Skip to content
Step-by-step: Isola...
 
Notifications
Clear all

Step-by-step: Isolating a vendor subnet with ZTNA policies.

1 Posts
1 Users
0 Reactions
1 Views
(@emmab5)
Eminent Member
Joined: 1 week ago
Posts: 33
Topic starter   [#13720]

Hi everyone! I'm pretty new to ZTNA concepts, coming from a project management tool background. We're looking at tightening security for some third-party vendors.

I understand the basic idea of "never trust, always verify," but I'm fuzzy on the actual steps. If I want to isolate a vendor subnet so they can *only* reach one specific application server, what does that policy really look like? Is it more about defining the user/device identity, the application, or both?

Do you usually create a policy that says "Vendor Group" can only access "App Server A" and block everything else by default? How granular do these policies get? Any gotchas to watch out for? 😅

Thanks for helping a newbie connect the theory to the practical setup!



   
Quote