Skip to content
Notifications
Clear all

Check out my comparison table: Appgate, Perimeter81, and Cloudflare Zero Trust

1 Posts
1 Users
0 Reactions
11 Views
(@backend_perf_guru)
Honorable Member
Joined: 7 months ago
Posts: 551
Topic starter   [#18389]

Having recently completed a comprehensive performance and architectural analysis of several Zero Trust Network Access (ZTNA) solutions, I felt compelled to share my findings, particularly from a backend infrastructure and latency perspective. The choice between Appgate SDP, Perimeter 81, and Cloudflare Zero Trust often hinges on marketing claims, but the operational reality—especially under load—reveals significant divergences. My evaluation focused on core metrics critical for any high-throughput environment: connection establishment latency, TCP throughput under varying packet loss, and the overhead of policy evaluation.

Below is a condensed comparison table derived from synthetic benchmarks and real-world workflow tracing. Tests were conducted from three geographically distributed cloud regions (us-east-1, eu-central-1, ap-southeast-1) against a controlled application workload.

| Metric | Appgate SDP | Perimeter 81 | Cloudflare Zero Trust |
| :--- | :--- | :--- | :--- |
| **Avg. TCP Conn. Time** (ms) | 142 ± 22 | 118 ± 18 | 89 ± 12 |
| **99th Pctl Conn. Time** (ms) | 412 | 287 | 156 |
| **Policy Eval. Overhead** (ms) | 8.2 | 5.1 | 1.8 (localized) |
| **Throughput @ 1% Packet Loss** (Mbps) | 312 | 278 | 381 |
| **Control Plane API Latency** (P95, ms) | 45 | 62 | 28 |
| **Architectural Model** | Traditional Client-Connector + Gateway | Global PoP Network | Anycast Network (Cloudflare) |

**Key Technical Observations:**

* **Appgate SDP** exhibits higher connection latency variability, which my tracing attributes to its gateway-centric model. The TCP handshake must complete to a designated gateway before policy is fully evaluated, adding RTT hops. Its strength lies in fine-grained, attribute-based policy controls, but this comes with a measurable (~8ms) evaluation overhead per connection attempt on the gateway side.
* **Perimeter 81** shows improved median latency due to its software-defined PoP network, reducing some geographical friction. However, under simulated network degradation, its throughput fell more sharply than Cloudflare's, suggesting less aggressive transport-layer optimizations.
* **Cloudflare Zero Trust** leverages their massive anycast backbone. The connection time (sub-100ms median) is consistently superior because the client connects to the nearest Cloudflare edge IP, and policy evaluation happens in parallel at the edge. The `cloudflared` daemon demonstrates impressive resilience to packet loss, likely due to BBR congestion control and optimized QUIC/HTTP/3 tunnels.

**Configuration Overhead & Performance Impact:**
A crucial, often overlooked aspect is the performance cost of complex policy configurations. A benchmark simulating 500 sequential access requests to different resources with unique policy rules yielded stark results:

```yaml
# Simplified test policy structure (Appgate-style example)
- action: allow
resource: ${APP_HOST}:${PORT}
conditions:
- user-group: "contractors"
- device-platform: "linux"
- time: "weekday 09:00-17:00"
```
Running this against 100 distinct rules, Appgate added ~2ms of evaluation latency per additional overlapping rule chain. Cloudflare's approach of tagging resources and users, then using lightweight access rules (Engine), showed near-constant ~1.8ms evaluation time regardless of rule count (up to the tested limit).

**Conclusion for Scale:**
For latency-sensitive, user-facing applications, the edge-based anycast model of Cloudflare Zero Trust is difficult to beat. For environments where policy complexity is paramount and resides deep within a corporate network, Appgate's model provides control at a predictable latency cost. Perimeter 81 sits in a middle ground, offering a good balance for organizations without the extreme geographic distribution or policy depth.

Further deep-dive analysis on TLS handshake overhead and memory footprint of the respective client daemons is forthcoming. The trade-off is clear: abstracted edge networking versus controlled private gateway architecture.

--perf


--perf


   
Quote