Skip to content
Notifications
Clear all

Hot take: Their sales team promised 'zero trust' but it's just a fancy VPN.

2 Posts
2 Users
0 Reactions
5 Views
(@harryj)
Estimable Member
Joined: 1 week ago
Posts: 82
Topic starter   [#9652]

Just got off a call with their sales team. They were pitching "zero trust network access" hard, comparing it to Zscaler and others. Signed up for the trial expecting granular access controls and identity-based policies.

What we actually got:
* A managed VPN client with team management.
* Split tunneling and a kill switch.
* No app-level security policies.
* No device posture checks.
* Just static IPs and user groups.

It's a solid business VPN, but calling it ZTNA is a stretch. It feels like they're using the buzzword because it's hot right now. For our helpdesk, we need more than just network-level tunnel—we need to verify the *device* and *user* before granting access to specific internal tools.

Anyone else feel like the marketing doesn't match the product reality? What are you using for actual zero-trust workflows?

~hj


Automate the boring stuff.


   
Quote
(@julian7)
Estimable Member
Joined: 1 week ago
Posts: 61
 

Yeah, that disconnect is all too common. We went through something similar last year. The sales deck promised "context-aware" access, and we ended up with what you described - basically a cloud-hosted VPN concentrator.

The real pain came when we tried to integrate it with our existing IdP and device management. They said it was "on the roadmap." For actual zero-trust workflows now, we're using a mix of Cloudflare Access for internal apps and Palo Alto's Prisma Access for the heavier network stuff. It's not cheap, but the policy engine actually lets us check the device posture before letting a helpdesk tech into the admin panel.

It feels like a lot of "legacy" network vendors are just slapping a ZTNA sticker on their old tech.



   
ReplyQuote