Zscalerのブログ

Zscalerの最新ブログ情報を受信

Products & Solutions

Seeing the Invisible - Performance Monitoring in a Zero Trust World

LISA LORENZIN, SANJIT GANGULI
November 09, 2021 - 7 分で読了

Performance monitoring of private applications accessed remotely via VPN has always been a challenge. The encrypted tunnel between the user and the data center blocked the ability to truly understand what might have been causing performance issues on those network connections. Without a proper flashlight, this dark tunnel often hid the root cause of persistent problems. 

This is the bane of any VPN administrator’s existence—the all-too-predictable support ticket: “my experience accessing this app over the VPN is extremely slow! But it works fine when I’m at my desk…”  How do you even begin to troubleshoot? It could be a memory or CPU constraint on the user’s device, slow local WiFi, congestion in the local ISP, problems on the backbone, congestion in the data center or cloud hosting environment, or latency on the back-end app server. Enter Zscaler...

The Zscaler Zero Trust Exchange (ZTE) provides seamless, zero trust access to private applications running on public cloud or within the data center, and Zscaler Private Access (ZPA), ensures that applications are never exposed to the internet, making them completely invisible to unauthorized users and traditional monitoring tools. With the integration of Zscaler Digital Experience (ZDX) and ZPA, it is now possible to understand user experience accessing internal applications, from both the application and network perspective. 

Visibility is the foundation of zero trust; you can’t protect what you don’t know. Replacing your legacy VPN with ZPA allows ZDX to shine a bright light into that dark tunnel, an area where even traditional monitoring tools have no visibility.

Using ZDX, application, network performance, and device health statistics are collected for every employee every few minutes and are used to calculate a ZDX score that reflects the user’s experience with that private (or public) application. The health data is aggregated across all regions, offices, and users to provide macro-level visibility into company-wide performance and degradations. 

This ZDX score is combined with hop-by-hop network path analytics using CloudPath to provide segment-by-segment latency and loss breakdowns to easily isolate the network’s contribution to performance degradations 

CloudPath leverages Zscaler’s integrated Client Connector agent and the Zero Trust Exchange itself to measure network performance. This allows CloudPath to make use of ZDX’s unique 360-degree monitoring (see my recent blog here). The network path analysis is done from the client endpoint, outbound, and also takes advantage of the Zscaler cloud to view network path from the Zscaler cloud, inbound. This is combined with the network path between the Zscaler cloud and the private application, including the App Connector hop. All in all, CloudPath creates an end-to-end view of network path by stitching these path traces together.

 

ZDX exposes the hops and network details of the connection between the user’s device, their gateway, and the connection to their ISP. These hops would be invisible to traditional monitoring tools and in VPN environments.

ZDX also identifies each of the hops between the user’s ISP and the Zscaler cloud, showing which backbone providers the private application traffic is connecting through.  

Zscaler Private Access provides zero trust access to private applications through the use of an App Connector. App Connectors provide the secure authenticated interface between a customer’s servers and the ZPA cloud. ZDX highlights the network hops between the ZPA Public Service Edge and the App Connector with any unusual latency hops on that path.

Finally, ZDX can provide details into the hops and latency between the App Connector and the private application. While App Connectors are typically deployed very close to the application host, there may be circumstances where this is not the case as seen in Figure 8.

We finally have the tool we need to address that painful support ticket and identify exactly why access to an application may be slow for a remote user when it works fine on premises. ZDX and ZPA, working together, illuminate the invisible by shining a bright light into zero trust environments. 

Further reading:

ZDX: Fast, Seamless Digital Experiences – Now For Your Collaboration Apps
 

form submtited
お読みいただきありがとうございました

このブログは役に立ちましたか?

免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。

Zscalerの最新ブログ情報を受信

このフォームを送信することで、Zscalerのプライバシー ポリシーに同意したものとみなされます。