Skip to content
Notifications
Clear all

iboss after 12 months - honest review from a 300-user shop

5 Posts
5 Users
0 Reactions
21 Views
(@cost_cutter_99)
Honorable Member
Joined: 6 months ago
Posts: 404
Topic starter   [#12058]

We rolled out iboss across our ~300-person company just over a year ago, moving from a more traditional web gateway setup. The pitch around "cloud security" and ZTNA was compelling, but the reality has been a mixed bag, especially on the cost and ops side.

**The Good:**
* The security posture is solid. The proxy and filtering work as advertised, and having a unified policy for on-prem and remote users simplified some of our rule sets.
* The support team is responsive, I'll give them that. Tickets don't languish.
* The DNS-layer blocking is effective and a performance win over forcing everything through an explicit proxy.

**The Not-So-Good (The Cost Ops View):**
* The pricing model feels opaque. It's per-user, but the real kicker is the commitment tier you get locked into. Scaling up mid-contract was straightforward, but they weren't eager to discuss lowering costs when we had a small reduction in headcount.
* We're primarily an Azure/AWS shop, and I found their cloud connector costs to be a bit of a black box. It's not as clear as, say, calculating a Reserved Instance commitment. The bandwidth charges for cloud connectors can add up if you're not careful with your routing.
* The admin portal, while powerful, has a steep learning curve. Simple reporting tasks sometimes require jumping through multiple modules. I've built more than a few external spreadsheets to track "actual usage vs. what we're paying for" because the built-in reports don't slice the data the way I need.

**The Bottom Line After 12 Months:**
It's a capable, secure platform. For us, the question is now about efficiency and value. The feature set is strong, but the total cost of ownership (including the internal man-hours to manage its quirks) feels higher than anticipated. I'm currently evaluating if a combination of more granular cloud-native tools (like Azure Firewall, Zscaler, or even open-source proxies) could meet our needs at a lower overall cost. The switch would be painful, but the potential long-term savings might justify it.

Has anyone else done a deep cost breakdown comparing iboss to other ZTNA/SWG solutions at this scale? I'm particularly interested in how others are tracking and allocating the cloud infrastructure costs iboss introduces.



   
Quote
(@josephr)
Trusted Member
Joined: 3 months ago
Posts: 29
 

Oh, the pricing and cloud connector piece is so real. We went through that same "per-user, but also per-connector, and what about bandwidth?" fog. It really hit us when we started pushing more internal app traffic through the connectors for ZTNA - the egress costs from AWS weren't trivial and felt disconnected from the per-user license we thought we were buying.

We built a little dashboard just to track the cloud connector utilization versus our bill, which helped us right-size the deployment after the fact. But I agree, it's an exercise you shouldn't have to do. The initial sales demos definitely glossed over the cloud infra side of the equation, making it sound like it was all bundled into the seat license 😅

Did you also find their reporting made it tough to attribute costs back to specific teams or projects? We struggled with that for chargeback.


—jr


   
ReplyQuote
(@connork)
Reputable Member
Joined: 2 months ago
Posts: 216
 

Yeah, the pricing stuff hits home. We're about half your size, but we saw the same thing with headcount reductions. They were very "the contract is the contract" when we tried to adjust. Makes you feel locked in.

The cloud connector cost opacity is worrying. We're not as deep in Azure yet, but planning to move more that way. Did you find any tricks for keeping those bandwidth charges predictable, or is it just constant monitoring?



   
ReplyQuote
(@cloud_migrate_tom)
Reputable Member
Joined: 6 months ago
Posts: 290
 

Yeah, the "contract is the contract" part is what makes me nervous. We're looking at a move to Azure next year, and hearing that about the cloud connectors is really concerning.

Is the monitoring you mentioned something you have to build yourself, or did you find a tool that could tie the bandwidth back to the iboss usage clearly? We're a smaller team and I'm worried we won't have the cycles for a custom dashboard.


One step at a time


   
ReplyQuote
(@isabelr)
Estimable Member
Joined: 2 months ago
Posts: 59
 

Monitoring cloud connector costs is the part they don't put on the shiny sales slides. For a smaller team, building a custom dashboard is a brutal ask on top of managing the thing.

We tried a couple cloud cost tools, but none cleanly mapped egress spikes back to iboss activity. You end up correlating timelines manually, which is a hobby nobody signed up for. The predictable cost trick? Honestly, it was treating our cloud connectors like a scarce resource and routing only absolute must-have traffic through them, which kind of defeats the "zero trust for everything" pitch, doesn't it?


Trust but verify – especially the audit log.


   
ReplyQuote