{"id":1320,"date":"2024-12-09T10:12:32","date_gmt":"2024-12-09T10:12:32","guid":{"rendered":"http:\/\/jaychou.co.uk\/?p=1320"},"modified":"2024-12-09T10:12:54","modified_gmt":"2024-12-09T10:12:54","slug":"%f0%9f%a7%87ztna-zero-trust-network-access-sase%f0%9f%a5%99","status":"publish","type":"post","link":"https:\/\/jaychou.co.uk\/?p=1320","title":{"rendered":"\ud83e\uddc7ZTNA &#8211; Zero Trust Network Access &#8211; SASE\ud83e\udd59"},"content":{"rendered":"\n<p>\ud83e\udd8aSecuring a network or SD-WAN isn&#8217;t just about placing a firewall or firewalls within your network. Traditionally Enterprises would do this at the perimeter edge before breaking out to the Internet.<br><br>With Cloud and Mobility thrown into the mix, traditional network security isn&#8217;t going to quite cut it.<br><br>What is ZTNA and why do you care?<br><br>Zero Trust, essentially operates under the meaning of &#8216;never trust and to always verify who you say you are&#8217;. Once you have verified who you are, there will always be a continuous check to make sure everything is secure without any changes, such as disabling your local firewall as an example.<br><br>How does ZTNA work?<br><br>Authentication &#8211; Making sure you are who you say you are! Usually you would implement MFA.<br><br>Authorisation &#8211; You are allowed to access ONLY what you need and nothing more.<br><br>Micro-Segmentation &#8211; The application you access will be within a contained perimeter so should there be a breach, then it is only affecting a smaller area of the network instead of the whole network.<br><br>Privilege &#8211; Provide you with the least privileged access, so only utilising and accessing information relevant to do your job and nothing more. Essentially this stops granting you information or applications you don&#8217;t need.<br><br>Posture &#8211; Continiously checking the device to determine if it meets the requirements, an example could be a user disabling their firewall or security updates of the device. The device must meet the ZTNA requirements otherwise access will be denied. The Profile of the ZTNA Posture is defined by the Organisation. Examples of Posture checking can be:<br><br>Type of OS<br>Firewall enabled<br>Endpoint installed<br>System Password<br>Encryption of the storage<br><br>This is not to suggest that ZTNA will replace your traditional security solutions, such as firewalls, end point protection. They all complement each other and adding ZTNA will only help!<br><br>I have included Cisco&#8217;s SSE\/ZTNA Secure Access as an example.<br><br>I&#8217;d love to hear how other vendors approach ZTNA so please let me know!<br><br>Hope this helps! \ud83d\ude01<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"566\" src=\"http:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224-1024x566.jpg\" alt=\"\" class=\"wp-image-1321\" srcset=\"https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224-1024x566.jpg 1024w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224-300x166.jpg 300w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224-768x425.jpg 768w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224-672x372.jpg 672w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528224.jpg 1233w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528268.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"551\" src=\"http:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528268-1024x551.jpg\" alt=\"\" class=\"wp-image-1322\" srcset=\"https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528268-1024x551.jpg 1024w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528268-300x161.jpg 300w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528268-768x413.jpg 768w, https:\/\/jaychou.co.uk\/wp-content\/uploads\/2024\/12\/1723712528268.jpg 1222w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>\ud83e\udd8aSecuring a network or SD-WAN isn&#8217;t just about placing a firewall or firewalls within your network. Traditionally Enterprises would do this at the perimeter edge before breaking out to the Internet. With Cloud and Mobility thrown into the mix, traditional network security isn&#8217;t going to quite cut it. What is ZTNA and why do you &hellip; <a href=\"https:\/\/jaychou.co.uk\/?p=1320\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">\ud83e\uddc7ZTNA &#8211; Zero Trust Network Access &#8211; SASE\ud83e\udd59<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1320","post","type-post","status-publish","format-standard","hentry","category-sd-wan"],"_links":{"self":[{"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1320"}],"collection":[{"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1320"}],"version-history":[{"count":1,"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1320\/revisions"}],"predecessor-version":[{"id":1323,"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1320\/revisions\/1323"}],"wp:attachment":[{"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jaychou.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}