Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler: Zero Trust Gateway for AWS Workloads

Zscaler
06/22/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Nicole Lippert. I'm a security strategist at AWS. And I'm Niels Ullmann. I'm principal product specialist at Zscaler. Since 2022, Zscaler and AWS combine zero-trust policies and implications together with cloud innovation. What that means, what it entails, and how we can help you to accelerate your cloud journey, this is what you're going to see in the video today. Thank you, Nicole. Today, we'd like to talk about the zero-trust gateway. Before we talk about the zero-trust gateway, I'd really like to quickly talk about the entire Zscaler platform and the things you may already know or not know. So we started off with connecting your users and their devices to the zero-trust exchange. This is things that you might most likely have done already. Most recently, we also added the capability of connecting your branches, your offices, or your IoT devices through the zero-trust branch device also to the zero-trust exchange to be able to connect to your applications. Another innovation that we have recently released is connecting your AI infrastructure to the zero-trust exchange. And right in this, I'd like to introduce you to the capabilities that we have developed together with AWS in order to connect your workloads in a secure fashion to the zero-trust exchange. And from there, obviously, into the internet, with your SaaS applications, or with your private applications. But before we really look into the zero-trust gateway, let's quickly reiterate on what the zero-trust exchange can do for your workloads. The Zscaler zero-trust exchange is a full proxy architecture. That means that all your workloads in AWS, when they are forwarded to the zero-trust exchange, the first thing that happens in the full proxy architecture is that the connection has been terminated. With this, we ensure that we have full capabilities to inspect the entire traffic. But with what we really first start is that we do verify, or we can verify, the identity of your workloads. So it's not just important for your users to be correctly identified, it's even more important for your workloads, for your servers, for your really important applications. Now as we have the identity of the workload, we want to control the risk of this workload. So all the capabilities that we have put in place to figure out the risk exposure are now being in place. And ultimately, we are going into policy enforcement. All the types of policies that we can do enforce, you do see here on the right side. It starts with DNS control, all the way down to sandbox control policies. Most importantly, firewall policies, URL policies, intrusion prevention policies, all that can be set within the stack. And in combination with the risk and the identity that is applied to this workload. If everything is right, we are going again to initiate the connection from the zero-trust exchange out to the internet, to your private applications or SaaS services you are consuming from within your servers. Now as we have reiterated on the capabilities of the zero-trust exchange and what it can do for your workloads, let's have a look into a typical AWS deployment and the involved building blocks and capabilities. Very often and most customers like you do build a so-called transit gateway architecture. Transit gateway architecture means that you are using the AWS transit gateway to connect through routing all the different building blocks with each other. Very often, and as you can see here, it starts with a north-south security VPC. So in this north-south security VPC, we are bundling all the functions and capabilities that you do want to apply to the traffic from your workloads out to the internet. The next building block is typically the east-west traffic block. So here we have the firewall capabilities or other capabilities that you do bundle in this block to have inspection and security provided for your workload to workload traffic. So for example, when a workload in here needs to talk to a workload over here. And how that typically works in such an environment is in order to inject all those different functionalities, when this workload wants to connect to this application, we are going out to the transit gateway, we are going back in the east-west VPC and again back in the transit gateway, finally to your application. As you can imagine, and as you see, this is super complex setup. So this is basically the number one challenge with this kind of setup. You need a lot of terraform code or whatever you're using for deploying your workloads. It's not easy. And the most obvious one is routing. You need lots of routing tables, you need to understand how all that comes together and how to maintain that in the workflow. Ultimately, especially when one of those workloads wants to connect to the internet, it's also very often an identity problem. So how can I identify the workload and apply the right policies for those workloads? To make this even more complex, this is only one application in one VPC in one region. But as you look into your enterprise catalog, you will figure out you have lots of applications in many regions. And so the overall maintenance and operations effort for this solution is super high. This brings us right to Zscaler's latest innovation, the Zero Trust Gateway. So the Zero Trust Gateway is basically the cloud connector provided as a service to you. This was the number one ask from our customers, from you to us. You don't want to run the cloud connector on your own, but rather consume it as a service. So the cloud connector is running, the Zero Trust Gateway is running in our accounts. And we are running it for you. You don't need to worry about deployment, because this is happening automatically. You don't need to worry about logging, because we are taking care for the logs, as well as we are monitoring the solution. And obviously, the entire solution is built to scale, so that at no point you need to worry about the scalability or the availability of this service. With all these achieved, the cloud connector will automatically connect to the closest and best Zero Trust Exchange near to your infrastructure. How easy this really is? We have recorded a quick video for you, showing you how to deploy the Zero Trust Gateway in your region of choice. We are here in the experience center, the home of all Zscaler configurations, and within the connector section, you see a new menu item called Zero Trust Gateway. We do have already a gateway deployed in Frankfurt. Now we are adding a new gateway into the London region. All information that you do really need is to figure out a name that you want to give to the gateway, and figure out the availability zones in which you'd like to provide the service. On the next screen, all we need to define is who can use that gateway. Is it only you? Is it only one account? Is it all of the corporate accounts? So up to you. Now with the gateway being deployed, we can focus on how do we connect our applications to the actual Zero Trust Gateway. And to do so, let's look on what we have done. So we do have the Zero Trust Gateway now deployed in a given region. As a result, we do have a service name for this gateway load balancer service. If for each of your applications, you'd like to connect through the Zero Trust Gateway with the internet or other applications, you can connect by simply deploying a gateway load balancer endpoint, and connect it to the service name of the gateway load balancer that we have created as part of the Zero Trust Gateway. Again, this is a really easy process. Everyone who has worked with AWS knows very well how that works. But to show you, we have recorded another video that we would like to show you. Now we are in the AWS console. As I said, I created already a VPC called null-ztg-demo-pool. And we do need the subnets that are available within this VPC. In this VPC, we are going to create an endpoint service that will be linked to the service name that we have provided or created as part of the Zero Trust Gateway. You can look that up in the Zero Trust Gateway console, copy it, and enter it into the AWS management console. Now, with the endpoint service being verified, we can decide into which subnets and VPC we like to deploy the gateway load balancer endpoint service. And we are done on the AWS side. So we can move back to our Zero Trust Exchange, to our high-level overview, and repeat that process multiple times. So it really doesn't matter how many of your applications you are connecting to the Zero Trust Gateway. The process is always the same. Take a gateway load balancer endpoint and connect it with the service that we have provided for you. The usual scalability of that is, as I said earlier, really good. So don't worry about it. Typically, you are deploying one Zero Trust Gateway per region. And then you can connect all your applications, no matter if dev or ops or production, right to the same gateway. And now, let's go back to where we started. I hope I could show you how easy it is to connect your workloads in AWS through the Zero Trust Gateway with our exchange. And following this with your applications, with your SaaS services, or just with the internet. So really, you can onboard your workloads in the speed you need and in the dimension and scale you need for your business. Thank you very much. If you have any further questions, please reach out to our sales team or look on our website. And I hope to see you soon on this channel.

