Zero Trust Network Access (ZTNA) & VPN Replacement
Zero trust network access for remote staff, contractors and partners: only the apps they need, never the whole network, after identity and device checks.
Lets remote staff, contractors and partners reach only the apps they need, never your whole network, after identity, MFA and device checks pass.
Also called
ZTNA, zero trust network access, VPN replacement, SASE, secure remote access, remote access VPN alternative.
What it does
- Per-app access Users see only what they’re allowed.
- Identity + posture Both must pass, every session.
- Same policy everywhere Office and remote use one engine.
- Session logging Every decision recorded.
Common concerns
- VPN means the whole network
- Access per application
- Separate remote policy
- One policy engine everywhere
- Unmanaged home laptops
- Posture checked before access
Questions and answers
- Does it replace our VPN?
- Yes. Remote users get access to specific applications instead of the whole network, so ZT-VPN can replace a legacy VPN.
- Does it work with our identity provider?
- Yes. It uses your existing directory or identity provider, with MFA, and checks device posture from NV-UEM.
- What is NV-ZT-VPN?
- Zero trust remote access: users reach specific applications after identity, MFA and device checks pass, instead of joining the whole network like a traditional VPN.
- Which checks happen before access?
- Identity through your identity provider, MFA, device posture from NV-UEM and policy conditions such as group, time and location.
- Can contractors get limited access?
- Yes. Policies can give contractors and partners access to named web applications only, for set hours.
- Are sessions logged?
- Yes. Every request and decision is recorded with user, device, location, application and outcome.
- Does it use the same policy as the office?
- Yes. NV-ZT-VPN uses the same policy engine as NV-ZT-NAC, so access rules are consistent on site and remote.
Often deployed with
- Unified Endpoint Management An agent for Windows, Linux and macOS that shows everything about each computer and lets IT act on it remotely: restart it, lock it, install software, fix it, or join a live session.
- Zero Trust NAC Knows every device the moment it connects and decides where it may go. Works with any switch, any hypervisor and any mix of enforcement, without changing your network.
Guides
- Replacing a legacy VPN with zero trust access Why per-application access is safer than joining users to the network.