Talk to us
by BroadcomTechBag Intel Page

Symantec ZTNA

Your vendors and contractors need two internal apps. They should not get your whole network to reach them — Symantec ZTNA joins each user to one private app through connectors that only dial out, agentless for web, SSH and RDP — and it logs the URLs opened and SSH commands run inside each session.

One app per user, agent optionalURLs and SSH commands logged per userQuote via partners; licence route varies

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price; every Broadcom product page offers only Buy via Partner and Contact Us
Quote
Gartner MQ
Broadcom in the 2025 Security Service Edge Magic Quadrant, where Zscaler, Netskope and Palo Alto led
Niche Player
KuppingerCole
ZTNA Leadership Compass 2022 for this product; Zero Trust Platforms 2026 for Symantec SSE
Overall Leader
India
Connectors can sit in your Indian sites; Broadcom names no Indian location for the ZTNA service itself
Ask

Quick answer

Symantec ZTNA is Broadcom’s cloud-delivered zero-trust access, built on its 2019 Luminate purchase and once sold as Secure Access Cloud. Connectors you place in a private cloud, AWS, Azure or Google Cloud link a user to one app at a time; browser access reaches web, SSH and RDP with no agent. Each URL opened and SSH command run is logged. It is quote-only through partners, and no Indian location for the service is documented. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Symantec ZTNA — Broadcom’s zero-trust access, sold through partners. The rest:

Quick facts

30-second orientation
Product
Cloud-delivered access to one private app at a time, agentless or through existing Symantec agents
Maker
Broadcom, headquartered in Palo Alto and run by Hock Tan; ZTNA belongs to Jason Rolleston’s security group
Origin
Luminate Security, acquired by Broadcom in 2019; marketed for years as Secure Access Cloud
Price
Quote-only through partners; Broadcom publishes no list price for ZTNA
Licence
Broadcom’s SSE page lists it as a Cloud SWG add-on; a March 2025 white paper puts it in Network Protection
Access
Agentless for web, SSH and RDP apps; agent-based through the Symantec Endpoint or Cloud SWG agent
Audit
Activity policies per app; logs URLs opened and SSH commands run; JIT and just-enough access for DevOps
Analysts
KuppingerCole ZTNA compass, Overall Leader (2022); Gartner SSE MQ 2025 placed Broadcom among Niche Players
India
Broadcom offices in Pune, Hyderabad and Bangalore; Westcon-Comstor distributes; no Indian ZTNA location stated
In India via
TechBag — app inventory, connector placement, quote in INR with GST, pilot beside the VPN
Part 02 · Learn

Understand zero-trust access before you retire a VPN

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is Symantec ZTNA?

Broadcom’s cloud-delivered access that joins a user to one application, never to the network.

A remote-access VPN vs Symantec ZTNA — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA remote-access VPNSymantec ZTNA
What a remote user can reachEvery routable host once the tunnel is upOnly the applications a policy names
Contractor accessA VPN account, often a company laptopA browser or native SSH and RDP tool, no agent
Inbound exposureA concentrator listening on the internetConnectors that only dial out
What gets recordedWhen the tunnel went up and downURLs opened and SSH commands run, per user
DevOps keysShared SSH keys copied between engineersKeys held centrally, access granted just in time
What it is NOT—A published price, or a documented Indian location

The cheapest test is one vendor team: two connectors, one IdP group and activity logging, run beside the VPN for a month.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where each access request is decided

Service

Symantec ZTNA cloud service

A SaaS service, run by Broadcom on Google Cloud with the rest of its security stack, weighs user, device and resource context before joining a user to one application.

02
How apps are reached without exposure

Connectors

Connectors beside your applications

Connectors you deploy in a private cloud, AWS, Azure or Google Cloud dial out to the service, so no app listens on the internet; RDP across several connectors needs session stickiness.

03
How users arrive

Entry

Agentless portal or a Symantec agent

Contractors and BYOD users reach web, SSH and RDP apps with nothing installed; managed laptops can use the Symantec Endpoint or Cloud SWG agent already on them for segment apps.

04
What a user may do once inside

Policy

Access and activity policies

Access rules map IdP groups to apps, activity rules limit actions inside each app, and every URL opened and SSH command run is logged and can be forwarded to your SIEM.