TL;DR

  • Zscaler's Zero Trust Gateway provides a fully managed cloud connector service for AWS workloads, eliminating the need to deploy and maintain cloud connectors while automatically scaling to meet demand.
  • The solution simplifies traditional transit gateway architectures by replacing complex routing tables and multiple security VPCs with Gateway Load Balancer endpoints that connect directly to Zscaler's Zero Trust Exchange.
  • All traffic undergoes full proxy inspection with identity verification, risk assessment, and comprehensive policy enforcement including firewall, URL filtering, intrusion prevention, and sandboxing capabilities.
  • Deployment requires only selecting a region and availability zones in the Zscaler console, then creating Gateway Load Balancer endpoints in application VPCs using the provided service name—a process that scales across unlimited applications and regions.

Zero Trust Gateway Overview and Architecture

This technical demonstration introduces Zscaler's Zero Trust Gateway, a managed cloud connector service designed to simplify secure connectivity for AWS workloads. The session contrasts traditional transit gateway architectures—which require complex routing tables, multiple VPCs for north-south and east-west traffic, and significant operational overhead—with Zscaler's streamlined approach. The Zero Trust Gateway runs as a fully managed service in Zscaler's infrastructure, eliminating the need for customers to deploy, monitor, or scale cloud connectors manually. The solution leverages AWS Gateway Load Balancer endpoints to connect application VPCs to the Zero Trust Exchange, where traffic undergoes full proxy inspection with identity verification, risk assessment, and comprehensive policy enforcement including DNS control, firewall rules, URL filtering, intrusion prevention, and sandboxing capabilities.

