Comparison of clientless and universal ZTNA
This comparison outlines the key technical and operational differences between clientless ZTNA and universal ZTNA deployment models. Clientless ZTNA uses a browser-based approach, which is ideal for guest users or unmanaged devices that require access to web applications. Universal ZTNA uses an agent-based solution that supports all protocols. It continuously monitors device posture in managed corporate environments. Consider factors such as application support, security inspection capabilities, and licensing requirements to choose the best strategy for securing your remote and on-premises workforce.
|
Factor |
Clientless ZTNA |
Universal ZTNA |
|---|---|---|
| Client required | No client is required(browser-based) | Yes, Secure Client is required |
| Application support | Supports web applications only | Supports all protocols and applications |
| Device posture | Device posture monitoring is limited (available through agents such as Duo Desktop) | Provides comprehensive and continuous device posture monitoring |
| Best for | Guest users, contractors, unmanaged devices | Employees, managed devices |
| Components involved |
Third-party identity provider (IdP) configured with application access using Security Assertion Markup Language (SAML) authentication |
|
|
Security policies |
Deep inspection (Snort, IPS, File) | Deep inspection (Snort, IPS, File) |
| User location | Remote and on-premises | Remote and on-premises |
| Licenses | Export-controlled license for Firewall Management Center | Licenses for Secure Access, Secure Client software, and Security Cloud Control Firewall Management (formerly Cisco Defense Orchestrator) |