Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

How Zscaler Airgap Simplifies Network Microsegmentation

Zscaler
09/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


And today in this video, I'm going to talk about one of the key challenges affecting corporate networks and how Zscaler's AirGap solution makes it super simple to fix that. So over here, we've got a really simple diagram showing a corporate network with your WAN connections and routing at the top, your core network and switching down below that. And then most networks have begun to segregate traffic, generally based on VLAN. So we'll put VLAN A here and VLAN B over here. And that segregation is generally usually based around use cases. So this usually separates things like corporate devices over here from things like servers or high-risk devices like IoT and OT or guest access. So a different VLAN for each one of those. So generally, companies have deployed segregation by adding firewalls into the network. On these firewalls, we tend to have fairly complicated rule sets, but effectively saying VLAN A can initiate a connection to clients in VLAN B, but clients in VLAN B can't initiate a connection back to VLAN A. In reality, this is complicated sets of IP addresses and lists of IP addresses and port numbers. So what this allows companies to do is to block, for example, into VLAN traffic. So VLAN B in this instance can't talk to VLAN A, but it does nothing to address intra-VLAN traffic. So A1 can talk without going through an enforcement point to A2 and A3. Why this is a problem is that when an attacker compromises the device at VLAN A, it can move laterally across that entire network segment. And in fact, because of the complexity of these firewall rules, generally there's issues and holes, and that attacker can move naturally across the entire network, compromising the entire organisation. We see this time and time again with ransomware attacks. So how does the AirGap solution resolve this? Firstly, we deploy in your existing infrastructure, similarly to a firewall, and this can be done with either virtual or physical appliances or a mix of both. The AirGap solution basically creates a segment of one for every device on the network. So going back to the original problem statement, A1 can now no longer talk to A2 or A3 or the rest of the network without going through an enforcement point. When we deploy the AirGap solution, generally we deploy firstly in learning mode, and what that actually enables is you to get complete observability and discovery of all of your network flows and assets. This means that when you're planning out policy changes, you can understand the impact of those changes before making them. As the solution is deployed, it begins to automatically identify and tag individual assets. So for example, this may be a Windows PC. It looks at different manufacturers or can identify things like printers or other IoT devices. And equally, you can manually tag. So for example, saying this is an ERP system over here. We can also integrate with third parties such as Microsoft Active Directory to grab user and group information, third party databases for additional device information or EDR solutions for posture. What this means is that we can use these tags to build up really simple to understand policy that matches the use cases. For example, a Windows PC with a high posture, so a corporate Windows PC can talk to the printers or a finance user can talk to the ERP system. But one of the standout features of AirGap is with a simple mouse click or API call, we can actually have multiple policies ready on the platform. If you suffer an incident on your network, you can deploy that instantaneously, for example, cutting off Windows to printers, but enabling those finance users to continue to connect to the ERP system because that's a business critical function, thereby enabling you to respond to an incident without having to kill the entire network. So generally, when we look at other solutions in the market today, they only cover a subset of use cases required. They take a really long time to plan and deploy, and throughout that deployment, they lead to a really poor user experience because without the visibility, you can't see what impact your policies are going to have. They lead to problems with the operations teams due to complexity and a relatively poor return on investment because of the complexity and overheads in OPEX. If you compare this to the AirGap solution, firstly, we cover most, if not all, solutions, and I'll leave that at 99% because I'm sure somebody would challenge me to find one that we don't cover. We are super quick to deploy. You can place AirGap in your network in learning mode, understand the flows, and very quickly develop policies without impacting users. And that leads to a really good user experience throughout the deployment. We provide all of that additional visibility to the ops teams, which would usually be requiring another product or products to deliver the same functionality. And that delivers an absolutely fantastic return on investment. So if you'd like to learn more about how AirGap makes micro-segmentation super simple, head on over to zscaler.com and hit request a demo.

