Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler: Zero Trust Gateway for AWS Workloads

Zscaler
06/22/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Nicole Lippert. I'm a security strategist at AWS. And I'm Niels Ullmann. I'm principal product specialist at Zscaler. Since 2022, Zscaler and AWS combine zero-trust policies and implications together with cloud innovation. What that means, what it entails, and how we can help you to accelerate your cloud journey, this is what you're going to see in the video today. Thank you, Nicole. Today, we'd like to talk about the zero-trust gateway. Before we talk about the zero-trust gateway, I'd really like to quickly talk about the entire Zscaler platform and the things you may already know or not know. So we started off with connecting your users and their devices to the zero-trust exchange. This is things that you might most likely have done already. Most recently, we also added the capability of connecting your branches, your offices, or your IoT devices through the zero-trust branch device also to the zero-trust exchange to be able to connect to your applications. Another innovation that we have recently released is connecting your AI infrastructure to the zero-trust exchange. And right in this, I'd like to introduce you to the capabilities that we have developed together with AWS in order to connect your workloads in a secure fashion to the zero-trust exchange. And from there, obviously, into the internet, with your SaaS applications, or with your private applications. But before we really look into the zero-trust gateway, let's quickly reiterate on what the zero-trust exchange can do for your workloads. The Zscaler zero-trust exchange is a full proxy architecture. That means that all your workloads in AWS, when they are forwarded to the zero-trust exchange, the first thing that happens in the full proxy architecture is that the connection has been terminated. With this, we ensure that we have full capabilities to inspect the entire traffic. But with what we really first start is that we do verify, or we can verify, the identity of your workloads. So it's not just important for your users to be correctly identified, it's even more important for your workloads, for your servers, for your really important applications. Now as we have the identity of the workload, we want to control the risk of this workload. So all the capabilities that we have put in place to figure out the risk exposure are now being in place. And ultimately, we are going into policy enforcement. All the types of policies that we can do enforce, you do see here on the right side. It starts with DNS control, all the way down to sandbox control policies. Most importantly, firewall policies, URL policies, intrusion prevention policies, all that can be set within the stack. And in combination with the risk and the identity that is applied to this workload. If everything is right, we are going again to initiate the connection from the zero-trust exchange out to the internet, to your private applications or SaaS services you are consuming from within your servers. Now as we have reiterated on the capabilities of the zero-trust exchange and what it can do for your workloads, let's have a look into a typical AWS deployment and the involved building blocks and capabilities. Very often and most customers like you do build a so-called transit gateway architecture. Transit gateway architecture means that you are using the AWS transit gateway to connect through routing all the different building blocks with each other. Very often, and as you can see here, it starts with a north-south security VPC. So in this north-south security VPC, we are bundling all the functions and capabilities that you do want to apply to the traffic from your workloads out to the internet. The next building block is typically the east-west traffic block. So here we have the firewall capabilities or other capabilities that you do bundle in this block to have inspection and security provided for your workload to workload traffic. So for example, when a workload in here needs to talk to a workload over here. And how that typically works in such an environment is in order to inject all those different functionalities, when this workload wants to connect to this application, we are going out to the transit gateway, we are going back in the east-west VPC and again back in the transit gateway, finally to your application. As you can imagine, and as you see, this is super complex setup. So this is basically the number one challenge with this kind of setup. You need a lot of terraform code or whatever you're using for deploying your workloads. It's not easy. And the most obvious one is routing. You need lots of routing tables, you need to understand how all that comes together and how to maintain that in the workflow. Ultimately, especially when one of those workloads wants to connect to the internet, it's also very often an identity problem. So how can I identify the workload and apply the right policies for those workloads? To make this even more complex, this is only one application in one VPC in one region. But as you look into your enterprise catalog, you will figure out you have lots of applications in many regions. And so the overall maintenance and operations effort for this solution is super high. This brings us right to Zscaler's latest innovation, the Zero Trust Gateway. So the Zero Trust Gateway is basically the cloud connector provided as a service to you. This was the number one ask from our customers, from you to us. You don't want to run the cloud connector on your own, but rather consume it as a service. So the cloud connector is running, the Zero Trust Gateway is running in our accounts. And we are running it for you. You don't need to worry about deployment, because this is happening automatically. You don't need to worry about logging, because we are taking care for the logs, as well as we are monitoring the solution. And obviously, the entire solution is built to scale, so that at no point you need to worry about the scalability or the availability of this service. With all these achieved, the cloud connector will automatically connect to the closest and best Zero Trust Exchange near to your infrastructure. How easy this really is? We have recorded a quick video for you, showing you how to deploy the Zero Trust Gateway in your region of choice. We are here in the experience center, the home of all Zscaler configurations, and within the connector section, you see a new menu item called Zero Trust Gateway. We do have already a gateway deployed in Frankfurt. Now we are adding a new gateway into the London region. All information that you do really need is to figure out a name that you want to give to the gateway, and figure out the availability zones in which you'd like to provide the service. On the next screen, all we need to define is who can use that gateway. Is it only you? Is it only one account? Is it all of the corporate accounts? So up to you. Now with the gateway being deployed, we can focus on how do we connect our applications to the actual Zero Trust Gateway. And to do so, let's look on what we have done. So we do have the Zero Trust Gateway now deployed in a given region. As a result, we do have a service name for this gateway load balancer service. If for each of your applications, you'd like to connect through the Zero Trust Gateway with the internet or other applications, you can connect by simply deploying a gateway load balancer endpoint, and connect it to the service name of the gateway load balancer that we have created as part of the Zero Trust Gateway. Again, this is a really easy process. Everyone who has worked with AWS knows very well how that works. But to show you, we have recorded another video that we would like to show you. Now we are in the AWS console. As I said, I created already a VPC called null-ztg-demo-pool. And we do need the subnets that are available within this VPC. In this VPC, we are going to create an endpoint service that will be linked to the service name that we have provided or created as part of the Zero Trust Gateway. You can look that up in the Zero Trust Gateway console, copy it, and enter it into the AWS management console. Now, with the endpoint service being verified, we can decide into which subnets and VPC we like to deploy the gateway load balancer endpoint service. And we are done on the AWS side. So we can move back to our Zero Trust Exchange, to our high-level overview, and repeat that process multiple times. So it really doesn't matter how many of your applications you are connecting to the Zero Trust Gateway. The process is always the same. Take a gateway load balancer endpoint and connect it with the service that we have provided for you. The usual scalability of that is, as I said earlier, really good. So don't worry about it. Typically, you are deploying one Zero Trust Gateway per region. And then you can connect all your applications, no matter if dev or ops or production, right to the same gateway. And now, let's go back to where we started. I hope I could show you how easy it is to connect your workloads in AWS through the Zero Trust Gateway with our exchange. And following this with your applications, with your SaaS services, or just with the internet. So really, you can onboard your workloads in the speed you need and in the dimension and scale you need for your business. Thank you very much. If you have any further questions, please reach out to our sales team or look on our website. And I hope to see you soon on this channel.

