Transcription
[Music]
What's up, best friends? My name is Brian D, and today we'll be covering all things ZCL private access related. A lot of new nuggets in this bad boy, so please don't fast forward; you might miss something.
The goal of private access is simple: we want to connect any user from any device to any application, regardless of location. Simple as that. We want to keep those users off the network because users on the network is yucky. We don't like to do yucky things.
There are really three core things that I kind of stand on. Number one, I have to deliver an exceptional user experience. Number two, by doing so, my goal here is to reduce your attack surface. Your attack surface is massive. I want to hide things back behind the zero trust exchange. And last but not least, three, I want to help eliminate lateral movement.
So let's see what this looks like. Let's connect the dots. We got the Zcar cloud; I write ZTE for short. For privileged users, it's the same thing that you're already used to. We have our Zare client connector that sends traffic up to the Zare cloud. Work from anywhere means a general user coming in from home, Starbucks, abroad, doesn't really matter. Heck, even in the office, they're going to have an agent that is always running, following them regardless of their location.
From a third-party perspective, yes, you can install an agent, but like, why? Why would you want to do that? Why would you want to inconvenience these people? So instead, we're going to come over here and say, "Hey, you can connect, but from any monitored web browser." So we call that cloud browser isolation.
Now, your ATT attack surface is huge. Our goal here is to reduce the attack surface because if it's reachable, it's reachable. So we come over here in the factory; we have a branch connector that gets deployed, and it has that application adjacency. You can talk to these internal applications because it's sitting there on the inside of the network. But the inbound ACL to this thing is an NE any deny. There is no inbound ACL.
So what we do is we have this thing kind of phone home to the zero trust exchange. Simple as that. Now, these core principles follow us in GCP, Azure, and AWS. So we'll deploy our little app connectors here, and they have application adjacency. They can talk to these internal applications, and then it phones back home the exact same way as it would at the factory. Little squeaky, but that's okay.
Then the same core principles follow us over here to the data center. So we have our app connector; they can talk to these applications internally, and again, it's going to reach outbound to the zero trust exchange and not be listening on anything. That inbound ACL isn't any any denied.
So we're taking our applications, hiding them back behind the zero trust exchange, helping minimize that attack surface. But there's also kind of an internal attack surface, and this is where AI comes in. We can look at your policy and say, "Hey, for application 2, right now the policy is written that maybe 10,000 people can talk to it." But since we understand the identity of the user, the departments, groups, and locations, we can help narrow that down.
So AI is going to come in and suggest some policy recommendations and say, "Hey, application 2, instead of being open to 10,000 people, maybe we can take that down to 75." I think we can all agree less access is a better thing.
Now, when we also look at some features that you've been asking for, Voice over IP is a big one. So you asked for it, you got it. Think of Voice over IP or maybe server traffic coming in; we can now support this. So we have our little Zare network connector that's going to be coming in, a separate VM that lives on-prem. It talks to VoIP, and again, it's reaching outbound to the zero trust exchange.
So from a VoIP perspective, whether users are in the office or working from anywhere, they can make and receive phone calls with ease. No third-party VPN needed. From the office perspective, I know what you're thinking: "Brian, it would be crazy if I have an agent to send that traffic from here all the way up, then back down."
So what we've introduced here is the private service edge, which is the ZTE running on-prem, PSSE. What we're trying to do is help minimize that attack surface because I'm taking a user, putting them on the network, and I already said that's yucky.
So what I want to do is reduce that attack surface and minimize that lateral movement and say these users, when they're on the network, the only thing they can talk to is the private services. The private service edge works the exact same way as this; this thing phones home. It also talks over here to the private service edge.
Now, when I'm on the network, if my goal is I'm only allowed to talk to application 2 when I'm off the network, then when I'm on the network, even though I have layer 2 adjacency, the only thing I can talk to is application 2.
Another big one is around B2B. You have these third parties coming in. Normally, you have a site-to-site VPN IPC tunnel between these two entities. You have firewalls; they have firewalls. It's a mess. You have to maintain them. We heard you.
So now you can allow these third-party entities to initiate an IP SE tunnel to the zero trust exchange to help us further roll out that zero trust messaging. Right there is no connectivity between here; there's no implicit trust. We're going to be looking at workloads, users, and applications all the same.
Next is some feature parity around ZIA. I'm sure a lot of people would be very happy to hear about this around cyber threat protection, which means you get DLP, SSL inspection, advanced threat protection, and malware all integrated into ZPA.
And last but not least is using risk signals to help with adaptive access. So we can look at this and say if I have a user coming in, they're doing something a little bit more risky, I can focus in on maybe putting that user in browser isolation. Or I can shift gears a little bit and say, "Hey, maybe I'll be more data-centric and say they can talk to anything except for private applications."
So with that said, team, when we look again at the core principles of Zare, I'm going to connect any user to any application, regardless of location, and keep them off the network. ZCCO private access really is the gel that kind of molds it all together.
Looking at the other enhancements, whether it's B2B, VoIP, server traffic type of support, and some feature parity with cyber threat protection on the ZIA front, I think it's a pretty comprehensive platform.
So with that said, that's my time, and thank you for watching.