Forescout Technologies headquartered in San Jose actively defends the Enterprise of Things by identifying, segmenting and enforcing compliance of every connected thing. Forescout boasts a widely deployed, enterprise-class platform at scale across IT, IoT, and OT managed and unmanaged devices. Forescout arms customers with device intelligence, in order to allow organizations across every industry to classify risk, detect anomalies and quickly remediate cyberthreats without disruption of critical…
N/A
Zscaler Private Access
Score 7.9 out of 10
N/A
Zscaler Private Access™ (ZPA) gives users secure access to private apps and OT devices while enabling zero trust connectivity for workloads.
It was able to relieve us of some of the duties performed by the operations team as it made it easy to do those tasks. It allows us to view devices that are connected to our network and segregate those that are not company owned and also account for guests' logins as are signed …
Better intergration with patch management tools. Forescount Platfform (CounterAct) is easily compatible with diverse network infrastructure to offer better service and efficiently ensure seamless operations. Its automation capabilities have also enabled us to depend less on the …
Forescout Platform (CounterACT) is capable to perform intelligent device classifications which able to group and segmentize the assets effectively. Besides, the classification techniques can be customized according to the organization requirements. With agentless deployment, …
When I got here, they already had this product in place, so I was not part of the final decision, but after using this for a couple of years, I can say that it was an intelligent decision for the business!!
Heterogeneous compatibility with switches and other network infrastructure setup is a major advantage. There are many companies where there is a legacy network combined with different OEM deployed. Integration of network devices like switches, FW, routers, AP's gives complete …
We selected CounterACT because it didn't require 802.1x and it didn't require any switch upgrades. To use 802.1x we would have to assume all endpoints are guilty until proven innocent. With CounterACT we can detect quickly if endpoints are not compliant and remediate without …
CounterACT was the product that was able to do exactly what we were looking to accomplish and that was to block non-company owned devices from connecting to our network based on our criteria. It will allow us to decide if a blocked device should be allowed on our network …
Ivanti had its moment. However moving to Zscaler Private Access was the best decision for us. Zscaler Private Access is faster, smoother UI and has heaps of feature that, in my opinion, makes it tower over Ivanti. The authenticate early option, ensures we don't loose connection …
All of these tools are for different needs. Zscaler Private Access being for internal seems very simple as it really only allows filtering up to L4 whereas ZIA allows for filtering up to L7. ZDX often tries to give insight into the environment but since it only works with …
Zscaler Private Access was chosen
as trusted VPN system versus Cisco, due to better licensing model, more
flexible configuration of the security protocols, verification scenarios. Also it
We had a nightmare experience with Prisma Access. The tool was not the most intuitive, and their peripherals to make it more secure were not efficient. Their integration with other tools to provide MFA was mediocre at best. That is the main reason we decided to explore …
Well ZPA is a good solution, however everyone has their own advantage and disadvantages, with ZPA you can deploy ZTNA model, which will help you better control on access, however Palo Alto, Fortinet they are also market leading firewall solution, and you can not deny if they …
We originally used Cisco AnyConnect but when the pandemic hit and everyone started working remotely the Cisco VPN just couldn't handle the massive increase in users. The connection was unreliable both inability to connect and stay connected. It also seemed to include a lot more …
I strongly recommend using it in networks where many machines enter, it is essential to have a capture of all ids, mac etc to prevent and detect unauthorized machines.We are in the technological era and there is a lot of technological robotization looking for weak systems to enter.Invest in greater security and that does not happen to you.
The tool is, for the most part, very intuitive. Most of our issues so far (working through them with our Resident Engineer) are the one-off applications. We are working on some exemptions to make them functional. Besides that, the team loves the tool and how it can provide better security than our previous tool.
Application Segmentation and Listener Configuration - The way applications are defined and listened for is fundamental to ZPA, but can be a source of frustration, especially when dealing with legacy or non-HTTP protocols
The ZCC is the user's primary gateway, but its control over local system network behavior can sometimes clash with enterprise requirements.
Few things stand out. The ease of access: It very convenient - one click to open add details and done. Packet capture: Can't talk enough about this feature. Troubleshooting private access is always problematic,but this feature helped a lot. One thing that can be improved is early warning about expiring authentication
They are prompt in their response with a complete resolution once they have identified the problem. Other OEM's generally give stop-gap arrangements and then later come with new upgrade versions. This gives downtime tasks to customers often, which isn't appreciated. Given the criticality of this software, their support is prompt.
CounterACT was the product that was able to do exactly what we were looking to accomplish and that was to block non-company owned devices from connecting to our network based on our criteria. It will allow us to decide if a blocked device should be allowed on our network temporarily
All of these tools are for different needs. Zscaler Private Access being for internal seems very simple as it really only allows filtering up to L4 whereas ZIA allows for filtering up to L7. ZDX often tries to give insight into the environment but since it only works with preconfigured items, that then means when a new problem shows up - ZDX isn't helpful troubleshooting postmortem. For the internal side of the house - Zscaler Private Access' strength is its simplicity to configure.
Positive: We have now charged users internally for the service
Negative: Dealing with users who also have the Zscaler Client Connector for their company, can cause confusions
Negative: Enabling the Zscaler Internet Access entitlement has been a major headache for us because Zscaler Private Access users can't autheniticate through ZIA on a non corporate device.