A remote-access design should grant the access a user needs and limit the consequences of a compromised account or device. VPN and zero trust network access can support different parts of that design; neither label is a complete security assessment.

Begin with the applications, user groups and device types rather than a plan to replace every tunnel.

What changes with zero trust

NIST SP 800-207 describes an approach that does not grant implicit trust solely because of network location. Identity, device information, resource policy and context inform access decisions.

Many ZTNA products use application-specific access and connectors near the protected service. Evaluate the product's actual behavior: supported protocols, device checks, session reassessment, logging and revocation.

A policy describing one application is useful only when its enforcement and exceptions have been tested.

VPN security depends on the surrounding controls

A VPN provides encrypted transport. It does not necessarily grant unrestricted internal access or authenticate only once: MFA, routing restrictions, firewalls, device checks and session policies can constrain access.

Review what a connected user can reach. Test with a normal account, an administrator, a contractor and an unmanaged device. Identify unnecessary routes and permissions rather than assuming the tunnel itself is the entire problem.

Keep gateways and clients maintained and monitor authentication events. These responsibilities continue during any transition.

Reduced exposure is not zero exposure

Outbound application connectors can reduce the need to expose an application's origin directly. The access broker, identity provider, client and administrative interfaces still need protection.

Check connector permissions, update ownership, certificate handling and failure behavior. Determine what happens when the broker or identity service is unavailable and how emergency access is controlled.

Do not treat a product's “zero trust” description as a promise that phishing, software vulnerabilities or lateral movement are impossible.

Plan a coexistence phase

Inventory browser applications, thick clients, administrative protocols, service accounts and site-to-site connections. Test representative applications before moving a user group.

A practical sequence is to narrow contractor access first, then migrate suitable application groups and retain tightly scoped VPN access for remaining dependencies. The schedule depends on the estate; there is no universal migration duration.

Measure progress with access-policy coverage, removed broad permissions, observed user experience and successful recovery exercises.

Questions for a proposal

  • Which applications and protocols are supported?
  • What device and identity evidence is checked?
  • When are sessions reassessed or revoked?
  • What remains reachable after an account compromise?
  • How are failures, exceptions and administrative access handled?
  • Who operates the logs and incident response?

For connections between whole sites, see the SD-WAN, MPLS and site-to-site VPN comparison to assess the underlying paths and failover requirements.

BustanTech provides Cisco networking and secure-access services and managed operations. Contact us to discuss an application-led remote-access assessment.