Enterprise SASE Stack — Mosdos Institutional
Cardinal #112 tangible-build · Pieces 131-137 consolidated · Mosdos tier enterprise substrate
What this vessel does
Mosdos tier (yeshivas + schools + shuls) needs enterprise-grade SASE substrate beyond consumer family-filter. KolBo absorbs Zscaler ZPA/ZIA + Netskope CASB/NewEdge + Forcepoint DLP + cloud-firewall + TLS-inspection + SD-WAN patterns. Composition into KolBo Mosdos-tier substrate without re-implementing.
Zero Trust Network Access (Zscaler ZPA pattern)
Piece 131
Mosdos tier institutional substrate; per-application access policy not per-network
Secure Web Gateway (Zscaler ZIA + Netskope NewEdge)
Piece 132
Cloud-delivered web filter at SASE layer; KolBo composes with existing DNS + Squid substrate
CASB (Netskope pattern)
Piece 133
Cloud Access Security Broker — visibility + policy over SaaS app usage by institutional Mosdos
DLP (Forcepoint / Netskope)
Piece 134
Data Loss Prevention — institutional-policy-driven; PII scanning (Piece 101 composition)
FWaaS (Firewall-as-a-Service)
Piece 135
Cloud-firewall composition; Mosdos tier
TLS inspection (institutional)
Piece 136
Institutional Mosdos tier TLS-decryption substrate; cert-deployment via MDM (Piece 61)
SD-WAN integration patterns
Piece 137
Software-defined WAN for institutional Mosdos networks; KolBo composes via existing DNS/proxy/content substrate