Appliance and proxy-based architecture. A reverse proxy appliance (the SDP connector) is deployed at the network edge and governed by a centralised policy-based controller.
Usually based on Single Packet Authorization (SPA). Often agentless for the client (initiating host). May not require a separate SDP connector appliance if the SDP Connector software is deployed directly to the target system(s).
Agent based architecture. Devices talk directly to one another coordinated by centralised policy-based management. Direct connections between cooperating systems are established using outbound-only traffic and a combination of device and user identity, UDP & TCP hole punching and NAT traversal techniques together create fast, end-to-end encrypted tunnels between connected systems from behind closed firewalls.
Some NAT configurations prevent the direct connection establishment, in such cases traffic relays are used to ensure a connection can be made.
Users and protected applications establish outbound connections to an access broker, which evaluates policy and mediates authorised sessions without exposing the private network.
The broker may be vendor-operated or self-hosted. Depending on the product and protocol, it may terminate and proxy the session or relay traffic through an application-side connector.
End-user access may be agentless. Vendors commonly also provide Cloud Access Security Broker (CASB) and Secure Web Gateway (SWG) functions complimentary to ZTNA.
Agent-based architecture. Vendor's product centrally manages credentials for access to target servers.
Long-lived end-user credentials are authorized and authenticated before being transparently swapped out for unique, often single-use or limit-limited credentials which grant temporary access to target servers. Some vendors may offer protocol aware features like session recording and playback.
Products often assume different all areas of the network be connected and routable such that clients have a network pathway available to reach target servers.
Agent or remote-management based architecture. Vendor manages host-based firewalls built into device operating systems to control access. Centralised policy-based controller coordinates updates to each firewall.
Products often require different areas of the network be connected and routable for any kind of traffic, and ACLs are enforced by host-based firewalls instead of perimeter devices to micro-segment networks which might otherwise be flat.
Agent based architecture. All traffic traverses network relays coordinated by centralised policy-based management.
Some vendors offer hardware devices to transparently connect devices to the network.
Thank you!
Wonderful, thanks for subscribing. Please check your email and click on the confirmation link to verify your subscription.
We'll keep you updated
Thanks for helping to support this project by subscribing, we'll let you know when new vendors or content are added.
Something went wrong
Sorry, we encountered a problem trying to add you to our mailing list. Please try again!