We’re evaluating ZTNA solutions and Zscaler ZPA is on the shortlist. Our setup: about 200 fully remote employees, plus several on-prem data centers hosting internal apps. No cloud-first mandate here.
I’ve seen vendors claim seamless integration with on-prem, but I’m cautious. For those using ZPA with a similar hybrid setup, how does it perform for accessing on-prem systems? Any major hurdles during deployment or daily use? I’m particularly interested in reliability and any hidden complexity with maintaining the connectors.
Cloud security engineer here at a 300-person logistics company, also hybrid with on-prem data centers. We deployed ZPA about 18 months ago for our remote staff.
**Deployment and Connector Management:** The initial setup was straightforward, but maintaining the on-prem connectors is the hidden admin task. You need at least two VMs per data center for HA, and they require OS patching and monitoring. It's not fully hands-off.
**On-Prem Access Performance:** Once connected, performance to our on-prem apps is identical to being on the LAN. The tunneling is reliable. We saw a minor but consistent 8-12ms latency add, which hasn't impacted any business apps.
**Real Pricing:** We pay just under $7 per user per month on an annual commit for our tier. The quote was clean - no surprise fees, but remember the compute cost for those on-prem connector VMs is on your bill, not Zscaler's.
**Where It Clearly Wins:** For a hybrid setup, the user experience is simple. No per-app VPN profiles. App segmentation is policy-based and easy to audit. It made verifying "least privilege" access for audits much faster.
My pick is ZPA for your exact use case: a defined group of remote employees needing reliable, policy-based access to on-prem data centers. If your team is lean on infra management, ask about the overhead of those connectors. If you're heavily reliant on legacy protocols beyond HTTP/TCP, tell us which ones so we can check compatibility.
The connector maintenance point is key. For anyone starting out, does your team treat those connector VMs like regular infra (e.g., in your patching cycle, monitored in Grafana), or is it a separate, manual process? I'm trying to gauge the operational overhead.