TL;DR

  • Traditional VLAN segmentation with firewalls blocks inter-VLAN traffic but does nothing to prevent lateral movement within VLANs, leaving organizations vulnerable to ransomware attacks that spread across network segments.
  • Zscaler Airgap creates a segment of one for every network device, ensuring all communication passes through an enforcement point regardless of VLAN membership.
  • Learning mode deployment provides complete network flow visibility and asset discovery before any policy enforcement, enabling impact assessment of policy changes.
  • Tag-based policies using automatic device identification and Active Directory integration allow simple, use-case-driven rules like allowing finance users to access ERP systems.

The Lateral Movement Problem in Traditional Networks

Traditional network segmentation using VLANs and firewalls creates a fundamental security gap that attackers routinely exploit. While organizations typically separate corporate devices, servers, IoT systems, and guest access into different VLANs with firewall rules controlling inter-VLAN traffic, this approach fails to address intra-VLAN communication. Devices within the same VLAN can communicate freely without passing through any enforcement point, enabling attackers who compromise a single device to move laterally across the entire network segment. The complexity of firewall rule sets often introduces additional vulnerabilities, creating holes that sophisticated attackers exploit during ransomware campaigns to compromise entire organizations.

Airgap's Segment-of-One Architecture

Zscaler Airgap addresses lateral movement by creating what the company calls a segment of one for every device on the network. Deployed as virtual or physical appliances within existing infrastructure, Airgap ensures that no device can communicate with any other device without passing through an enforcement point. The solution initially deploys in learning mode, providing complete observability and discovery of all network flows and assets before any policy enforcement begins. This visibility enables organizations to understand the impact of policy changes before implementing them, avoiding the user experience problems that typically plague microsegmentation deployments. The platform automatically identifies and tags assets by type, manufacturer, and function, and integrates with Microsoft Active Directory, third-party databases, and EDR solutions to enrich device context with user information and security posture data.

Chapters

0:00 - Introduction
0:23 - Traditional Network Segmentation
1:44 - The Lateral Movement Problem
2:23 - Airgap Solution Overview
2:58 - Learning Mode and Asset Discovery
4:11 - Tag-Based Policy Creation
5:04 - Competitive Comparison

Key Quotes

1:52 "A1 can talk without going through an enforcement point to A2 and A3. Why this is a problem is that when an attacker compromises the device at VLAN A, it can move laterally across that entire network segment."
2:38 "The AirGap solution basically creates a Segment of one for every device on the network."
4:38 "But one of the standout features of AirGap is with a simple mouse click or API call, we can actually have multiple policies ready on the platform."
5:52 "We are super quick to deploy. You can place AirGap in your network in learning mode, understand the flows, and very quickly develop policies without impacting users."

FAQ

How does Airgap deploy without disrupting existing network operations?

Airgap deploys initially in learning mode using virtual or physical appliances within existing infrastructure. This mode provides complete observability and discovery of all network flows and assets without enforcing any policies, allowing organizations to understand traffic patterns and plan policy changes before implementation.

How does Airgap handle emergency security incidents?

Organizations can prepare multiple policies on the platform in advance. During an incident, a single mouse click or API call can instantly deploy a more restrictive policy, such as cutting off Windows devices from printers while maintaining finance user access to business-critical ERP systems.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • Zero Trust
  • Technical Deep Dive
  • Demo
  • microsegmentation
  • lateral movement prevention
  • network security
  • zero trust networking
  • VLAN segmentation
  • ransomware defense
  • asset discovery
  • network visibility
  • policy automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: How Zscaler Airgap Simplifies Network Microsegmentation

              Industry Events (Sponsor Hosted)

              • Oct
                01

                Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?

                10/01/202601:00 PM ET
                • Oct
                  13

                  Interactive Q&A Session on DatasecAI 2026 Insights and Innovations

                  10/13/202602:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: A Comprehensive Approach to Visibility and Control
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-a-comprehensive-approach-to-visibility-and-control/
                    • 10/01/2026
                      01:00 PM
                      10/01/2026
                      Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?
                      https://www.truthinit.com/index.php/channel/2144/meta-muse-101-embracing-the-arrival-of-the-agentic-internet-whats-next/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Interactive Q&A Session on DatasecAI 2026 Insights and Innovations
                      https://www.truthinit.com/index.php/channel/2141/interactive-q-a-session-on-datasecai-2026-insights-and-innovations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version