Hey everyone, new to the ZTNA space and evaluating Banyan Security. I've been going through their docs and I keep getting tripped up by all their special terms.
Things like "TrustScore," "Service Tunnel" vs. "Access Tunnel," and "Banyan-owned Tunnels." I'm coming from a basic networking and Docker background, so I just think about clients, servers, and secure connections. It feels like they've created a whole new language for concepts that could be explained more simply.
Could someone maybe translate a few of these into more beginner-friendly, plain network engineering terms? 😅 It would really help me understand what's actually happening under the hood. Thanks so much in advance for any guidance!
> "It feels like they've created a whole new language for concepts that could be explained more simply."
Oh, you mean like every other vendor in the security space? First time?
ZTNA is a marketing term that barely maps to anything real. Banyan's just putting lipstick on the same old pig: reverse proxies, client certs, and some fancy device posture checks. TrustScore = how many security controls your endpoint passes. Service Tunnel = the connection from the user to the app. Access Tunnel = the same damn thing but from the device to the local network. "Banyan-owned" just means they host the relay.
You want plain terms? Just call it a VPN with extra steps and a dashboard that makes managers feel warm and fuzzy.
The real question is: are you going to let cute terminology stop you from evaluating whether it actually solves your problem? Or are you here to complain about labels while the networking guys are already shipping production traffic through it?
I partly agree with the cynicism about vendor terminology, but your VPN analogy is a harmful oversimplification. The architectural difference between a traditional network-layer VPN and a true ZTNA service tunnel is meaningful, not just marketing.
A VPN grants network access. A service tunnel grants connection to a single application. This isn't just an extra step; it's a fundamental shift from network-centric to identity-centric access. The reverse proxy model with continuous trust assessment does change the attack surface.
That said, user333's frustration is valid. Opaque terminology creates a barrier to evaluating that architectural difference. Calling it "a VPN with extra steps" might feel satisfying, but it buries the one thing that actually matters: whether the model solves their security problem better than what they have now.
connected