Agentless or through a Symantec agent — users meet outbound connectors in the ZTNA cloud, and every action is logged.

Part 03 · Evaluate

Nine capabilities. Connect, control, watch.

Symantec ZTNA gives contractors and staff one app at a time, and records what they do once inside.

Connect
Agentless

Nothing to install for partners

Third parties and BYOD users reach internal web, SSH and RDP apps with no agent, keeping the native tools they already use.

Connect
Agents

Reuse the Symantec agent

Where the Symantec Endpoint or Cloud SWG agent is already deployed, Broadcom says ZTNA can be switched on through it, with no new client.

Connect
Connectors

Applications stay cloaked

Outbound-only connectors in your data centre, AWS, Azure or Google Cloud hide every resource; no inbound port faces the internet.

Control
Context

Checked on every request

Authorisation is continuous and contextual, weighing user, device and resource instead of trusting one sign-in at the start of the day.

Control
Identity

Your IdP and MFA decide

It plugs into the corporate identity provider and MFA you already run, so the groups held there settle who reaches which app.

Control
RBAC

Delegated administration

Role-based admin and an API-driven platform let app owners manage their own access and let pipelines grant it from CI/CD or IaC.

Watch
Activity

Actions, not just logins

Activity policies set what a user or group may do inside an app, and each URL opened or SSH command typed is written to the log.

Watch
DevOps

Just-in-time to production

Just-in-time and just-enough access to production, staging and dev, with SSH keys held centrally and engineers’ sessions monitored.

Watch
Data

DLP and CloudSOC tie-in

Integrations with Symantec DLP and CloudSOC CASB carry the data rules you already enforce on web traffic over to private apps.

See it, don’t just read it

Watch Symantec ZTNA in action

An SSH demo, Broadcom’s case against VPN access, and agent-based access through the older WSS Agent. All from Symantec’s official channel, 2023–2025.

Symantec by Broadcom (official)·Demo, July 2025

Symantec ZTNA SSH Demo

SSH access to a private server through Symantec ZTNA, the administrator use case the product leans on.

Symantec by Broadcom (official)·Overview, September 2024

The Future of Secure Access with Symantec ZTNA

Broadcom’s case for replacing VPN access with per-application connections, from 2024.

Symantec by Broadcom (official)·Demo, January 2023

ZTNA with the Symantec Cloud SWG Agent (WSS)

Agent-based access through the WSS Agent, filmed in 2023; that agent is now end-of-line, so plan new rollouts on the SES agent.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Symantec ZTNA

A VPN logs who connected. Symantec ZTNA logs what they did inside each app.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Third parties in without a VPN account

Contractors, consultants and BYOD users reach internal web apps, SSH and RDP with nothing installed and keep their own tools. Broadcom’s 2025 white paper cites an anonymised 60,000-employee firm that moved 90% of its VPN use cases — vendor-reported, not audited.

02

Switched on through agents you already run

If the Symantec Endpoint agent or the Cloud SWG agent is already on your laptops, Broadcom says ZTNA can be provisioned through it, making rollout a policy change, not a new client. Plan on the SES agent: the WSS Agent is end-of-line.

03

A record of what users did, not only who connected

Activity policies define what a user or group may do inside an application, and the service logs the URLs each user opens and the SSH commands they run. DevOps teams also get just-in-time access, central SSH-key management and session monitoring.

04

Where it stops

There is no public price, and Broadcom’s own pages differ on whether ZTNA is an add-on or comes with Network Protection. Broadcom documents no Indian service location, no server-initiated traffic such as VoIP and no named posture checks, and Gartner rated Broadcom a 2025 SSE Niche Player.

The idea
One app per user, agent optional
The difference
URLs and SSH commands logged per user
The price
Quote via partners; licence route varies
Proof, not promises

The numbers behind the platform

2019
the year Broadcom bought Luminate Security, whose technology became Symantec ZTNA
— Vendor
90%
of VPN use cases an anonymised 60,000-employee firm moved, per Broadcom’s 2025 paper
— Vendor
4 connector homes
a private cloud, AWS, Azure or Google Cloud: where Broadcom says connectors can run
— Vendor
3 agentless app types
web, SSH and RDP applications, reached with nothing installed on the user’s device
— Vendor
2026
KuppingerCole’s Zero Trust Platforms compass that ranked Symantec SSE, ZTNA included, Overall Leader
— Analyst
2025
the 2025 Gartner SSE Magic Quadrant, in which Broadcom was placed a Niche Player
— Analyst

What your Symantec ZTNA rollout looks like

Week 1Model

List every app the VPN carries

Inventory private apps by protocol — web, SSH, RDP, thick client, server-initiated — and mark who needs each one.

