Zero Trust Network Access on a budget (ZTNA)

I wanted to start a ZTNA on a budget thread to list good approaches and apps that can be used to implement the BeyondCorp model - preferably open source / free / low cost.
I have nothing to kick start this with other than a useful curated list of ZTNA resources from pomerium on Github:


I'll try keeping the OP updated as this develops and list recommended products and approaches here.
Any tools you've used and want to share?

Go!
 
If you already have M365 with an Azure AD P1 or P2 license (or M364 E3/E5) Azure AD Application Proxy could be worth looking at. Think it only works for web applications though.
 
It depends on the size of the organization and their infrastructure.
What I am finding is that we are turning a fair amount of "offices" into internet cafes essentially.

Even if they have infrastructure in the network, it becomes completely isolated and inaccessible except through the same mechanisms as their cloud infrastructure or other infrastructure.

For example something like Netskopes NPA builds a private cloud where you publish everything to this. Access to this private cloud is only via certain mechanisms and is not exposed at all. You can turn your public cloud into a private cloud by cutting it off to the internet and publishing it.
With the office, you only access whatever you need via this private cloud as well.

There are other methods of zero trust which also utilizes dynamic evaluation to change security rules and access based on the evaluation criteria in a similar way to Ciscos TrustSec model (which was actually a really good concept for when it was released) traffic gets tagged and then access and privileges are adjusted accordingly
 
It depends on the size of the organization and their infrastructure.
What I am finding is that we are turning a fair amount of "offices" into internet cafes essentially.

Even if they have infrastructure in the network, it becomes completely isolated and inaccessible except through the same mechanisms as their cloud infrastructure or other infrastructure.

For example something like Netskopes NPA builds a private cloud where you publish everything to this. Access to this private cloud is only via certain mechanisms and is not exposed at all. You can turn your public cloud into a private cloud by cutting it off to the internet and publishing it.
With the office, you only access whatever you need via this private cloud as well.

There are other methods of zero trust which also utilizes dynamic evaluation to change security rules and access based on the evaluation criteria in a similar way to Ciscos TrustSec model (which was actually a really good concept for when it was released) traffic gets tagged and then access and privileges are adjusted accordingly
That is a good explanation. You still need to have inherent secure servers regardless. Twenty users on a server with no 2FA and all using the same password is a brainfart regardless of ZTN.
 
Top
Sign up to the MyBroadband newsletter
X