Skip to content
Notifications
Clear all

NordLayer vs Perimeter81 for a mid-market finance company

1 Posts
1 Users
0 Reactions
32 Views
(@code_weaver_anna)
Prominent Member
Joined: 7 months ago
Posts: 563
Topic starter   [#11163]

We're evaluating secure access solutions for our engineering teams at a 200-person finance company. Our core requirement is zero-trust network access (ZTNA) for developers connecting to on-premise application servers and cloud VPCs, with strong audit trails for compliance. The final shortlist is NordLayer and Perimeter81.

Our technical assessment criteria are weighted as follows:
* **Connection Reliability & Latency (30%):** Stable site-to-site tunnels and minimal overhead for developer remote access. We cannot tolerate frequent reconnection drops during market hours.
* **Administrative Granularity (25%):** Ability to define access policies based on user groups, device posture, and specific applications, not just IP ranges.
* **API & Automation (20%):** Programmatic user provisioning, policy management, and integration with our existing IaC (Terraform) and IDP (Okta).
* **Audit Logging & Reporting (15%):** Immutable logs of connection events, data transfer, and policy changes for quarterly compliance reviews.
* **Client-Side Resource Footprint (10%):** Impact on developer laptops (Mac/Windows).

From a configuration perspective, we need to replicate granular firewall-like rules. For example, a policy to allow only the `backend-dev` group to reach port 5432 on specific database servers via TCP.

```hcl
# Example of our desired policy-as-code structure
resource "access_policy" "db_dev_access" {
user_group = "backend-dev"
target_type = "application"
target = "prod-db-cluster"
allowed_ports = [5432]
protocol = "tcp"
enabled = true
}
```

Initial testing shows Perimeter81 offers more native policy constructs that map to this model, while NordLayer seems more reliant on managing static IP allow lists, which becomes cumbersome at scale. However, NordLayer's agent demonstrates a lower CPU idle footprint (~0.5% vs ~1.2% for P81 in our tests).

Has anyone implemented either solution in a regulated environment with similar automation needs? Concrete data points on API stability, the true overhead of always-on tunnels, and the practicality of their Terraform providers would be decisive.

benchmark or bust


benchmark or bust


   
Quote