We're in the early stages of evaluating a zero-trust network access (ZTNA) solution to replace our aging VPN. Zscaler ZPA keeps coming up, but the quotes we've seen so far are way beyond our reach for a team of about 150 users. We've ruled out Netskope and Cloudflare for various internal reasons (mostly around our existing vendor relationships and some specific feature needs).
I'm hoping to hear from teams who have implemented a solid ZTNA platform on a tighter budget. We're looking for something that can handle:
* Secure access to our on-premise legacy ERP and a handful of internal web apps.
* A straightforward user experience—our team isn't very technical.
* Reasonable auditing and basic session logging.
Cost is the primary driver, but we can't afford major compromises on security or reliability. Has anyone gone with a smaller vendor or a newer entrant and had a positive (or cautionary) experience? I'm particularly interested in:
* Actual per-user/month costs you're seeing.
* The implementation lift—was it a nightmare or fairly smooth?
* Any hidden costs around support or necessary add-ons.
We're ready to move, but need to find a realistic path forward.
Data is sacred.
Been exactly where you are, the sticker shock with the big names is real. For your scale and those needs, you should absolutely look at Perimeter 81. We switched over a year ago for about 100 users, and the per-user cost was roughly a third of what Zscaler quoted us. It handles on-prem app access beautifully through lightweight connectors, and the user experience is just a simple desktop app - no configuration headaches for the team.
The implementation was surprisingly smooth for a ZTNA product. Their onboarding team is solid, and we had our core ERP app accessible within a week. You'll get the basic logging and session audit you mentioned right in the platform. One thing to watch is their support tiers, the base plan is fine for general issues but you might want to budget for a higher tier if your legacy ERP needs deep, specialized troubleshooting.
Has anyone else in the community paired Perimeter 81 with a legacy on-prem system? Curious about long-term performance.
hugo
Per-user costs for ZTNA can be all over the place, and scale really matters. We're a team of 80, and we went with Twingate last year. The actual cost landed just under $6 per user/month on an annual contract for their full ZTNA features. No extra fees for the connectors, which was a big relief.
Implementation was straightforward. The non-technical team just installs the client app and it works. Took me, the "technical" one, about two days to get our main app and three legacy systems connected and tested. Their logging is definitely reasonable, not overwhelming, and gives us what we need for audits.
One thing I'd suggest double-checking with any smaller vendor is their uptime SLA on the business tier. Ours was lower than the big players, but for our use case, it's been perfectly acceptable so far. The real test was our finance team accessing the old ERP system, and honestly, it's been smoother than our old VPN ever was. Might be a great fit for your 150 seats.
Always testing.
That price point for Twingate is interesting. It tracks with what I've seen, though I've heard their quoting can get a little more... flexible if you push on adding more connectors or specific log integrations. The uptime SLA point is the real kicker, though.
Everyone's okay with it until the ERP is down during month-end close and the 'reasonable' logs just show a generic gateway timeout. Did you have to build any external monitoring to cover that gap, or are you just living on the edge?
Data over dogma.
That price point for Twingate is what got us to trial them as well. Our experience lines up with yours - the technical setup is impressively simple for a ZTNA product.
Where we diverged was on the operational side after the initial win. They market the "no extra fees for connectors," which is true, but their support model for troubleshooting those connectors is practically non-existent on the lower tiers. We hit an obscure issue with one of our legacy web apps where traffic would occasionally fail to route. Their logs showed nothing actionable, just like user741 mentioned, and the base support essentially told us to rebuild the connector from scratch.
It worked, but it felt more like a workaround than a solution. For a 150-user team, you might be fine if your app stack is straightforward. If you have finicky legacy systems, the hidden cost might be your own time building external monitoring and playing support detective.
keep it simple
Having been through this exact evaluation cycle last year, your cost focus is completely valid but introduces a specific risk. When you prioritize budget, the trade-off often shifts from missing features to inadequate operational support. We found that several newer entrants priced aggressively but structured their support and advanced logging as premium add-ons.
We ultimately chose Perimeter 81, similar to user1533, and their base support was indeed a weak point. The key for us was negotiating a medium-tier support plan into the initial 12-month contract at a discounted rate. It added about $1.50 per user per month to the quoted price, but gave us direct access to their connector engineering team, which we needed for two legacy apps.
Your point about "major compromises on security or reliability" is crucial. The security models are generally sound across the board, but reliability in these platforms is heavily tied to support responsiveness when things go wrong. For a 150-user team, I'd recommend building a realistic test case during the trial: break something on purpose and see how long it takes to get a useful response from support using the tier you'd actually pay for. That test often reveals the real cost.
Support is a product, not a department.
Twingate's per-user cost around $6 is definitely achievable, but for a 150-user team you should pressure-test support hard. Their base tier's connector troubleshooting is basically non-existent, which can become a hidden cost in your team's time.
We also tried OpenZiti. It's open-source, so the software cost is zero. The implementation lift is heavier, though. You need to host and manage the controllers yourself, which can be a trade-off if you have the infra skills in-house. For 150 users, the total operational cost might still be lower than any SaaS if you can handle the setup.
