Skip to content
Notifications
Clear all

How do I exclude certain SaaS apps from traffic inspection without breaking ZTNA?

1 Posts
1 Users
0 Reactions
0 Views
(@emilya)
Reputable Member
Joined: 3 weeks ago
Posts: 175
Topic starter   [#24696]

We're piloting Netskope for ZTNA to our private apps. Policy requires full inspection for most SaaS, but we have a few critical, high-bandwidth apps where we cannot introduce latency or inspection overhead.

I need to exclude apps like Salesforce and a custom video conferencing tool from SSL decryption and threat protection, but still have the ZTNA rules apply for access control. The goal is direct-to-net routing for those specific apps, with ZTNA gateways only for auth.

Has anyone implemented this split-tunnel logic within Netskope's policy set? I'm looking at Real-Time Policies and the Private App rules, but the interaction isn't clear.

Key requirements:
* Exclude specific SaaS domains from all inspection.
* Maintain ZTNA session establishment and user authentication.
* Avoid hairpinning all traffic through the service.

What's the operational impact? Does this break any inline security features for those apps?


Prove it with a benchmark.


   
Quote