3 ms·
Advocating for a VPN or not isn't relevant. ZeroTrust isn't "no vpns". You can do ZeroTrust and have a VPN. ZTN is more about what you do than what you don't do
by staticassertion 4y ago
Advocating for a VPN or not isn't relevant. ZeroTrust isn't "no vpns". You can do ZeroTrust and have a VPN. ZTN is more about what you do than what you don't do, despite the name.
1. Clients authenticate servers
2. Servers authenticate clients
3. Communications are encrypted and auditable
4. Fine grained authorization using available context like device health
You could have employees hold a client cert, connect to a VPN, have the VPN attest the employee's state, and then provide them access to a subnet. From that subnet they can continue talking to other services that also perform authn/authz. The VPN doesn't make it "less" zero trust, it's just that the traditional VPN model is one where it's the single point of auth.