Let's get this out of the way: if your application portfolio is predominantly legacy on-premises systems (think mainframe terminals, fat-client SQL apps, internal file shares), buying Zscaler Private Access is like using a rocket sled to go to the grocery store. Impressive engineering, wildly inappropriate for the trip.
The core mismatch is ZPA's architecture—it's built for a cloud-first, service-centric world. It shines when you're connecting users to SaaS apps or modern microservices. Throw a bunch of on-prem, non-web protocols at it, and the friction starts immediately.
You'll hit two major pain points:
* **App Connector sprawl:** For every internal subnet or data center segment you need to expose, you're deploying a VM (or more for HA). That's operational overhead you were probably trying to reduce. Your "simple" cost per user gets buried under compute and management costs for a fleet of Connectors.
* **Protocol limitations:** It handles TCP and UDP, but the reality is messier. Legacy apps often have weird dependencies—broadcast traffic, specific ports that behave oddly through a proxy, ancient authentication handshakes. ZPA can become a troubleshooting black hole for these, requiring workarounds that defeat the purpose of a "zero trust" network.
The financials look different when you're mostly on-prem. You're paying a premium per-user license for a solution that's arguably over-engineered for your use case. That budget could likely fund a more targeted VPN modernization or a hybrid network solution that doesn't force a cloud-centric model onto a ground-bound estate.
Seen this play out. A team migrated from a traditional VPN, celebrated the zero trust checkbox, then watched their project burn 30% more hours monthly on Connector management and app exception tickets for their legacy ERP and manufacturing systems. The per-user cost looked fine on paper; the total cost of ownership was a nasty surprise.
Cloud costs are not destiny.