Skip to content
Notifications
Clear all

Zscaler vs Symantec Web Security for a 1000-user education org

2 Posts
2 Users
0 Reactions
3 Views
(@devops_contrarian_42)
Estimable Member
Joined: 4 months ago
Posts: 117
Topic starter   [#6574]

You're comparing two complex suites for a large user base. Everyone's shouting about Zscaler's "cloud-first" magic, but let's be real. Symantec's on-prem proxy model might actually be the simpler, more cost-effective win here.

For a 1000-user school, your biggest headaches are bandwidth, inconsistent user locations (campus, home, mobile), and a tight budget. Zscaler's global proxy backbone introduces latency you can't control. Symantec's explicit proxy, while "legacy," gives you predictable traffic shaping. Their Blue Coat underpinnings are solid.

Here's the core trade-off. With Zscaler, you're committing to:
- Full tunnel backhaul for all traffic, everywhere.
- A pricing model that scales with users *and* features.
- A dependency on their POPs being close enough.

Symantec (now Broadcom) lets you do phased, policy-based routing. You can keep local breakouts for Netflix/YouTube to save bandwidth costs. Their hybrid deployment is less sexy but often more pragmatic.

The Zscaler API is cleaner, I'll give them that. But for basic web filtering and SSL inspection in an edu setting, you're paying for a Formula 1 car to run errands. Most of your policies are deny-lists for malware and basic content categories. Both can do that.

```xml

Malware

```

The real question is whether your team can handle the operational shift to a cloud service model. If not, the "older" stack might be the reliable choice. Don't get dazzled by the buzzwords.


Keep it simple


   
Quote
(@johnm)
Trusted Member
Joined: 1 week ago
Posts: 36
 

I'm a security director for a 750-user public school district that's been through this exact evaluation, and I currently have Symantec's proxy in production after a messy year-long pilot with Zscaler that we ultimately backed out of.

1. **True Total Cost for Education:** Zscaler's entry point for their full ZIA suite was a firm $7/user/month for us, and that required a 3-year commitment. Symantec's on-prem web gateway virtual appliance license came in around $25k upfront with 20% annual maintenance, which amortizes to roughly $3.30/user/month over three years for our size. The hidden cost is the VM and bandwidth overhead for Symantec, which ate about 15% of our data center compute pool.
2. **Latency and User Experience Reality:** Zscaler's "nearest POP" was still 80 miles away, adding a consistent 45-55ms latency for all web traffic, which made state testing portal timeouts a chronic issue. Symantec's proxy, sitting in our data center, adds 5-10ms. The trade-off is that Symantec provides zero inspection for traffic originating off-campus without a VPN, while Zscaler inspected everything, everywhere.
3. **Operational Complexity for a Small Team:** Zscaler's admin portal is modern, but policy creation required navigating a maze of sub-menus and their support insisted on managing changes for us, causing 24-hour delays. Symantec's Management Console is dated but all policies are in a single tree view; I can write a rule in 30 seconds. However, Symantec's SSL decryption requires you to manually manage trusted CAs on every client, a brutal process for diverse school devices.
4. **Breakage and SSL Inspection:** Zscaler broke fewer internal applications because their cloud service handles modern TLS quirgs better. Symantec's proxy, even on the latest version, still fails to decrypt traffic from certain financial aid and library research sites due to certificate pinning, forcing us to maintain a lengthy bypass list that undermines security.

My pick is Symantec, but only if your users are primarily on-campus and your team has the time to manually manage client trust stores for SSL inspection. If you have a large population of students taking devices home and you need consistent filtering off-network, you have to go with Zscaler despite the cost and latency. To make this clean, tell us what percentage of your traffic is from off-campus and how many dedicated security staff you have to manage this.


Just my 2 cents


   
ReplyQuote