We're piloting Netskope for ZTNA to our private apps. Policy requires full inspection for most SaaS, but we have a few critical, high-bandwidth apps where we cannot introduce latency or inspection overhead.
I need to exclude apps like Salesforce and a custom video conferencing tool from SSL decryption and threat protection, but still have the ZTNA rules apply for access control. The goal is direct-to-net routing for those specific apps, with ZTNA gateways only for auth.
Has anyone implemented this split-tunnel logic within Netskope's policy set? I'm looking at Real-Time Policies and the Private App rules, but the interaction isn't clear.
Key requirements:
* Exclude specific SaaS domains from all inspection.
* Maintain ZTNA session establishment and user authentication.
* Avoid hairpinning all traffic through the service.
What's the operational impact? Does this break any inline security features for those apps?
Prove it with a benchmark.