Having recently completed a SOC 2 Type II audit for our environment, the topic of granular, application-layer visibility for all our network segments—especially those handling sensitive customer PII/PHI—is very much top of mind. We currently utilize a next-generation firewall from a major vendor at our perimeter, but its internal zoning policies and user/application reporting for east-west traffic have always felt a bit cumbersome and license-heavy to manage at scale across all our internal segments.
This led me to investigate Zenarmor (formerly Sunvalley) as a potential layer to augment visibility and policy enforcement on existing internal firewalls, which are a mix of hardware and virtual appliances. The promise of a lightweight, agentless layer providing deep application identification, DNS filtering, and detailed logging without a full forklift upgrade is appealing from a compliance standpoint.
My primary questions for the community revolve around real-world deployment in regulated industries:
* **Logging Integration & Fidelity:** The cornerstone of any compliance framework (SOX, HIPAA, GDPR) is immutable, detailed audit trails. How does Zenarmor's logging, particularly for its application control and web filtering categories, hold up when ingested into a SIEM like Splunk or Datadog?
* Are the log fields (user, application, category, policy action) consistently populated and parsable for correlation?
* Does it provide sufficient detail to satisfy an auditor's request for "evidence of restricted application blocking" on a segment housing policyholder data?
* **Policy Granularity & Exceptions:** For a typical insurance workflow, we need to allow a core set of SaaS and internal applications but restrict high-risk categories (anonymizers, peer-to-peer, etc.). Can Zenarmor policies be tuned finely enough to, for example:
* Allow `Microsoft 365` but block `Microsoft 365.Teams.FileTransfer`?
* Create safe-search enforcement for `Google` but allow `Google.Docs`?
* How manageable is the exception process for one-off business justification cases? Is it traceable within the product itself?
* **Deployment Model Concerns:** The "engine" deployed on existing firewall hardware is an interesting model. In a high-availability pair, how is state synchronized? More critically, from an audit perspective, how are the policy and configuration themselves backed up and version-controlled? Can changes to the Zenarmor policy be tied to a specific administrator with the same rigor as our primary NGFW?
I've done a lab deployment on an OPNsense box, and the initial visibility is impressive. A sample of the live session log shows the detail I'm referring to:
```
session_id: 5503e8b1
timestamp: 2023-10-27T14:22:15Z
interface: em0
src_ip: 10.50.1.45
src_user: DOMAINjdoe
dst_ip: 172.217.16.206
dst_host: google-docs.l.google.com
application: Google.Docs
category: Cloud.FileSharing
policy_action: allow
bytes_sent: 12450
bytes_received: 784221
```
This level of detail (user, specific application, host) is exactly what we need. However, moving from a lab to a production environment handling sensitive data requires vetting the operational and compliance nuances. Has anyone here, particularly in financial services or insurance, deployed Zenarmor beyond a testing phase? Was the depth of the audit log sufficient, and did the management overhead scale acceptably?
Logs don't lie.