3 ms·
You can have ZTN with a VPN and you can have a perimeter with ZTN. What you can't have is trust based on network position. So I think Zero Trust is fine. It's
by staticassertion 4y ago
You can have ZTN with a VPN and you can have a perimeter with ZTN. What you can't have is trust based on network position. So I think Zero Trust is fine.
It's a marketing term ultimately and any practitioner should be able to understand what it means. If they don't it's kinda on them.
- theptip 4y agoI’m not familiar with anyone in the ZTN space advocating for a need for VPNs. Do you have any examples you can share? Google explicitly positions BeyondCorp as a replacement for VPN: > BeyondCorp is a Zero Trust security framework modeled by Google that shifts access controls from the perimeter to individual devices and users. The end result allows employees to work securely from any location without the need for a traditional VPN. https://beyondcorp.com/ https://beyondcorp.com/
- staticassertion 4y agoAdvocating for a VPN or not isn't relevant. ZeroTrust isn't "no vpns". You can do ZeroTrust and have a VPN. ZTN is more about what you do than what you don't do, despite the name. 1. Clients authenticate servers 2. Servers authenticate clients 3. Communications are encrypted and auditable 4. Fine grained authorization using available context like device health You could have employees hold a client cert, connect to a VPN, have the VPN attest the employee's state, and then provide them access to a subnet. From that subnet they can continue talking to other services that also perform authn/authz. The VPN doesn't make it "less" zero trust, it's just that the traditional VPN model is one where it's the single point of auth.