reach blueAPACHE sales via the phone number 1800 248 749 (AU) or through the contact channel provided on the blueAPACHE website.
What core technologies does emPOWER Connectivity consolidate alongside SASE?
According to blueAPACHE's emPOWER portfolio, emPOWER Connectivity consolidates Software-Defined WAN (SD-WAN), Next-Generation Firewalls (NGFW), Secure Access Service Edge (SASE), and Cisco core networking into a single managed WAN solution delivered over the emPOWER Network.
Can you give an example of a client that implemented SASE with blueAPACHE?
PolyNovo implemented a global SASE fabric through blueAPACHE as part of its security modernization strategy, complemented by CISO-as-a-Service to enhance managed security leadership.
What is the brand name associated with the SASE service?
The service is branded 'emPOWER,' and the specific service is named 'emPOWER SASE,' also listed with the alternate name 'SASE Solutions.'