# What is the Network Edge?

> The network edge is a context-dependent boundary or zone where an organization’s network connects to users, devices, workloads, providers, partner networks, access networks, or the public internet.

- Canonical URL: https://yellowcube.eu/glossary/network-edge/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It can include branch gateways, access points, cloud ingress and egress, carrier links, operational sites, and service-delivery points. Modern distributed systems have many edges rather than one permanent perimeter.

The edge often concentrates routing, access, translation, inspection, and policy enforcement, but its location depends on service architecture and control ownership. Cloud, mobile, software-defined wide-area networking, edge computing, and direct-to-service access can move traffic around a traditional headquarters gateway.

### Key points

- **Edge inventory:** Map connectivity, exposed services, trust transitions, upstream providers, management paths, alternate routes, encryption endpoints, and business owners.
- **Layered policy:** Authenticate subjects and devices, restrict routes and services, segment destinations, protect name resolution, validate encrypted sessions, and collect useful telemetry on each viable path.
- **Resilience:** Size links and enforcement points, distribute critical services, protect management planes, plan upstream denial-of-service mitigation, and test failover without silently bypassing policy.
- **Important limitation:** The network edge is not a complete security boundary. Authorized traffic can carry attacks, identities and data can be misused after access, internal and cloud-to-cloud paths may never cross it, and excessive consolidation can create bottlenecks or shared failure.

### Related terms

[Edge computing](<https://yellowcube.eu/glossary/edge-computing/>) · [Network security](<https://yellowcube.eu/glossary/network-security/>) · [Secure access service edge (SASE)](<https://yellowcube.eu/glossary/secure-access-service-edge/>) · [Network latency](<https://yellowcube.eu/glossary/network-latency/>) · [Software-defined wide area network (SD-WAN)](<https://yellowcube.eu/glossary/software-defined-wide-area-network/>) · [Branch networking](<https://yellowcube.eu/glossary/branch-networking/>)

### Sources

[NIST SP 800-82 Rev. 3, Guide to Operational Technology Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final) · [NIST SP 800-207, Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final) · [NIST SP 800-215, Guide to a Secure Enterprise Network Landscape](https://csrc.nist.gov/pubs/sp/800/215/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

