Zscaler Blog

Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang

Products & Solutions

Beyond VoIP and SCCM: Securing Legacy Applications with ZPA

image

Beyond VoIP and SCCM: Securing Legacy Applications with ZPA

VPN for Legacy Apps started with VoIP and server-to-client apps like SCCM. New capabilities now extend it to support full zero trust access to IP address dependent systems like mainframes, multi-entity organizations and complex routing environments, so more of your legacy estate can move to Zscaler Private Access (ZPA).

Most organizations moving from a traditional VPN/Firewall to zero trust reach the same point: user-to-app traffic moves to ZTNA easily, but a set of legacy apps keeps the old VPN concentrator or NGFW running. VPN for Legacy Apps in ZPA closes that gap. It gives those apps a home on the Zscaler Zero Trust Exchange, delivered through the same Zscaler Client Connector users already have. You can move off your traditional VPN vendor completely, with one agent, one policy framework and one platform for all private access, instead of running Zscaler and legacy VPN solutions side by side.

Why the last mile of VPN migration is the hardest

In our earlier post, we introduced VPN for Legacy Apps in ZPA. It covers the applications that have challenges with  zero trust design: Cisco Jabber, Avaya and Genesys VoIP, SCCM, follow-me printing and active FTP. These apps need the server to reach back to the client, and many expect a fixed client IP. That is why the VPN concentrator stays on long after everything else has moved to ZTNA.

As more customers move these apps onto ZPA using VPN for Legacy App solution, they have told us what would make large migrations even smoother: onboarding large VPN configurations quickly, supporting systems that expect a fixed client IP, bringing acquired companies onboard on their own terms, and fitting cleanly into existing routing.

Over the last few releases, we have delivered a set of features that address each of these needs and open VPN for Legacy Apps to use cases beyond where it started. Together, they make onboarding a legacy app to ZTNA as simple as adding it to your VPN, so you can retire your legacy VPN concentrators with confidence.

Expanded use-case coverage

The first set of capabilities removes common blockers that keep legacy apps on the VPN, while making onboarding and day-to-day operations simpler.

1. User group-based access policy

Legacy VPN access is often defined by IP ranges alone, which says little about who is actually connecting. Access policies for VPN for Legacy Apps can now use IdP group attributes alongside existing IP criteria. Admins can grant access to a legacy app based on who the user is (for example, the finance or contact-center group), not just which network range they target and coming from.

2. FQDN wildcard support: onboard everything, then migrate in phases

A typical VPN configuration covers a large number of hosts and domains, and discovering and rebuilding each one as an exact ZPA segment before cutover takes time. One missed host can break a VoIP callback or an SCCM push with no obvious cause. Network segments now support wildcard FQDNs, such as *.acme.com, so a single definition covers your legacy destinations on day one. You can move all of your VPN traffic to Zscaler in one step and retire the VPN, with users working just as they did before. From there, migrate to ZTNA at your own pace: use ZPA visibility to see which apps are really in use, then carve out specific network segments with least-privilege policies, one app group at a time. Upfront discovery and rework drop sharply.

3. Static IP assignment to users: keep IP-based controls working

Mainframes and many other legacy systems still trust an IP address. Firewalls, application allowlists and licensing servers key on the client IP, and regulated teams need a stable user-to-IP mapping in their logs. Admins can now statically map a user to an IP address, so the user gets the same address every time they connect to VPN for Legacy Apps. Security teams can track the user by IP across enterprise systems, allowlist-based apps keep working, and IP-based firewall rules need no rewrites. Banks, healthcare providers and other regulated teams keep a consistent user-to-IP record for audit and compliance.

4. Micro-tenancy: isolation inside one ZPA tenant

Mergers, acquisitions and multi-campus organizations bring separate VPN estates, each with its own apps, admins and policies, and often overlapping RFC 1918 address space. VPN for Legacy Apps now works with ZPA Microtenants, which provide isolation inside a single ZPA tenant. Each subsidiary, acquired business or campus can run its legacy app segments, Network Connectors and policies in its own microtenant, on its own timeline, even when its private address ranges overlap with others. Microtenants can also share network segments with each other, with granular control over which segments are shared and with whom. Central IT keeps one platform and one view, while each business onboards fast.

5. BGP summary routes: simpler routing integration

Previously, the customer's router had to advertise prefixes that exactly matched each ZPA segment, so every new or changed segment meant a router change request and coordination between security and network teams. Now your router can send a single summary route to the Network Connectors. Network Connectors then use conditional routing to advertise the specific routes that match your configured segments. For example, if the router sends 10.1.1.0/24 and the network segment is 10.1.1.1, the Network Connector advertises only 10.1.1.1/32. The network team configures BGP once, and the security team adds or changes network segments in ZPA without opening a router ticket.

Enterprise-ready: resiliency, control and visibility

With these capabilities, VPN for Legacy Apps goes beyond the handful of use cases to supporting all the use cases large enterprises run need

Get Started: ZPA Trial for VoIP and Legacy Application Zero Trust Migration

ZPA now supports VoIP, server-to-client (S2C) applications, and all IP address dependent use-cases. This enables customers to move all their applications and streamlines operations by consolidating their secure remote access solution with Zscaler Private Access. 

Check out the latest product innovations with ZPA in addition to network connectivity. And read the Forrester Total Economic Impact study to learn how ZPA customers have realized 289% ROI. 

Contact your regional sales team to learn more about the solution and get a free 30 day trial to explore the solution, or take a quick tour. 

 

form submtited
Danke fürs Lesen

War dieser Beitrag nützlich?

Haftungsausschluss: Dieser Blog-Beitrag wurde von Zscaler ausschließlich zu Informationszwecken erstellt und wird ohne jegliche Garantie für Richtigkeit, Vollständigkeit oder Zuverlässigkeit zur Verfügung gestellt. Zscaler übernimmt keine Verantwortung für etwaige Fehler oder Auslassungen oder für Handlungen, die auf der Grundlage der bereitgestellten Informationen vorgenommen werden. Alle in diesem Blog-Beitrag verlinkten Websites oder Ressourcen Dritter werden nur zu Ihrer Information zur Verfügung gestellt, und Zscaler ist nicht für deren Inhalte oder Datenschutzmaßnahmen verantwortlich. Alle Inhalte können ohne vorherige Ankündigung geändert werden. Mit dem Zugriff auf diesen Blog-Beitrag erklären Sie sich mit diesen Bedingungen einverstanden und nehmen zur Kenntnis, dass es in Ihrer Verantwortung liegt, die Informationen zu überprüfen und in einer Ihren Bedürfnissen angemessenen Weise zu nutzen.

Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang

Mit dem Absenden des Formulars stimmen Sie unserer Datenschutzrichtlinie zu.