F5 Networks provides BIG-IP Access Policy Manager as an identity and access solution which can be deployed as a standalone solution or as an add-on to F5 Networks' flagship BIG-IP TLM or F5 Advanced WAF applications.
N/A
Zscaler Private Access
Score 7.9 out of 10
N/A
Zscaler Private Access™ (ZPA) gives users secure access to private apps and OT devices while enabling zero trust connectivity for workloads.
In the current digital world we are moving into, I would recommend F5 for all SMB to enterprise organizations. There are various models to pick from. This helps secure the environment and make the network robust to any sort of attacks. I am not able to think of any reason why one should not deploy or this device is less appropriate because nowadays every small company has application / ERPs. It is also worthwhile to note in case if all your apps are being deployed in the cloud by another service provider who provides you SAAS access, in that case, you can be at ease as securing these app falls on to the provider. However, should the budget be available I would recommend deploy this and enhancing your security.
The tool is, for the most part, very intuitive. Most of our issues so far (working through them with our Resident Engineer) are the one-off applications. We are working on some exemptions to make them functional. Besides that, the team loves the tool and how it can provide better security than our previous tool.
Application Segmentation and Listener Configuration - The way applications are defined and listened for is fundamental to ZPA, but can be a source of frustration, especially when dealing with legacy or non-HTTP protocols
The ZCC is the user's primary gateway, but its control over local system network behavior can sometimes clash with enterprise requirements.
If F5 BIG-IP Access Policy Manager usability is fine it's not hard to use if you read the documentation but it does feel dated and could use a responsive design update to modernize user interface to current standards.
Few things stand out. The ease of access: It very convenient - one click to open add details and done. Packet capture: Can't talk enough about this feature. Troubleshooting private access is always problematic,but this feature helped a lot. One thing that can be improved is early warning about expiring authentication
F5 BIG-IP Access Policy Manager integrates extremely well with the rest of our F5 infrastructure which is a big plus and provides us with a familiar user interface, but it isn't as scalable in its current iteration as something like Zscaler Private Access.
All of these tools are for different needs. Zscaler Private Access being for internal seems very simple as it really only allows filtering up to L4 whereas ZIA allows for filtering up to L7. ZDX often tries to give insight into the environment but since it only works with preconfigured items, that then means when a new problem shows up - ZDX isn't helpful troubleshooting postmortem. For the internal side of the house - Zscaler Private Access' strength is its simplicity to configure.
Positive: We have now charged users internally for the service
Negative: Dealing with users who also have the Zscaler Client Connector for their company, can cause confusions
Negative: Enabling the Zscaler Internet Access entitlement has been a major headache for us because Zscaler Private Access users can't autheniticate through ZIA on a non corporate device.