Week 2Decide

Settle the licence question

Ask the partner in writing whether ZTNA is an add-on or already in your Network Protection bundle, and where it runs.

Week 3Pilot

Place two connectors

Deploy connectors beside one app group in your Indian data centre or cloud account, with session stickiness for RDP.

Month 2Prove

Bring in contractors first

Move one vendor team to agentless web and SSH access, turn on activity logging, and send the logs to your SIEM.

Month 3Commit

Shrink the VPN on a schedule

Move managed laptops through the SES agent, keep a dated exception list for VoIP-style apps, and cut VPN groups.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
46+ reviews*
78% would recommend
Agentless access4.3
Ease of rollout4.1
Activity auditing4.2
Protocol reach3.7
Value for money3.6
5★
40%
4★
36%
3★
15%
2★
6%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our statutory auditors reach two internal web apps and one SSH jump host from their own laptops. Nobody issued them a VPN login.”
IT Risk Lead
BFSI
IT Services
“Every command the vendor typed on our database host showed up in the activity log next morning, which closed an audit observation.”
Security Operations Manager
IT Services
Manufacturing
“The Symantec endpoint agent was already everywhere, so turning ZTNA on was a policy job, not another client to package and push.”
Desktop Engineering Lead
Manufacturing
Healthcare
“RDP kept dropping until support had us enable session stickiness across both connectors. It has been stable since that change.”
Network Engineer
Healthcare
Retail
“The partner could not say at first whether ZTNA was an add-on or already in our bundle; that took three calls to settle.”
Head of IT
Retail
Logistics
“Our softphones still ride the old VPN. Write the exception list before anyone promises to switch the concentrator off.”
Infrastructure Architect
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero-trust access market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Zero Trust Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Symantec ZTNAThis page

Quote-only via partners; a Niche Player in Gartner’s 2025 SSE MQ.

Grid 02 · The architecture

Access Reach × In-App Control

The grid nobody publishes — how many apps, protocols and device types the product can reach vs how far it controls and records what users do inside each app.

Audit-first, narrower reachBroad and auditedBasic app accessWide reach, light control
Symantec ZTNAThis page

Agentless web, SSH, RDP; URL and SSH-command logging, JIT.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Symantec ZTNA vs the ZTNA field

Against Zscaler Private Access, Netskope One Private Access, Skyhigh Private Access, Cloudflare Access and InstaSafe ZTNA — on connectors, access modes, protocols, posture, identity, inspection, scale, price, India and analyst standing.

DimensionSymantec ZTNAZscaler Private Access (ZPA)Netskope One Private AccessSkyhigh Private AccessCloudflare AccessInstaSafe ZTNA
What it isZTNA in Symantec SSEZscaler’s ZTNANetskope One moduleZTNA in Skyhigh SSEAccess in Cloudflare OneIndia-built, IP layer
Connector designOutbound connectorsApp + Network ConnectorNewEdge brokeringConnector VM, groupsCloudflare TunnelDark until verified
Access modesAgentless + agentClient + browserUniversal ZTNAClient Proxy + browserWARP + agentlessAgent + agentless
Apps and protocolsWeb, SSH, RDP; segmentsWidest, with applianceAdds VoIP and SCCMSSH, HTTPS; RDP unnamedWeb, SSH and RDPThick clients, devices
Device postureContextual, unnamedRe-evaluated in sessionEvery request checkedFour named checksWARP or browser signalsAgent and browser
Identity and SSOIdP, MFA, SIEMSAML, OIDC, SCIMSAML, OIDC, SCIMSAML onlySAML, OIDC, SCIMSAML and OIDC
Inline inspectionThreat scan + DLP linkDLP is a separate lineOne DLP everywhereDLP + isolation inlineIn the wider suiteAccess only
Scale evidence60,000 users (claim)Most widely deployedVerified above 5,000Not shown at 5,000+Verified at scaleMid-market documented
Pricing modelQuote via partnersPer user, in editionsPer user, in platformPer user, per yearFree tier, then per userPer user, published
Published entry priceNot published~$6–11 reportedNot publishedNot published$0, then $7/user/mo~$8/user/month
Standalone or bundledAdd-on or included?StandalonePlatform moduleAdd-on or SSE CompleteStandaloneStandalone
India presenceNot documentedPoP cities unconfirmed8 India data centres3 Indian PoPs6 Indian citiesBuilt and hosted here
Analyst standingSSE 2025 Niche PlayerSSE 2025 LeaderSSE 2025 LeaderSSE 2025 Niche PlayerSASE 2025 VisionaryNot in the SSE MQ
Best fitSymantec agent estatesFull VPN retirementAwkward protocolsSkyhigh gateway estatesFast, priced startIndian and GeM buyers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Symantec ZTNA if…

