A classic VPN hands over the whole network. What Zero Trust Network Access does differently, what migration costs, and when it is not worth it.
VPNs spread because they are simple: the remote user works as if sitting in the office. That is precisely the problem. If a laptop is compromised, the attacker also works as if sitting in the office.
| Classic VPN | ZTNA | |
|---|---|---|
| What it grants | Network access | Application access |
| Default | Inside, therefore trusted | Every request evaluated individually |
| Visibility | Applications visible on the network | Only what you are entitled to |
| Device posture | Typically irrelevant | Part of the decision |
| Logging | At connection level | At application and action level |
The essential difference: after VPN the user is on the network; after ZTNA they are at a specific application. What is not explicitly permitted is not even visible, so it cannot be discovered.
When there are many third parties. Suppliers, contractors, maintenance providers. Giving them VPN means giving them visibility into the network. With ZTNA they see only what they must work on.
When cloud applications dominate. A VPN routes traffic to the datacentre and onward to the cloud, an unnecessary detour. ZTNA permits direct but verified access.
When you want device posture to matter. An unmanaged machine should not receive the same access as a corporate one.
When the VPN concentrator is the bottleneck. In many organisations it has been the most loaded element since remote work became normal.
When legacy, non-HTTP applications dominate. A significant share of ZTNA products is optimised for web protocols. Support for older client-server applications is uneven.
When identity is not in order. ZTNA rests on identity. Without central authentication and MFA, migration solves nothing and merely costs more.
When the OT network is the target. Industrial supplier access needs different tooling: jump servers, session recording, on-demand activation. We covered this in our ICS/SCADA article.
1. Application inventory. What do users reach over VPN today? In practice the list is shorter than expected and full of things nobody uses any more.
2. Start with one application. A well-bounded web application with a smaller user group. This is where the organisation learns the pattern.
3. Third parties second. Risk reduction is greatest here and user resistance lowest, because the process is new to them anyway.
4. Parallel operation. Keep the VPN live until ZTNA covers the main use cases. Switching it off should be a deliberate decision, not a forced one.
5. Retiring the VPN. This often drags on for years because of legacy applications. While a VPN exists, MFA and segmentation are needed there too.
ZTNA does not replace endpoint protection. If the machine is infected, ZTNA admits an infected machine to the application.
Configuring logging. One of ZTNA's biggest advantages is detailed logging, but it does not reach the SIEM by default. We covered this in our logging article.
Availability. The ZTNA gateway sits on a critical path. If it fails, nobody works. It needs redundancy and a tested failure scenario.
We covered the broader architectural questions in the Zero Trust guide.
Comprehensive IT security services including firewalls, WAF, IPS, SIEM, DLP and endpoint protection from…
How to turn Zero Trust principles into real steps: identity, device posture, micro-segmentation and least…
SMS, app codes, push, hardware keys: what each method protects against and what it does not, where to…
Our specialists are happy to discuss what this means in your organisation's environment.