Fully managed, secure and scalable global SD-WAN with SASE Solution designed around application performance
Customer Overview
A leading global mining company with operations across more than 100 sites in 20 countries and six continents, including Africa, Europe, Southeast Asia, North America, South America, and Australia. The company provides products and services to a broad range of customers across the mining sector, helping make mining safer, more efficient, and more sustainable.
The Group’s strategy is to be the supplier of choice in the markets it serves, while continuing to grow both domestically and through the ongoing expansion of its footprint across key geographies and market segments. In support of this strategy, its businesses are structured around two growth pillars: Mining and Chemicals, which includes the Specialty Minerals South Africa joint venture.
Customer Challenge
The organisation needed to move away from its legacy hub-and-spoke architecture and create a global WAN solution that would enable digitisation at scale while future-proofing the business in line with its long-term strategic vision. The objective was to establish a modular, scalable, integrated network and security architecture that would deliver a seamless, predictable, and consistent end-user experience across distributed environments, underpinned by Zero Trust Network Access (ZTNA).
Logicalis Solution Overview
The project was designed to implement a fully managed, secure, and scalable global SD-WAN and Secure Access Service Edge (SASE) solution, optimised for application performance. Modernising the existing wide area network by transitioning it into a unified, software-defined hybrid architecture, enhancing visibility, operational control, and overall user experience.
The scope encompassed all corporate offices, branch locations, and data centres, as well as secure remote access through Zero Trust Network Access (ZTNA). It also included integration with identity providers (such as Azure Active Directory and Entra ID) and the migration from MPLS to a hybrid network environment.
The solution includes a unified SASE framework through Palo Alto Prisma Access, delivering tightly integrated cloud-based networking and security capabilities. These include:
- Zero Trust, Network Access (ZTNA) for secure, least privilege access
- Secure Web Gateway (SWG)
- Firewall-as-a-Service (FWaaS)
- Cloud Access Security Broker (CASB)
- Autonomous Digital Experience Management (ADEM)
- DNS Security
- Centralised policy framework across users and locations
- Integrated 5G/4G connectivity for resilience and provider redundancy
Business Outcomes
This solution delivered a strategic transformation of the legacy WAN into a simplified, secure, and application-centric network architecture. By placing application performance at the core, it leverages an advanced application performance engine to dynamically optimise traffic flows in alignment with business priorities, ensuring critical services consistently receive the required bandwidth and quality of experience.
The proposed architecture provided optimal connectivity, integrated security, and a seamless user experience across all environments, spanning corporate sites, branches, and remote users. Through application-aware traffic management, the network achieved improved performance, scalability, and reliability, while extending data centre-grade security controls to the network edge.
A centralised, cloud-based orchestration platform, Palo Alto’s Strata Cloud Manager, underpins the solution, enabling intelligent network control, enhanced operational efficiency, and deep visibility into application usage. This ensures consistent policy enforcement across the enterprise and provides IT teams with the insights needed to proactively manage and optimise network performance.
Key architectural capabilities include Layer 7 application intelligence for granular policy definition and traffic engineering, end-to-end application performance optimisation (including SaaS), and fully integrated Zero Trust security with comprehensive visibility of users, devices, and applications. In addition, automated provisioning significantly simplifies branch deployments and accelerates time to value.
The solution provides tailored last-mile connectivity designed to meet the specific requirements of each site, ensuring reliable, scalable access across all locations. It incorporates site-specific design based on user density and bandwidth demands, supports multiple access technologies, and includes defined primary, secondary, and backup links to enable resilience and seamless failover.
The approach also offers the flexibility to adapt to regional ISP constraints while accommodating evolving business requirements.
The solution further incorporates the Palo Alto AIOps solution of machine learning driven autonomous operations to deliver advanced analytics, continuous optimisation, and predictive insights. Combined with cloud-delivered networking services, this enables greater business agility, reduced operational complexity, and improved return on investment.
Summary
Overall, the solution establishes a modern, intelligent network foundation that enhances performance, strengthens security, and supports the organisation’s evolving digital and business requirements. This implementation not only delivers measurable business value but also signals a new era of trusted, strategic partnership between the customer, Logicalis, and Palo Alto Networks.