Skip to content
Notifications
Clear all

Complete newbie asking: Is Zscaler a firewall replacement or just an add-on?

2 Posts
2 Users
0 Reactions
0 Views
(@cameronj)
Estimable Member
Joined: 1 week ago
Posts: 96
Topic starter   [#11641]

Having just sat through yet another vendor presentation where the terms "cloud-native," "zero trust," and "firewall replacement" were thrown around with the casual abandon of a startup's ping-pong tournament, I feel compelled to ask this from an architectural standpoint. The marketing collateral is, predictably, a masterclass in ambiguity.

My understanding, after wading through the fluff, is that Zscaler is fundamentally a secure web gateway and private access broker built as a global proxy cloud. It terminates and inspects traffic, applies policy, and can broker connections to private apps. This is a different paradigm than a stateful inspection firewall sitting at my perimeter.

So, my blunt question: When a vendor says "firewall replacement," are they talking about completely ripping out my NGFW boxes and relying solely on Zscaler Internet Access for all north-south traffic, or is this just a way to say "we handle the web and SaaS part, but you still need something to manage east-west, non-web protocols, and maybe some legacy DNAT rules"?

I'm particularly skeptical of the "replacement" claim for scenarios involving:
* Legacy applications using non-HTTP/S protocols on random ports that need IP-based ACLs.
* Data center east-west segmentation where microsegmentation is still handled by the internal firewall.
* Compliance checkboxes that still, for some archaic reason, require a "firewall" device in the diagram.

If the answer is "it's a replacement for your *outbound web proxy and VPN concentrator*," then just say that. Calling it a firewall replacement feels like a stretch designed to get the CFO's attention by promising a massive capex reduction. I want to understand the technical reality, not the sales slide.

What's the actual deployment pattern? Is anyone running a truly *firewall-less* perimeter, with Zscaler as the sole internet-facing control point, and if so, what does your network flow diagram look like for, say, an SFTP server or a VoIP system? Or is the pragmatic path a hybrid model where Zscaler handles user-to-internet and user-to-app, and a stripped-down firewall cluster handles the messy, non-proxy-friendly bits?

-- Cam


Trust but verify.


   
Quote
(@code_panda)
Estimable Member
Joined: 3 months ago
Posts: 67
 

You've nailed the core architectural difference. It's a proxy vs a packet filter.

The "replacement" claim hinges entirely on your definition of a firewall's job. If your firewall's primary role is inspecting outbound web traffic and brokering inbound app access, then yes, ZIA/ZPA can replace it. For everything else, it's an add-on.

Your skepticism about non-HTTP protocols and legacy port-forwarding is spot on. I've yet to see a clean Zscaler-only design for a factory floor with SCADA systems or an on-prem legacy app server that needs a straight NAT rule. That still screams for a traditional NGFW, or at least a very minimalist one acting as a simple router and stateful filter.


Spreadsheets > marketing slides.


   
ReplyQuote