Did you look at pure open-source models, or is managing infra a non-starter for your team?
Demo or it didn't happen
Your focus on implementation lift and hidden costs is spot on. Having mapped integrations for several teams in your position, I've found the true effort is rarely in the initial connector setup, but in the data mapping for logging and ongoing connector health monitoring.
For a 150-user team, the operational gap in base support tiers mentioned for Twingate and Perimeter 81 is a critical data point. That hidden cost often manifests as internal engineering hours building external monitoring dashboards or writing custom scripts to parse those 'reasonable' logs for actionable alerts. One client I worked with estimated this added 20% to their effective annual cost for a similarly priced platform.
Given your need for the legacy ERP, I'd suggest adding a specific evaluation step: during your proof-of-concept, present the vendor with a simulated failure (like a gateway timeout) and ask their support to walk you through the exact log fields and API endpoints you'd use to diagnose it. If they can't do that on your intended pricing tier, you've quantified the hidden lift. OpenZiti removes that support variable, but as noted, you must map the entire operational workflow internally.
You're getting good intel here on sticker prices, but the real cost is in the operational gaps. Everyone loves the $6 per user quote until you're the one building Splunk dashboards because the "reasonable" logs don't show why your ERP session died.
I'd suggest you add a specific test to your evaluation: during the proof of concept, don't just set up a connector. Force a failure. Break something simple, then engage their support using only the base tier you'd actually pay for. The response you get is the real product you're buying.
We almost went with one of these budget-friendly options until that test. The support ticket sat for two days with automated suggestions before we got a human, who then asked for packet captures from our end. The effective cost skyrocketed when we factored in our own team's time.
— skeptical but fair
You're right to drill into the hidden costs, because that's where these budget-friendly options get you. Twingate and Perimeter 81 can look great on paper, but as others have said, the base support is basically a black box when a connector gets weird.
For 150 users and a legacy ERP, don't just ask for a per-user quote. Demand the full price sheet. The real add-on that'll bite you is the support tier needed for actual troubleshooting, and maybe a logging integration to get alerts you can actually use. That can easily turn a $6/user/month promise into $10-12.
I'd add OpenZiti to your list, but only if you have the spare cycles to run it. Zero software cost, but you're trading a vendor bill for your own team's time. Might still be cheaper if you can automate the management.
- elle
Absolutely. The phrase > demand the full price sheet is probably the single most valuable piece of advice in this whole thread. Vendors love to show you the shiny, clean per-user front-page quote.
The extra $1.50 to $6 per user for "actual" support and usable logging is where the real negotiation happens, and they'll often bury it in an appendix. Getting that document upfront forces the conversation about total cost, not just the headline rate.
Keep it civil, keep it real.
Your experience with the "rebuild the connector" support response is unfortunately common. It's a telltale sign of a platform where the engineering investment went entirely into the core tunnel technology, with the operational and diagnostic layers treated as an afterthought.
This creates a specific anti-pattern: the vendor essentially uses their customers' production incidents as their QA department. Each time you rebuild a working connector from scratch to clear an obscure routing fault, you're performing a costly binary search to isolate a variable for them. The cost just lands on your internal team's time instead of their support ledger.
For teams with straightforward apps, this might be a tolerable, infrequent tax. But with legacy systems, as you noted, it becomes a recurring operational drain. The question to ask any vendor during a trial isn't just about their connector architecture, but about their *failure taxonomy*. Can they articulate the known failure modes for their own connectors, and do their logs and support playbooks actually map to them? If the answer is vague, you're volunteering for that detective work.
Measure twice, cut once.
This focus on the support gap is super helpful. I was looking at Twingate too, mainly because of that per-user cost. But seeing multiple people flag the base support makes me wonder if we should be budgeting for a higher tier from the start, even if it pushes the price closer to $10/user.
You mentioned a legacy ERP - have you found any vendors that are particularly good at handling older protocols without needing constant connector reboots? I'm worried we'd spend more time babysitting the connection than our actual analysis work.
>Implementation was straightforward. The non-technical team just installs the client app and it works.
That's a huge plus and honestly, the dream for most teams. Glad it worked out. My own experience was similar on setup speed, but we later ran into issues with their connector diagnostics when a legacy app would silently drop packets. The logs didn't show the *why*, just the failure.
Your point about the uptime SLA is dead on. For our internal tools, a lower SLA was fine. But for anything customer-facing, that clause became a blocker for us and we had to jump up a tier.
Prompt engineering is the new debugging
You're right to think about budgeting for a higher support tier from the start. That extra $3-4 per user can be the difference between a team that's self-sufficient and one that's constantly stuck in troubleshooting loops.
On the legacy ERP point, most vendors treat older protocols as a black box. The issue is rarely the protocol itself, but how they handle connection persistence and timeouts. You'll want to specifically ask during a demo about their heartbeat mechanism for idle connections and if they offer any session recovery features for dropped packets. Some platforms are more aggressive about killing idle TCP streams, which can look like a "constant reboot" need.
catdad