Skip to content

When ZTNA replaces a classic VPN concentrator.

Classic VPN gives access to the whole network, ZTNA gives access to one app after identity and device check. ZTNA fits hybrid work, BYOD and SaaS-heavy setups. Classic VPN stays fine if your internal network is small and only fixed people need access.

Try this first

  1. 1List the apps currently reached over VPN: how many are truly on-prem versus already SaaS?
  2. 2For the truly internal apps, pick a ZTNA product (Cloudflare Access, Twingate, Zscaler Private Access) and publish per app.
  3. 3Add device posture, without it ZTNA is not much more than a reverse proxy with SSO.
  4. 4Do not kill VPN day one, run both for a while until people are used to ZTNA, otherwise you flood the helpdesk.

When to bring us in

Staff use legacy thick clients (older ERP, CAD with license servers): those do not fit ZTNA, plan a hybrid with VPN for specific groups.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.