Transcript
This is Henry again. Let's step into the solution that Zscaler is going to resolve for the five issues that we are listing here. First of all, Zscaler is a cloud security leader in the market, and what we are doing is to provide cloud security services through the Zero Trust Exchange available over the global internet. We have 160 plus data centers globally, including China. What we do is we provide services there available over normal internet. Especially in China, we make a special offer, what we call China Premium. What we do there is to position the Zero Trust Exchange inside a premium internet service provider. It is then a combination of the security as a service and network as a service. To resolve that, this helps us as an overview on architecture to resolve the five issues. By placing the Zero Trust Exchange in the cross-border ISP data centers, the Zero Trust Exchange, the Zscaler nodes there actually are providing the security services, which is covering the secure web gateway, the SSL inspection, the antivirus, the DOP, the firewall IPS that you are going to have for your on-prem stacks. This helps to provide the service and connectivity as a service at the same time from the cloud. Remember, we mentioned this is only available, required for a normal internet in China. For the China users, the easiest way to access this service is to insert a Zscaler client connector, what we call ZCC. The authenticated user with the ZCC will always connect to the closest data center or closest Zscaler nodes available for the user. This traffic will go to the ZTE without coming back to the data center. That helps to resolve the backhauling issues. Because of that, we are also basically having the connectivity arise on the Zscaler nodes. Zscaler is doing a Zero Trust basically contextual check for the access from the user by looking at who is accessing what application, at which time, using what kind of device, covering what kind of traffic. Is that a dangerous traffic? Is that a bad actor with a potential attack? Or is that traffic containing sensible data? After looking at all the context, the access can be authorized after checking the policies that you as a customer or organization define. If that authorized access is an internet traffic, the traffic will go to the ISP who is making the traffic split. This is important to notice that the Zscaler partner ISP here inside China is going to do the traffic split for you. If it is a Chinese website's traffic, it goes to the China internet, which means you actually do not have that risk of compliance anymore. If that's the global internet traffic, it breaks out by the ISP to the global internet as well. Since it is a legit internet service provider inside China, you don't have that compliance risk of sending sensitive or blocked information by the Great Firewall to the global internet as well. That is how we basically solve the internet traffic issues for the users in China. How about what if the users require access to private applications?