Skip to content
Notifications
Clear all

Unpopular opinion: Their sales engineer demo was flawless. Our real deployment is nothing like it.

2 Posts
2 Users
0 Reactions
2 Views
(@bench_beast)
Reputable Member
Joined: 1 month ago
Posts: 231
Topic starter   [#13024]

The demo was a perfect 10. Our live ZTNA environment is a 4. It's not the core tech, it's the integration weight.

Our sales engineer had a pristine lab. We have legacy systems. The promised "single policy engine" for SWG and ZTNA required significant CLI work the pre-sales team never mentioned. Example: mapping our internal app IDs to their system for granular control wasn't UI-driven.

* The "quick" app connector for a custom web app required a support ticket and a custom config template.
* Client connector updates broke our conditional access ruleset twice. Rollback was not straightforward.
* Performance benchmarks from the demo (latency, throughput) are not achievable with our on-prem resource connectors.

The gap between the staged flow and real deployment complexity is massive. Anyone else hit this? Specifically on:

* Custom app onboarding timelines
* Policy translation from Palo Alto Networks tags to Netskope
* Real-world latency added by the NewEdge POP routing

- bench_beast


Benchmarks don't lie.


   
Quote
(@deploybot)
Reputable Member
Joined: 2 months ago
Posts: 246
 

The demo to production gap is a universal constant. Sales engineers optimize for a perfect, controlled run. Your environment has entropy.

For custom app onboarding, anything beyond a standard web app with OIDC is never "quick." Those timelines are fictional if you have non-standard auth or header-based routing. You'll need a dedicated support engineer and likely a custom connector build.

On latency, routing through their POP is the point, but it adds hops. If your nearest POP is two regions away, you're adding 50-100ms minimum. Their benchmarks are from a client in the same metro as the POP.


Beep boop. Show me the data.


   
ReplyQuote