Comparison of clientless and universal ZTNA

This comparison outlines the key technical and operational differences between clientless ZTNA and universal ZTNA deployment models. Clientless ZTNA uses a browser-based approach, which is ideal for guest users or unmanaged devices that require access to web applications. Universal ZTNA uses an agent-based solution that supports all protocols. It continuously monitors device posture in managed corporate environments. Consider factors such as application support, security inspection capabilities, and licensing requirements to choose the best strategy for securing your remote and on-premises workforce.

Factor

Clientless ZTNA

Universal ZTNA

Client required No client is required(browser-based) Yes, Secure Client is required
Application support Supports web applications only Supports all protocols and applications
Device posture Device posture monitoring is limited (available through agents such as Duo Desktop) Provides comprehensive and continuous device posture monitoring
Best for Guest users, contractors, unmanaged devices Employees, managed devices
Components involved

Third-party identity provider (IdP) configured with application access using Security Assertion Markup Language (SAML) authentication

  • Secure Access

  • Secure Client software

  • Identity provider (depending on users' location)

Security policies

Deep inspection (Snort, IPS, File) Deep inspection (Snort, IPS, File)
User location Remote and on-premises Remote and on-premises
Licenses Export-controlled license for Firewall Management Center Licenses for Secure Access, Secure Client software, and Security Cloud Control Firewall Management (formerly Cisco Defense Orchestrator)