Zscaler Private Access: Fast, Secure Access To Private Applications With Cloud-Delivered Zero Trust Network Access (ZTNA)
Zscaler Private Access: Fast, Secure Access To Private Applications With Cloud-Delivered Zero Trust Network Access (ZTNA)
Zscaler Private Access: Fast, Secure Access To Private Applications With Cloud-Delivered Zero Trust Network Access (ZTNA)
Businesses are moving private apps that once ran solely in the data
center to public clouds. At the same time, they are searching for ways
to enable productivity as users work from anywhere and on any device.
The key to success begins with finding the right balance of security and
user experience.
Today, the security perimeter extends beyond the corporate network to anywhere users connect
and wherever applications run. Traditional network security architectures have become less relevant
for modern workflows, as they are anchored in the data center and rely on appliances. These
architectures were not built for the cloud and mobile world and were never designed to scale like a
cloud service.
Network-based architectures are also vulnerable as a result of excessive trust. Remote users
connecting from an approved list of IP addresses (via VPN) are assumed to be trusted and are
granted access to the network through a firewall, which is often exposed to the internet. On-premises
users on the network can move laterally across it. Ultimately, this inherent trust leads to risk and
overprivileged network access.
The security paradigm needs to shift from a static network perimeter and, instead, focus on the entity,
resource, and user device. This shift in focus is why Gartner recommends that organizations adopt a
zero trust network access service (ZTNA) to secure access to private applications.
• Application access should be based on context and should not require network access
• Inside-out connections should be used to make applications invisible to unauthorized users
• Application segmentation should connect users to a specific app and limit lateral movement
• The internet must become the enterprise’s new transport network
DATA SHEET
When a user (employee, third-party contractor, or customer) attempts to access an application, the user’s
identity and device posture are verified using Zscaler™ Client Connector software (formerly Zscaler App)
installed on the user device. Policy is checked, and a ZPA Service Edge determines where the closest
application instance exists. ZPA uses the location of the client and determines the closest application to
the user according to what a ZPA App Connector (lightweight VM) can see. Lastly, two outbound tunnels,
one from the Client Connector on the device and the other from the App Connector, are stitched together
by a ZPA Service Edge. All of this takes place automatically and in real time.
A ZPA Service Edge can either be hosted by Zscaler in the cloud (ZPA Public Service Edge) or can be
run on-premises on the customer’s infrastructure (ZPA Private Service Edge). In either case, they are
managed by Zscaler and no appliances are required. Below is a look at the ZPA architecture:
Direct
App Connectors 4 Connect
How it works:
1 User authentication with IDP (first time only)
3 The ZPA Service Edge enforces policy and sends dispatch to connectors
4 The App Connector closest to app sends inside-out tunnel to ZPA Service Edge
5 The ZPA Service Edge stitches together the connection between app and user
• Discovering applications running in your public cloud and applying granular access controls
• Giving you the ability to view real-time user activity and the health of applications, servers,
and connectors
• Automatically streaming user audit logs to your SIEM provider
• Using policies hosted in the Zscaler cloud to determine which users can access apps
• Defining and managing policies for users, user groups, applications, and application groups
• Segmenting access by user and app as a more granular alternative to network segmentation
Core
Business capabilities
Transformation capabilities
ZTNA components
• ZPA App Connectors Pair/1,000 users (max:10) Pair/500 users (max: 100) Pair/300 users (max: 300)
• ZPA Private Service Edge for on-premises ZTNA Pair/10k users (max: 5) Pair/5K users (max: 10)
• Zscaler B2B Pro platform – ZTNA for customers 1 TB/m/50k users (max: 4 TB)
About Zscaler
Zscaler enables the world’s leading organizations to securely transform their networks and applications for a mobile and cloud-first world.
Its flagship services, Zscaler Internet Access™ and Zscaler Private Access™, create fast, secure connections between users and applications,
regardless of device, location, or network. Zscaler services are 100% cloud delivered and offer the simplicity, enhanced security, and improved
user experience that traditional appliances or hybrid solutions are unable to match. Used in more than 185 countries, Zscaler operates
a multitenant, distributed cloud security platform that protects thousands of customers from cyberattacks and data loss. Learn more at
zscaler.com or follow us on Twitter @zscaler.
Zscaler, Inc.
120 Holger Way
San Jose, CA 95134
+1 408.533.0288
www.zscaler.com
©2021 Zscaler, Inc. All rights reserved. Zscaler™, Zscaler Private Access™, and ZPA™ are either (i) registered trademarks or service marks or (ii)
trademarks or service marks of Zscaler, Inc. in the United States and/or other countries. Any other trademarks are the properties of their respective
owners. V.270720