For decades, the virtual private network, more commonly known by the acronym VPN has been a mainstay of enabling secure remote connectivity.
With a VPN, a secured, encrypted tunnel, enabled either via SSL-VPN or IPsec is created between the user and the enterprise. Once connected, the user then gets the same access as they would if they were physically present within the organization's own LAN. In the modern era, many organizations have recognized that VPN alone is not enough to secure access, as threats can come from both outside and inside of a network perimeter. That realization has in part led to the growth of the zero-trust network access (ZTNA) approach.
With ZTNA access and authorization to applications is always being validated in a model where there is no inherent – or implied – trust.
"Most enterprises I’ve recently encountered provide VPN access to the entire network," Damian Chung, Business Information Security Officer (BISO) at Netskope told SDxCentral. " Meaning once you’ve authenticated to the VPN, your device is treated as a trusted host and its traffic is permitted anywhere in the network."
Chung added that VPN users don't necessarily get full access to all of the applications, but network discovery is possible, which provides enough intel to further attempt access to applications with potentially known vulnerabilities. He noted that organizations may not consider this to be their security perimeter, but it certainly extends the security perimeter as many employees are working remotely. While ZTNA is starting to become thought of as a plausible option for VPN replacement, Chung said that we are still in the early stages of this evolution.
ZTNA myths and misconceptionsThere are numerous myths and misconceptions about ZTNA and how it can go beyond what a VPN-only approach to remote access provides.
According to Peter Newton, senior director of product and solutions at Fortinet, a common ZTNA myth is that you have to move to the cloud to implement zero trust or that it can only be used for remote employees. Newton noted that sometimes organizations even set up separate solutions: one for cloud access and another one for on-premises.
Reality though is a bit different. Newton said that with modern universal ZTNA solutions, users can have the same experience for both cloud and on-premises access without performance degradation, so it’s an ideal way to support hybrid networks and hybrid workers.
Netskope's Chung also sees the misconception that ZTNA is only for a remote access solution. Chung said that if ZTNA is properly adopted across an enterprise, all access requests must be verified before access is granted.
"This can take an organization's level of security to that next level of protection where cascading failures in layers of defense becomes extremely difficult, even near impossible in many cases for an attacker to exploit," Chung said.
Best practices for moving from VPN to ZTNAWhen considering a transition from VPN to a ZTNA model, there are a number of things that organizations should be aware of as part of an evaluation and potential migration.
Culture and mindset. Newton said that IT leaders should understand that the biggest shift will be in their organization’s mindset.
"It’s important to talk openly and often about the strengths of zero trust to get as much buy in as possible before rolling out changes," Newton told SDxCentral.
Identity is key. When building a plan, realize that identity is the foundation of any zero-trust project as you enforce who is allowed to do what. Newton said that role-based access control (RBAC) is a critical component of ZTNA as it allows organizations to limit the data and applications a user can access according to the needs of their job.
Consider universal coverage. Newton also suggests that organizations consider a ZTNA solution that provides complete coverage for a hybrid workforce, whether users are remote or on-premises.
Bridge the gap. A unified agent that addresses both VPN and ZTNA can also ease the transition, according to Newton.
"Even if you migrate to a ZTNA model, there may be times when users still need a VPN, so it’s worthwhile to use a single solution for both," Newton said. "A unified agent can also provide endpoint protection and a path to secure access service edge (SASE)."
Moving from VPN to ZTNA is also about making sure all requirements are met. Netskope's Chung suggests that organizations take a thorough inventory of the current VPN solution, to include the infrastructure, limitations, performance and security features.
"Knowing where you are coming from can provide a much better understanding of where you want to go and how ZTNA can be that next level solution," Chung said.
It's a journey. Chung suggests that changes are phased in over a period of time that is acceptable to the organization. These changes should include implementing MFA, enforcing the principle of least privilege across all applications, and leveraging user and entity behavior analytics (UEBA). Chung recommends ensuring that the organization's security operations center (SOC) is aware of the policy changes as they are implemented so they know how to respond to the new alerts and incidents.
Finally, Chung also suggests continuous monitoring and adjustment of policies as the organization and technology changes.
Comments