Zscaler Internet Access is useful for role-based access control. In our company, we have different profiles for users, and based on the profiles, there are types of accesses that are allowed. For example, some are allowed to access social media, while some are not. It is based on their job titles, what their profiles are, and their job functions.
Zscaler Internet Access (ZIA)
Zscaler, Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Helps maintain a consistent posture of internet security while getting rid of VPN and hovering into zero trust
What is our primary use case?
What is most valuable?
It is quite a valuable product for our company as we get visibility of our security posture, which is the tool's main advantage. Maintaining a consistent posture of internet security while getting rid of VPN and hovering into zero trust, are some of the areas that have been very helpful for our organization.
The product is majorly used by the IT side and is useful for pretty much all of the internet access from office, on-prem or off-site locations. As the remote workforce along with everyone else goes through the same policies, all are forced to use it in our company.
In terms of how Zscaler Internet Access has improved the area of secure web gateway management, I would say that rather than having multiple firewall tools and different types of proxies, it is better to have one platform to look at so that you can have a consistent view and visibility over what is happening across your user base, offices and it is especially helpful when you have to deal with IT and IoT kind of scenarios where you can look at specific requirements, specific exclusions, and allow IT and IoT to function in a consistent manner. The granularity of the policy, which is aligned to specific users and user groups, helps a lot in terms of giving our company wider visibility and raising the productivity of the users.
The SSL inspection capabilities of Zscaler Internet Access have had an impact on our company's security posture, especially since our organization installed its root security certificate. Most of the products have SSL inspection, but there are exceptions, such as banking or government sites, so there are some exclusions. Luckily, the tool works quite well, and our company gets to reduce the number of exceptions and make sure that pretty much all the connectivity or where the access goes through, specifically through where the secure access goes through, is inspected with the help of SSL inspection.
The product has helped save our company costs because you don't need a huge workforce. Rather than having multiple types of policies and firewall rules, the tool allows our company to be consistent across the company at the same time. You don't need a huge amount of people to maintain the policies in the tool. The tool reduces the number of devices required. For example, our company has around 80 locations, so we expect to have something like 160 firewall devices, along with 150 types of policies. Besides the aforementioned area, you plug everything into the cloud environment to reduce admin overhead and the cost of the solution and have better visibility.
Speaking about how the product handles network latency and user experience in remote locations, I would say that I have been using the product since 2010, and I have seen that it has improved a lot lately. With the tool, there are a lot of failover mechanisms you can use when one specific data center doesn't work well. The tool also has an automated switchover process. The tool has helped our company, and we haven't encountered any major latency issues.
What needs improvement?
There could be a better way for the tool to categorize the traffic. For example, the tool does exceptions and everything overall. If I want to give guest access or provide access to guest users or any other internet access and if it does not go through the SSL inspection because, in our company, we can't have the root certificate on a device that we don't manage, which can be called out as an exception or an exclusion, but that doesn't provide a proper reflection of the picture of what is happening in the environment. There are granularities bringing it down. The tool I used or still have is Zscaler Cloud Connector to protect the cloud environment, which can have a bit more user-friendly installation and setup, and it would help a lot.
The deployment process of Zscaler Cloud Connector needs to be more user-friendly.
Improvements are required in the exception category. For example, suppose I report on a monthly basis what the breaches and traffic violating the SSL inspection area are coming from. In that case, I may find that half of them may be coming through some guest network, meaning the tool doesn't differentiate between the guest or normal networks or the corporate networks. Having options to differentiate different networks would be ideal so that it can show a true picture of things to users, as half of the things in the tool are not in our control and are not of our concern.
For how long have I used the solution?
I have experience with Zscaler Internet Access for more than ten years. Although I left the company where the product was being used, I know it is still used there. I have used the solution within the last twelve months. My company was a user of the product.
What do I think about the stability of the solution?
My company has not faced any major issues when it comes to stability. The product has a failover mechanism, and my company receives notifications about any issues with the tool. Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution a ten out of ten.
How are customer service and support?
The solution's technical support is helpful. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used to use ZIA and ZPA, including Zscaler Cloud Firewall, and it offers quite a good way of moving into the zero trust model.
I have used Blue Coat, Palo Alto, and similar products. Though the previous products that I have used have merits and demerits, Zscaler Internet Access is a solution that seems to be ahead of the other vendors. The merits related to the product stem from areas related to the setting up of the solution and the cloud presence. The technical implementation part of the tool is good.
For example, Palo Alto and Blue Coat all have an extended cloud activity, but such tools are not as comprehensive as Zscaler Internet Access, especially in areas related to firewalls, adding policies, or synchronization with the different types of user groups.
How was the initial setup?
The product's initial setup phase is a bit easy, as one doesn't need high technical expertise. Zscaler does provide help, as this solution offers very good after-sales engineers of service and technical support staff who are quite helpful and can actually get things done on time.
I rate the product's initial setup phase as seven and a half to eight out of ten, where ten means it has an easy setup process.
The solution is deployed in a hybrid environment.
Our company was able to migrate to around 80 locations with around 5,000 to 6,000 users in a time frame of six months.
What was our ROI?
In terms of the product's ability to reduce costs, I would say that specifically, we have been able to get a drop by a huge amount in our company, which I don't want to put in a percentage form. At least there has been a subsequent and substantial reduction in the amount of hardware costs my company was spending along with the licensing part. Either you can opt for the pay-as-you-go model, or you can apply for a licensing model based on the number of users, and it is not specifically associated with sites or anything like that. With Zscaler Internet Access, you are looking at things differently when it comes to cost.
What's my experience with pricing, setup cost, and licensing?
Price-wise, the tool is reasonable compared to the other products in the market but it is not a very low-priced tool. The solution does provide value for money.
What other advice do I have?
I recommend those who plan to use the product start off with the PoC phase and make sure that you get value out of it after which you can move on to the planning phase. In my opinion, the solution is easy to deploy.
I rate the overall tool an eight out of ten.