  • ✓The Symantec Endpoint or Cloud SWG agent is already on your laptops and you want private access without another client
  • ✓Auditors, vendors or contractors need web, SSH or RDP access from devices you will never manage
  • ✓You need a log of what each user did inside an app — URLs and SSH commands — and just-in-time access for DevOps

Compare alternatives if…

  • ✓VoIP, SCCM or other server-initiated traffic has to cross — Netskope documents it, and Zscaler adds a Network Connector
  • ✓Enforcement must happen in a named Indian city — Netskope, Cloudflare and Skyhigh document Indian locations
  • ✓You want to read a price first — Cloudflare Access is free to 50 users, and InstaSafe publishes about $8 a user a month

Do not expect…

  • ✓A list price, or one clear answer on whether ZTNA is an add-on or already in your Network Protection bundle
  • ✓Documented reach for server-initiated traffic, such as an on-premises softphone system or SCCM
  • ✓A documented Indian location for the ZTNA service, or a named Indian customer

Symantec ZTNA is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does granting access by VPN cost you?

Drag the sliders (people who reach private apps today; IT admin-hour cost). Estimates model admin hours spent creating VPN accounts, opening firewall rules and reviewing who can reach what, at an assumed 1.5 hours per person a year, with 70% of that work removed when access is granted per app from identity groups. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual remote-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Broadcom publishes no price for Symantec ZTNA, and every product page offers only Buy via Partner and Contact Us. Its SSE page lists ZTNA as an add-on to Cloud SWG, while a March 2025 Broadcom white paper says it comes with Symantec Network Protection at no additional cost — so confirm in writing which applies to you. Westcon-Comstor distributes Symantec across APAC, India included. TechBag lists your apps and users first, then quotes in INR with GST.

ZTNA with Cloud SWG

Best for estates already on Symantec web security

  • Listed as an add-on in Symantec SSE
  • Quoted through partners
  • Same agents and console as Cloud SWG

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

ZTNA via Network Protection

Best for Network Protection subscribers

  • Broadcom’s 2025 paper: no additional cost
  • Confirm inclusion in writing
  • Quoted through partners

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Application list

Which apps are web, SSH, RDP, thick client or server-initiated? Broadcom documents the first three agentless.

2
Licence scope

Is ZTNA an add-on to Cloud SWG in your quote, or already included with Network Protection? Get it in writing.

3
Service location

Where does the ZTNA service run for Indian users? Broadcom documents no Indian location, so ask the partner.

4
Agents

Which agent will managed laptops use? The WSS Agent is end-of-line; plan on the Symantec Endpoint Security agent.

5
Connectors

Where will connectors sit — your Indian data centre, AWS, Azure or Google Cloud — and how many per app group?

6
Identity

Which IdP and MFA will federate, and how will groups be kept current if SCIM is not described for this product?

7
Audit trail

Which apps need activity policies, and where will URL and SSH-command logs land for review and retention?

8
Exceptions

Which apps stay on the VPN, who owns that list, and on what date will each one be reviewed or retired?

FAQ

Questions buyers ask

It is Broadcom’s cloud-delivered zero-trust network access. A user signs in through your identity provider, the service weighs user, device and resource context, and it joins that user to one named application through a connector that only dials out. Nothing else on the network is visible.

Ready to evaluate Symantec ZTNA?

Sort the apps your VPN carries by protocol first, or let a TechBag advisor scope a pilot that moves one contractor team onto agentless access with logging on.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.