Your vendors and contractors need two internal apps. They should not get your whole network to reach them — Symantec ZTNA joins each user to one private app through connectors that only dial out, agentless for web, SSH and RDP — and it logs the URLs opened and SSH commands run inside each session.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Symantec ZTNA — Broadcom’s zero-trust access, sold through partners. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Broadcom’s cloud-delivered access that joins a user to one application, never to the network.
What consolidation actually replaces, dimension by dimension.
| Dimension | A remote-access VPN | Symantec ZTNA |
|---|---|---|
| What a remote user can reach | Every routable host once the tunnel is up | Only the applications a policy names |
| Contractor access | A VPN account, often a company laptop | A browser or native SSH and RDP tool, no agent |
| Inbound exposure | A concentrator listening on the internet | Connectors that only dial out |
| What gets recorded | When the tunnel went up and down | URLs opened and SSH commands run, per user |
| DevOps keys | Shared SSH keys copied between engineers | Keys held centrally, access granted just in time |
| What it is NOT | — | A published price, or a documented Indian location |
The cheapest test is one vendor team: two connectors, one IdP group and activity logging, run beside the VPN for a month.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A SaaS service, run by Broadcom on Google Cloud with the rest of its security stack, weighs user, device and resource context before joining a user to one application.
Connectors you deploy in a private cloud, AWS, Azure or Google Cloud dial out to the service, so no app listens on the internet; RDP across several connectors needs session stickiness.
Contractors and BYOD users reach web, SSH and RDP apps with nothing installed; managed laptops can use the Symantec Endpoint or Cloud SWG agent already on them for segment apps.
Access rules map IdP groups to apps, activity rules limit actions inside each app, and every URL opened and SSH command run is logged and can be forwarded to your SIEM.
Agentless or through a Symantec agent — users meet outbound connectors in the ZTNA cloud, and every action is logged.
Symantec ZTNA gives contractors and staff one app at a time, and records what they do once inside.
Third parties and BYOD users reach internal web, SSH and RDP apps with no agent, keeping the native tools they already use.
Where the Symantec Endpoint or Cloud SWG agent is already deployed, Broadcom says ZTNA can be switched on through it, with no new client.
Outbound-only connectors in your data centre, AWS, Azure or Google Cloud hide every resource; no inbound port faces the internet.
Authorisation is continuous and contextual, weighing user, device and resource instead of trusting one sign-in at the start of the day.
It plugs into the corporate identity provider and MFA you already run, so the groups held there settle who reaches which app.
Role-based admin and an API-driven platform let app owners manage their own access and let pipelines grant it from CI/CD or IaC.
Activity policies set what a user or group may do inside an app, and each URL opened or SSH command typed is written to the log.
Just-in-time and just-enough access to production, staging and dev, with SSH keys held centrally and engineers’ sessions monitored.
Integrations with Symantec DLP and CloudSOC CASB carry the data rules you already enforce on web traffic over to private apps.
An SSH demo, Broadcom’s case against VPN access, and agent-based access through the older WSS Agent. All from Symantec’s official channel, 2023–2025.
SSH access to a private server through Symantec ZTNA, the administrator use case the product leans on.
Broadcom’s case for replacing VPN access with per-application connections, from 2024.
Agent-based access through the WSS Agent, filmed in 2023; that agent is now end-of-line, so plan new rollouts on the SES agent.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Contractors, consultants and BYOD users reach internal web apps, SSH and RDP with nothing installed and keep their own tools. Broadcom’s 2025 white paper cites an anonymised 60,000-employee firm that moved 90% of its VPN use cases — vendor-reported, not audited.
If the Symantec Endpoint agent or the Cloud SWG agent is already on your laptops, Broadcom says ZTNA can be provisioned through it, making rollout a policy change, not a new client. Plan on the SES agent: the WSS Agent is end-of-line.
Activity policies define what a user or group may do inside an application, and the service logs the URLs each user opens and the SSH commands they run. DevOps teams also get just-in-time access, central SSH-key management and session monitoring.
There is no public price, and Broadcom’s own pages differ on whether ZTNA is an add-on or comes with Network Protection. Broadcom documents no Indian service location, no server-initiated traffic such as VoIP and no named posture checks, and Gartner rated Broadcom a 2025 SSE Niche Player.
Inventory private apps by protocol — web, SSH, RDP, thick client, server-initiated — and mark who needs each one.
Ask the partner in writing whether ZTNA is an add-on or already in your Network Protection bundle, and where it runs.
Deploy connectors beside one app group in your Indian data centre or cloud account, with session stickiness for RDP.
Move one vendor team to agentless web and SSH access, turn on activity logging, and send the logs to your SIEM.
Move managed laptops through the SES agent, keep a dated exception list for VoIP-style apps, and cut VPN groups.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our statutory auditors reach two internal web apps and one SSH jump host from their own laptops. Nobody issued them a VPN login.”
“Every command the vendor typed on our database host showed up in the activity log next morning, which closed an audit observation.”
