It can include branch gateways, access points, cloud ingress and egress, carrier links, operational sites, and service-delivery points. Modern distributed systems have many edges rather than one permanent perimeter.
The edge often concentrates routing, access, translation, inspection, and policy enforcement, but its location depends on service architecture and control ownership. Cloud, mobile, software-defined wide-area networking, edge computing, and direct-to-service access can move traffic around a traditional headquarters gateway.
Key points
Edge inventoryMap connectivity, exposed services, trust transitions, upstream providers, management paths, alternate routes, encryption endpoints, and business owners.
Layered policyAuthenticate subjects and devices, restrict routes and services, segment destinations, protect name resolution, validate encrypted sessions, and collect useful telemetry on each viable path.
ResilienceSize links and enforcement points, distribute critical services, protect management planes, plan upstream denial-of-service mitigation, and test failover without silently bypassing policy.
Important limitationThe network edge is not a complete security boundary. Authorized traffic can carry attacks, identities and data can be misused after access, internal and cloud-to-cloud paths may never cross it, and excessive consolidation can create bottlenecks or shared failure.