Skip to content
Notifications
Clear all

Switched from Citrix Secure Access to Netskope ZTNA. The network team is happier.

3 Posts
3 Users
0 Reactions
45 Views
(@devops_rookie_22)
Honorable Member
Joined: 7 months ago
Posts: 311
Topic starter   [#11205]

Hi everyone! I'm pretty new to the networking side of DevOps, but our team just finished a big switch from Citrix Secure Access to Netskope ZTNA. I was mostly watching the network engineers, but their relief was super clear.

The main win seems to be how it handles access. With Citrix, it felt like everything was an all-or-nothing VPN tunnel. Netskope lets them set rules based on the app or data itself, which they say is way more granular. They also mentioned the admin console is simpler to use. No more complex gateway configs for every little internal tool we need to expose.

I'm still learning a lot about ZTNA concepts. Anyone else made a similar move? Curious about how it changed your day-to-day workflows, especially for someone like me who's more comfortable with containers than network policies! 😅



   
Quote
(@andrewb)
Reputable Member
Joined: 3 months ago
Posts: 292
 

Staff engineer at a SaaS company, ~250 users, full remote. I ran both products across two different jobs.

1. Target audience: Citrix is legacy enterprise, full of orgs with on-prem Active Directory that can't move. Netskope skews mid-market cloud-first. The ZTNA features feel grafted onto Citrix, while Netskope was built around it.
2. True cost: Netskope's sticker shock is real. Citrix Secure Access is ~$12/user/month bundled. Netskope ZTNA alone starts at ~$8 but you'll need their SWG and CASB for the real value, pushing it to $18+. Netskope wins on operational overhead, Citrix wins on predictable licensing.
3. Performance hit: For app-specific access, Netskope is faster because it's not tunneling all traffic. But for full-device, always-on, Citrix's tunnel was more stable in my last shop. Netskope's client had more random dropouts requiring restart.
4. Support quality: Both are bad, but in different ways. Citrix support is slow but follows a script. Netskope support is faster but you'll get a different answer each time. Escalations are painful with both.

If you're cloud-native and your team already knows SaaS consoles, Netskope. If you have legacy apps or need full-tunnel for certain use cases, Citrix. To make a clean call, tell us your mix of legacy vs. cloud apps and whether you need 24/7 device tunneling or just per-app access.


—aB


   
ReplyQuote
 amyt
(@amyt)
Reputable Member
Joined: 3 months ago
Posts: 221
 

You nailed the big shift! Moving from that all-or-nothing VPN tunnel to app-level access is huge. Our security team loves the same granularity you mentioned.

From my side, I saw an immediate boost in Salesforce and analytics tool performance for our remote sales team. They're not hauling a useless tunnel of personal traffic around anymore. The network folks get control, and we get speed.

Curious, have you noticed any workflow changes for your devs yet? I'm betting that simpler admin console means less time waiting on network tickets for new app access.



   
ReplyQuote