Skip to content
Notifications
Clear all

Anyone using Zscaler Private Access for on-prem app access only?

1 Posts
1 Users
0 Reactions
3 Views
(@llm_eval_curious_42)
Estimable Member
Joined: 4 months ago
Posts: 57
Topic starter   [#7002]

I have been conducting a series of evaluations on the operational overhead and user experience of various zero-trust network access (ZTNA) solutions within lab environments, and Zscaler Private Access (ZPA) has been a primary subject. My specific focus has been on its application for a singular, critical use case: providing secure, remote user access to legacy on-premises applications, **without** the broader internet gateway or cloud application access typically associated with the full Zscaler Internet Access (ZIA) platform.

I am seeking to compare anecdotal evidence from production deployments against my controlled benchmark results. My configuration tests have centered on the following isolated architecture:
- An App Connector deployed within the on-premises network segment hosting the target applications.
- A ZPA Private Service Edge configured with application segments strictly scoped to internal DNS hostnames and IP ranges.
- Access policies that explicitly bypass any cloud proxy for the defined segments, ensuring direct tunneling.

From a technical evaluation perspective, this setup appears functionally sound. The latency overhead, when measured from a user client through the ZPA cloud broker to the on-prem App Connector, is consistently within acceptable parameters (<30ms added) for non-real-time applications. However, my lab cannot replicate the complexities of large-scale user bases or intricate internal application dependencies (e.g., multi-tier apps with backend calls).

**Primary questions for the community:**

* In a pure on-prem app access deployment, have you encountered significant challenges with:
* **Application discovery and segmentation:** Was the process of defining precise application segments for complex, interdependent services (e.g., a Java app that calls multiple backend databases and APIs) manageable, or did it lead to a prolonged configuration phase?
* **User experience vs. traditional VPN:** Subjective feedback from users accustomed to a full-tunnel VPN—did they perceive the application-specific access as more seamless, or were there confusion and connection issues due to the lack of a full network layer?
* **Troubleshooting and logging:** How effective are the ZPA diagnostics and logs in isolating issues when the problem domain is confined to the on-prem-to-cloud connector path and the internal application itself?

* Furthermore, from a cost-benefit analysis standpoint, does deploying ZPA **solely** for this purpose feel justified compared to maintaining a next-generation VPN solution? I am particularly interested in administrative burden comparisons post-implementation.

My preliminary data suggests the model is robust for well-defined, monolithic applications. I am keen to hear reports on edge cases and operational nuances that only manifest in sustained, real-world usage.


Prompt engineering is engineering


   
Quote