TL;DR

  • Zscaler's Zero Trust Gateway provides a fully managed cloud connector service for AWS workloads, eliminating the need to deploy and maintain cloud connectors while automatically scaling to meet demand.
  • The solution simplifies traditional transit gateway architectures by replacing complex routing tables and multiple security VPCs with Gateway Load Balancer endpoints that connect directly to Zscaler's Zero Trust Exchange.
  • All traffic undergoes full proxy inspection with identity verification, risk assessment, and comprehensive policy enforcement including firewall, URL filtering, intrusion prevention, and sandboxing capabilities.
  • Deployment requires only selecting a region and availability zones in the Zscaler console, then creating Gateway Load Balancer endpoints in application VPCs using the provided service name—a process that scales across unlimited applications and regions.

Zero Trust Gateway Overview and Architecture

This technical demonstration introduces Zscaler's Zero Trust Gateway, a managed cloud connector service designed to simplify secure connectivity for AWS workloads. The session contrasts traditional transit gateway architectures—which require complex routing tables, multiple VPCs for north-south and east-west traffic, and significant operational overhead—with Zscaler's streamlined approach. The Zero Trust Gateway runs as a fully managed service in Zscaler's infrastructure, eliminating the need for customers to deploy, monitor, or scale cloud connectors manually. The solution leverages AWS Gateway Load Balancer endpoints to connect application VPCs to the Zero Trust Exchange, where traffic undergoes full proxy inspection with identity verification, risk assessment, and comprehensive policy enforcement including DNS control, firewall rules, URL filtering, intrusion prevention, and sandboxing capabilities.

Deployment Process and Multi-Region Scalability

The demonstration walks through the deployment workflow, showing how administrators can provision a Zero Trust Gateway in any AWS region through the Zscaler console by simply selecting a gateway name and availability zones. Once deployed, the gateway generates a service name that applications reference when creating Gateway Load Balancer endpoints in their VPCs. This architecture supports multiple applications across development, operations, and production environments connecting to a single regional gateway, with automatic routing to the nearest Zero Trust Exchange point of presence. The solution addresses common enterprise challenges including workload identity management, policy consistency across multi-region deployments, and the operational complexity of maintaining traditional hub-and-spoke security architectures with separate north-south and east-west inspection VPCs.

Chapters

0:00 - Introduction and Partnership Overview
0:33 - Zscaler Platform Capabilities
2:12 - Zero Trust Exchange Architecture
4:18 - Traditional AWS Transit Gateway Challenges
6:46 - Zero Trust Gateway Solution
7:57 - Gateway Deployment Demo
8:46 - Connecting Applications via GWLB Endpoints
11:09 - Summary and Next Steps

Key Quotes

0:15 "Since 2022, Zscaler and AWS combine zero-trust policies and implications together with cloud innovation."
6:59 "The Zero Trust Gateway is basically the cloud connector provided as a service to you. This was the number one ask from our customers, from you to us. You don't want to run the cloud connector on your own, but rather consume it as a service."
7:18 "You don't need to worry about deployment, because this is happening automatically. You don't need to worry about logging, because we are taking care for the logs, as well as we are monitoring the solution."
11:02 "Typically, you are deploying one Zero Trust Gateway per region. And then you can connect all your applications, no matter if dev or ops or production, right to the same gateway."

FAQ

How does the Zero Trust Gateway differ from deploying Zscaler cloud connectors directly in my AWS environment?

The Zero Trust Gateway is a fully managed service that runs in Zscaler's infrastructure rather than your AWS accounts. You don't need to deploy, monitor, scale, or maintain any cloud connector instances—Zscaler handles all operational aspects including logging and availability. You simply create Gateway Load Balancer endpoints in your application VPCs that connect to the service name provided by the Zero Trust Gateway.

Can I connect multiple applications in different VPCs to the same Zero Trust Gateway?

Yes, you typically deploy one Zero Trust Gateway per AWS region and can connect unlimited applications to it regardless of whether they're in development, operations, or production environments. Each application VPC creates its own Gateway Load Balancer endpoint that references the same Zero Trust Gateway service name, and the solution automatically scales to handle the traffic.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Zero Trust
  • Network Security
  • Technical Deep Dive
  • Demo
  • Zero Trust Architecture
  • AWS Security
  • Cloud Workload Protection
  • Gateway Load Balancer
  • Transit Gateway Architecture
  • Cloud Connector Services
  • Multi-Region Deployment
  • Secure Internet Gateway
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler: Zero Trust Gateway for AWS Workloads

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version