Initiating Your Zero Trust Journey: Considering ZTNA Instead of VPN
Zero-trust network access (ZTNA) has emerged as a key strategy for organizations seeking to implement zero-trust principles. Gartner forecasts that 60% of organizations will adopt zero trust by 2025,1 making it a prevalent trend in cybersecurity. However, fully realizing a zero-trust architecture can be complex, often requiring significant infrastructure changes and the deployment of numerous components. As a result, ZTNA is often the first step taken by organizations embarking on their zero-trust journey.
ZTNA addresses the need to modernize application access, particularly in knowledge-work industries where 90% of work is done through applications.2 The pandemic accelerated remote work adoption, demonstrating the feasibility of maintaining productivity while employees embrace flexibility. As organizations transition back to a hybrid work model, effectively controlling application access from both remote and on-premises environments is crucial. ZTNA’s ability to safeguard this critical attack surface marks a significant advancement in the zero-trust journey.
ZTNA enhances security by performing user identity and device posture checks before granting explicit access to individual applications. It continuously monitors both user and device to ensure they remain connected to the authorized application. This granular access control enables organizations to apply appropriate levels of control for each application, significantly hindering the ability of attackers to gain and maintain access.
Adopting a complete ZTNA solution undoubtedly involves network and application access modifications. However, some organizations may prefer a more cautious approach. Legacy VPN networks have effectively secured remote user traffic over the internet, and these solutions are already in place. While VPNs offer certain benefits, they have limitations in authenticating and monitoring users, devices, and access. For these organizations, implementing ZTNA over VPN augments an established solution with critical capabilities.
Fortinet’s Security Fabric seamlessly integrates ZTNA and VPN technologies, facilitating the rapid and straightforward implementation of ZTNA over VPN. FortiGate next-generation firewalls (NGFWs) include both a VPN concentrator and a ZTNA application gateway, while FortiClient endpoints provide both VPN and ZTNA agent capabilities. Organizations can leverage these integrated features to enable user identity verification, device posture assessment, and granular application access control over VPN tunnels.
While ZTNA over VPN is not a comprehensive ZTNA solution, as it only applies to remote users, it represents a significant improvement over legacy VPN-based networkwide access. Many Fortinet customers have adopted ZTNA over VPN as their initial step towards a zero-trust architecture.



































