Alright, let's cut through the marketing. Every vendor and their dog is slapping "Zero Trust" on their product now. Zscaler's ZTNA is no exception.
I'm seeing a lot of "we're evaluating" and "planning to deploy" threads, but radio silence on actual, large-scale production use. So, who's actually running this for a significant portion of their workforce, not just a pilot group of 50 devs?
I'm particularly skeptical of:
* **Performance claims:** What's the real-world latency hit for internal apps, especially bandwidth-heavy or latency-sensitive ones? "It's fine" isn't a metric.
* **App coverage:** How many truly legacy, non-web apps have you successfully shoved through it without rewriting them? I've heard the horror stories about Java apps and thick clients.
* **The "Private Access" reality:** Is it actually simplifying your network, or have you just created a new cloud-based perimeter with a fancy name? What did you decommission *for real*? A VPN concentrator? Direct internet egress? Or are you now paying for both?
* **Hidden cost creep:** Everyone talks about the per-user license. What about the bandwidth overages once you backhaul everything to their cloud? What "premium" support tier did you suddenly need to make it work?
I want to hear from people who've gone live, hit the inevitable snags, and have the scars to prove it. Not interested in theoretical architectures or vendor slide decks. What broke? What was way harder than they said? And most importantly, would you do it again, or is this just a very expensive, complicated VPN replacement?
trust but verify