“The Symantec endpoint agent was already everywhere, so turning ZTNA on was a policy job, not another client to package and push.”
“RDP kept dropping until support had us enable session stickiness across both connectors. It has been stable since that change.”
“The partner could not say at first whether ZTNA was an add-on or already in our bundle; that took three calls to settle.”
“Our softphones still ride the old VPN. Write the exception list before anyone promises to switch the concentrator off.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero-trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only via partners; a Niche Player in Gartner’s 2025 SSE MQ.
The grid nobody publishes — how many apps, protocols and device types the product can reach vs how far it controls and records what users do inside each app.
Agentless web, SSH, RDP; URL and SSH-command logging, JIT.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Private Access, Netskope One Private Access, Skyhigh Private Access, Cloudflare Access and InstaSafe ZTNA — on connectors, access modes, protocols, posture, identity, inspection, scale, price, India and analyst standing.
| Dimension | Symantec ZTNA | Zscaler Private Access (ZPA) | Netskope One Private Access | Skyhigh Private Access | Cloudflare Access | InstaSafe ZTNA |
|---|---|---|---|---|---|---|
| What it is | ZTNA in Symantec SSE | Zscaler’s ZTNA | Netskope One module | ZTNA in Skyhigh SSE | Access in Cloudflare One | India-built, IP layer |
| Connector design | Outbound connectors | App + Network Connector | NewEdge brokering | Connector VM, groups | Cloudflare Tunnel | Dark until verified |
| Access modes | Agentless + agent | Client + browser | Universal ZTNA | Client Proxy + browser | WARP + agentless | Agent + agentless |
| Apps and protocols | Web, SSH, RDP; segments | Widest, with appliance | Adds VoIP and SCCM | SSH, HTTPS; RDP unnamed | Web, SSH and RDP | Thick clients, devices |
| Device posture | Contextual, unnamed | Re-evaluated in session | Every request checked | Four named checks | WARP or browser signals | Agent and browser |
| Identity and SSO | IdP, MFA, SIEM | SAML, OIDC, SCIM | SAML, OIDC, SCIM | SAML only | SAML, OIDC, SCIM | SAML and OIDC |
| Inline inspection | Threat scan + DLP link | DLP is a separate line | One DLP everywhere | DLP + isolation inline | In the wider suite | Access only |
| Scale evidence | 60,000 users (claim) | Most widely deployed | Verified above 5,000 | Not shown at 5,000+ | Verified at scale | Mid-market documented |
| Pricing model | Quote via partners | Per user, in editions | Per user, in platform | Per user, per year | Free tier, then per user | Per user, published |
| Published entry price | Not published | ~$6–11 reported | Not published | Not published | $0, then $7/user/mo | ~$8/user/month |
| Standalone or bundled | Add-on or included? | Standalone | Platform module | Add-on or SSE Complete | Standalone | Standalone |
| India presence | Not documented | PoP cities unconfirmed | 8 India data centres | 3 Indian PoPs | 6 Indian cities | Built and hosted here |
| Analyst standing | SSE 2025 Niche Player | SSE 2025 Leader | SSE 2025 Leader | SSE 2025 Niche Player | SASE 2025 Visionary | Not in the SSE MQ |
| Best fit | Symantec agent estates | Full VPN retirement | Awkward protocols | Skyhigh gateway estates | Fast, priced start | Indian and GeM buyers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Symantec ZTNA is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (people who reach private apps today; IT admin-hour cost). Estimates model admin hours spent creating VPN accounts, opening firewall rules and reviewing who can reach what, at an assumed 1.5 hours per person a year, with 70% of that work removed when access is granted per app from identity groups. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Broadcom publishes no price for Symantec ZTNA, and every product page offers only Buy via Partner and Contact Us. Its SSE page lists ZTNA as an add-on to Cloud SWG, while a March 2025 Broadcom white paper says it comes with Symantec Network Protection at no additional cost — so confirm in writing which applies to you. Westcon-Comstor distributes Symantec across APAC, India included. TechBag lists your apps and users first, then quotes in INR with GST.
Best for estates already on Symantec web security
Best for a broader rollout
Best for Network Protection subscribers
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which apps are web, SSH, RDP, thick client or server-initiated? Broadcom documents the first three agentless.
Is ZTNA an add-on to Cloud SWG in your quote, or already included with Network Protection? Get it in writing.
Where does the ZTNA service run for Indian users? Broadcom documents no Indian location, so ask the partner.
Which agent will managed laptops use? The WSS Agent is end-of-line; plan on the Symantec Endpoint Security agent.
Where will connectors sit — your Indian data centre, AWS, Azure or Google Cloud — and how many per app group?
Which IdP and MFA will federate, and how will groups be kept current if SCIM is not described for this product?
Which apps need activity policies, and where will URL and SSH-command logs land for review and retention?
Which apps stay on the VPN, who owns that list, and on what date will each one be reviewed or retired?
Sort the apps your VPN carries by protocol first, or let a TechBag advisor scope a pilot that moves one contractor team onto agentless access with logging on.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.