Deployment Process and Multi-Region Scalability

The demonstration walks through the deployment workflow, showing how administrators can provision a Zero Trust Gateway in any AWS region through the Zscaler console by simply selecting a gateway name and availability zones. Once deployed, the gateway generates a service name that applications reference when creating Gateway Load Balancer endpoints in their VPCs. This architecture supports multiple applications across development, operations, and production environments connecting to a single regional gateway, with automatic routing to the nearest Zero Trust Exchange point of presence. The solution addresses common enterprise challenges including workload identity management, policy consistency across multi-region deployments, and the operational complexity of maintaining traditional hub-and-spoke security architectures with separate north-south and east-west inspection VPCs.

Chapters

0:00 - Introduction and Partnership Overview
0:33 - Zscaler Platform Capabilities
2:12 - Zero Trust Exchange Architecture
4:18 - Traditional AWS Transit Gateway Challenges
6:46 - Zero Trust Gateway Solution
7:57 - Gateway Deployment Demo
8:46 - Connecting Applications via GWLB Endpoints
11:09 - Summary and Next Steps

Key Quotes

0:15 "Since 2022, Zscaler and AWS combine zero-trust policies and implications together with cloud innovation."
6:59 "The Zero Trust Gateway is basically the cloud connector provided as a service to you. This was the number one ask from our customers, from you to us. You don't want to run the cloud connector on your own, but rather consume it as a service."
7:18 "You don't need to worry about deployment, because this is happening automatically. You don't need to worry about logging, because we are taking care for the logs, as well as we are monitoring the solution."
11:02 "Typically, you are deploying one Zero Trust Gateway per region. And then you can connect all your applications, no matter if dev or ops or production, right to the same gateway."

FAQ

How does the Zero Trust Gateway differ from deploying Zscaler cloud connectors directly in my AWS environment?

The Zero Trust Gateway is a fully managed service that runs in Zscaler's infrastructure rather than your AWS accounts. You don't need to deploy, monitor, scale, or maintain any cloud connector instances—Zscaler handles all operational aspects including logging and availability. You simply create Gateway Load Balancer endpoints in your application VPCs that connect to the service name provided by the Zero Trust Gateway.

Can I connect multiple applications in different VPCs to the same Zero Trust Gateway?

Yes, you typically deploy one Zero Trust Gateway per AWS region and can connect unlimited applications to it regardless of whether they're in development, operations, or production environments. Each application VPC creates its own Gateway Load Balancer endpoint that references the same Zero Trust Gateway service name, and the solution automatically scales to handle the traffic.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Zero Trust
  • Network Security
  • Technical Deep Dive
  • Demo
  • Zero Trust Architecture
  • AWS Security
  • Cloud Workload Protection
  • Gateway Load Balancer
  • Transit Gateway Architecture
  • Cloud Connector Services
  • Multi-Region Deployment
  • Secure Internet Gateway
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler: Zero Trust Gateway for AWS Workloads

              Upcoming Webinar Calendar

              • 06/24/2026
                11:00 AM
                06/24/2026
                Accelerating Insights on AI Innovation and Trends
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-innovation-and-trends/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Implementing AgenticTrust for Transformative Engagement
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-implementing-agentictrust-for-transformative-engagement/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/15/2026
                12:00 PM
                07/15/2026
                Discover How Cyera Is Transforming Agent Security Approaches
                https://www.truthinit.com/index.php/channel/2036/discover-how-cyera-is-transforming-agent-security-approaches/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                24

                Accelerating Insights on AI Innovation and Trends

                06/24/202611:00 AM ET
                • Jun
                  25

                  Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                  06/25/202601:00 PM ET
                  • Jun
                    30

                    Mastering Active Directory Certificate Services for Long-Term Success

                    06/30/202601:00 PM ET
                    • Jul
                      01

                      Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                      07/01/202604:00 AM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version