
ZTNA migration decks draw a clean line from SSL VPN to Zscaler or Cloudflare Access. Deployment reality is messier. The VPN exit problem was never the protocol. Fortinet SSL VPN and Pulse Secure stacked up CVE after CVE (CVE-2018-13379, CVE-2019-11510, CVE-2021-22893) because the appliance sat internet-facing with a flat path behind it. ZTNA shrinks that blast radius and hands over a policy engine nobody wants to own. Every app needs an identity-aware proxy rule. Legacy apps without OIDC land behind a clientless portal that quietly reintroduces session hijacking risk. Split tunneling gets treated as a rollout checkbox when SDP terms say it decides whether lateral movement actually drops. Internal DNS is where rollouts stall. VPN handled resolver access implicitly. Connector-based ZTNA turns it into an explicit design decision. #cybersecurity
