Pivithuru Milan PereraSecurity · Networks
Resume
  • Network Security
  • Product
  • Solution

How Hillstone and Sophos Are Building Their Own Take on ZTNA

By Pivithuru Milan Perera4 min read

Cover image for How Hillstone and Sophos Are Building Their Own Take on ZTNA
Zero Trust Network Access (ZTNA) has become one of the most talked-about categories in enterprise security, and for good reason. As remote and hybrid work became permanent rather than temporary, the old model of "connect to the VPN and you're on the network" started to look like a liability rather than a convenience. ZTNA flips that model: instead of granting broad access to a network segment, it grants narrow, identity-based, continuously verified access to a specific application and nothing else.


Most writeups on this topic default to the big-name players, but it's worth looking at how two other established security vendors, Sophos and Hillstone Networks, have built out their own ZTNA offerings. Both come at the problem from a slightly different angle, shaped by where they already had a strong footprint, both Next generation firewall and endpoint protection for Sophos, and next-generation firewalls for Hillstone.
Sophos ZTNA: Built Around the EndpointSophos approached ZTNA as a natural extension of its endpoint and firewall ecosystem rather than as a standalone bolt-on product. Sophos ZTNA is designed to provide transparent, secure application access by combining device posture checks, its Synchronized Security framework, and Workspace Protection features to protect users wherever they work.

A few things stand out about how Sophos has positioned this:
  • Built for the cloud from the start, Sophos ZTNA is fully delivered and managed through Sophos Central. Organizations already using Sophos Firewall or Intercept X can manage ZTNA policies from the same centralized console, simplifying administration and improving visibility across their security environment.
  • Deep integration with the Sophos security ecosystem. Sophos ZTNA works seamlessly with Sophos Endpoint, Sophos Firewall, and Sophos Workspace Protection. Unlike traditional access solutions that only verify user identity, Sophos ZTNA also evaluates the security posture of the device before granting access. This ensures that only authenticated users on healthy, compliant devices can connect to corporate resources.
  • Perhaps the most distinctive feature is how Sophos handles a compromised device. Device health information is shared across Sophos Endpoint, Sophos Firewall, and ZTNA so that if a device shows signs of an active threat, it's automatically isolated and contained until it's cleaned up, preventing ransomware from spreading further across the network.
  • The platform supports clientless access to browser-based web apps, plus a client-based option for "thick" applications like SSH, VNC, and RDP, with access policies that can be based on user groups or on Synchronized Security health checks. On the infrastructure side, Sophos also expanded into a fully cloud-brokered "ZTNA-as-a-Service" model, in addition to the existing on-premises gateway options across VMware, Hyper-V, and other platforms.

For organizations already using Sophos solutions, Sophos ZTNA integrates seamlessly with their existing security infrastructure. Managed through the same platform and leveraging the same security intelligence, it extends the benefits of Sophos Synchronized Security without requiring a separate management framework or significant additional training.
Hillstone Networks ZTNA: Built on the Firewall FoundationHillstone takes a different starting point. Rather than building ZTNA around endpoint telemetry, it builds it on top of its existing next-generation firewall (NGFW) line and centralized management platform.
  • Hillstone's ZTNA solution combines its Hillstone Security Management (HSM) platform with its NGFW product line, supporting a wide range of authentication schemes along with popular enterprise devices and operating systems. For existing Hillstone customers, this has a practical upside: the ZTNA capability can often be enabled on existing next-gen firewalls with a software upgrade, letting customers adopt a zero-trust strategy with minimal additional cost or effort.
  • Hillstone describes its core principle as authenticating the user and checking the endpoint's health status before granting access privileges to specific apps or services on a need-to-know basis. That continuous evaluation is framed almost like an extension of Hillstone's SD-WAN logic: just as SD-WAN continuously monitors links to optimize routing, the ZTNA component continuously monitors the context around an endpoint to decide, moment to moment, whether access should be granted or blocked.
  • The client agent evaluates a range of device signals operating system patch levels, MAC address binding, hardware and software certificates, antivirus status, and browser security and patch levels and weighs all of that against policy before granting access rights.
  • Policy management is centralized and pushed out to distributed ZTNA gateways, giving administrators global visibility through a single operational view, with zero-touch provisioning to simplify large deployments.
  • Hillstone leans into two specific buyer profiles. On one end, it positions ZTNA as an extra layer of protection for government entities and enterprises facing strict compliance requirements, where policies can require multi-factor authentication and trusted devices for remote employees. On the other end, it's also pitched at service providers helping smaller businesses many of which have little in-house IT expertise secure remote and work-from-anywhere access to company resources.

In short, Hillstone's story is "zero trust without ripping out your firewall." If your security architecture already revolves around Hillstone's NGFW and HSM, ZTNA becomes an incremental capability rather than a new platform to deploy and manage.

The TakeawayNeither Sophos nor Hillstone is trying to out-feature the ZTNA market leaders on raw scale both are leaning into what they already do well. Sophos leverages its endpoint telemetry and Synchronized Security story to make ZTNA feel like a natural extension of a product you might already be running. Hillstone leverages its firewall install base and management platform to make ZTNA feel like an upgrade rather than a migration.
When selecting a ZTNA solution, organizations should consider not only the features offered but also how well the solution integrates with their existing security infrastructure. Vendors with an established presence in the environment, such as through firewalls, endpoint protection, or centralized management platforms, can simplify deployment, reduce operational complexity, and accelerate adoption.
Disclosure: this post draws on publicly available vendor documentation and marketing materials from Sophos and Hillstone Networks. As with any vendor comparison, it's worth validating current feature sets and licensing details directly with each vendor, since ZTNA products in this space are evolving quickly.

Keep reading

More articles

Explore other writeups on network security, firewalls, and practical engineering.