<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Better solution for remote access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1239987#M125339</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/434669845"&gt;@W.Granada&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Classic VPN models are often setup in an all-or-nothing configuration (they don't have to be but are often setup as such) sending all traffic back through the corporate network This backhauling can add significant latency.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your instincts are correct. ZTNA is an alternative to explore.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It operates on the principle of "never trust, always verify." No user or device is trusted by default, regardless of their location. Every access request is verified based on factors like user identity, device posture (is it up-to-date with security patches?), and context.&amp;nbsp; Its model enforces the principle of least privilege. So instead of granting network access, ZTNA provides highly granular, application-specific access. A remote trader would only be granted access to the specific trading platform and data resources they need for a single session. This significantly reduces the attack surface and minimizes the risk of lateral movement if a device is compromised.&lt;BR /&gt;&lt;BR /&gt;ZTNA is often a cloud-based service, which can improve performance. It establishes secure, direct, one-to-one connections between the user and the specific application, bypassing the need to backhaul all traffic through a central data center. This "split-tunneling" approach can lead to lower latency and a better user experience.&amp;nbsp; ZTNA can be more seamless for users. It works transparently in the background, without requiring the user to manually connect to a VPN client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An alternative solution for trading can be&amp;nbsp;to use VPS (Virtual Private Server).&amp;nbsp; Your remote traders would connect to a high-performance VPS, which is typically located in a data center with ultra-low latency connectivity.&amp;nbsp; This bypasses the latency and connectivity issues of the home user's ISP. The connection between the VPS and the trading exchange is optimized for speed. It also ensures 24/7 uptime for automated strategies, regardless of the home user's internet connectivity.&amp;nbsp; That said, it's a different operational model and might not be the right fit if your traders need to access other internal applications directly from their home computers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sources:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/zero-trust-best-practices" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/zero-trust-best-practices&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-ztna" target="_blank"&gt;https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-ztna&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-2-0" target="_blank"&gt;https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-2-0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Oct 2025 08:08:30 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2025-10-14T08:08:30Z</dc:date>
    <item>
      <title>Better solution for remote access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1239926#M125337</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;
&lt;P&gt;I wasn't sure which group to post this on exactly so I figure try general topics first and then perhaps the conversation will lead me to the correct place where I can get more insight on this.&amp;nbsp; What I am trying to do is I wanted to see if there is a better want to provide remote users access.&amp;nbsp; Right now I am using VPN tunnels/GRE tunnels.&amp;nbsp; In the beginning(covid days) this seem to be good enough but now a days I am getting more complaints about latency and the back and forth between us and the different home users ISPs about connectivity issues and latency.&amp;nbsp; I work for a trading firm so latency and more reliable and stable connectivity for our remote traders is what I am trying to fix.&amp;nbsp; I started reading about PA ZTNA&amp;nbsp; and was wondering if anyone had any comments about this? I am looking in the right place or is there a better alternative?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Warren&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 16:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1239926#M125337</guid>
      <dc:creator>W.Granada</dc:creator>
      <dc:date>2025-10-13T16:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Better solution for remote access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1239987#M125339</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/434669845"&gt;@W.Granada&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Classic VPN models are often setup in an all-or-nothing configuration (they don't have to be but are often setup as such) sending all traffic back through the corporate network This backhauling can add significant latency.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your instincts are correct. ZTNA is an alternative to explore.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It operates on the principle of "never trust, always verify." No user or device is trusted by default, regardless of their location. Every access request is verified based on factors like user identity, device posture (is it up-to-date with security patches?), and context.&amp;nbsp; Its model enforces the principle of least privilege. So instead of granting network access, ZTNA provides highly granular, application-specific access. A remote trader would only be granted access to the specific trading platform and data resources they need for a single session. This significantly reduces the attack surface and minimizes the risk of lateral movement if a device is compromised.&lt;BR /&gt;&lt;BR /&gt;ZTNA is often a cloud-based service, which can improve performance. It establishes secure, direct, one-to-one connections between the user and the specific application, bypassing the need to backhaul all traffic through a central data center. This "split-tunneling" approach can lead to lower latency and a better user experience.&amp;nbsp; ZTNA can be more seamless for users. It works transparently in the background, without requiring the user to manually connect to a VPN client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An alternative solution for trading can be&amp;nbsp;to use VPS (Virtual Private Server).&amp;nbsp; Your remote traders would connect to a high-performance VPS, which is typically located in a data center with ultra-low latency connectivity.&amp;nbsp; This bypasses the latency and connectivity issues of the home user's ISP. The connection between the VPS and the trading exchange is optimized for speed. It also ensures 24/7 uptime for automated strategies, regardless of the home user's internet connectivity.&amp;nbsp; That said, it's a different operational model and might not be the right fit if your traders need to access other internal applications directly from their home computers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sources:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/zero-trust-best-practices" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/zero-trust-best-practices&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-ztna" target="_blank"&gt;https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-ztna&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-2-0" target="_blank"&gt;https://www.paloaltonetworks.com/cyberpedia/what-is-zero-trust-network-access-2-0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 08:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1239987#M125339</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-10-14T08:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Better solution for remote access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1240013#M125346</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;
&lt;P&gt;Interesting yes this sounds something that I need to dig deeper into but thank you for the information and links!!!&amp;nbsp; I will check them out and reach out to Palo as we already do business with them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the info!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Warren&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 18:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/better-solution-for-remote-access/m-p/1240013#M125346</guid>
      <dc:creator>W.Granada</dc:creator>
      <dc:date>2025-10-14T18:37:49Z</dc:date>
    </item>
  </channel>
</rss>

