- Network Security
- Product
- Solution
How Hillstone and Sophos Are Building Their Own Take on ZTNA
By Pivithuru Milan Perera4 min read

Sophos ZTNA: Built Around the EndpointSophos approached ZTNA as a natural extension of its endpoint and firewall ecosystem rather than as a standalone bolt-on product. Sophos ZTNA is designed to provide transparent, secure application access by combining device posture checks, its Synchronized Security framework, and Workspace Protection features to protect users wherever they work.
A few things stand out about how Sophos has positioned this:
- Built for the cloud from the start, Sophos ZTNA is fully delivered and managed through Sophos Central. Organizations already using Sophos Firewall or Intercept X can manage ZTNA policies from the same centralized console, simplifying administration and improving visibility across their security environment.
- Deep integration with the Sophos security ecosystem. Sophos ZTNA works seamlessly with Sophos Endpoint, Sophos Firewall, and Sophos Workspace Protection. Unlike traditional access solutions that only verify user identity, Sophos ZTNA also evaluates the security posture of the device before granting access. This ensures that only authenticated users on healthy, compliant devices can connect to corporate resources.
- Perhaps the most distinctive feature is how Sophos handles a compromised device. Device health information is shared across Sophos Endpoint, Sophos Firewall, and ZTNA so that if a device shows signs of an active threat, it's automatically isolated and contained until it's cleaned up, preventing ransomware from spreading further across the network.
- The platform supports clientless access to browser-based web apps, plus a client-based option for "thick" applications like SSH, VNC, and RDP, with access policies that can be based on user groups or on Synchronized Security health checks. On the infrastructure side, Sophos also expanded into a fully cloud-brokered "ZTNA-as-a-Service" model, in addition to the existing on-premises gateway options across VMware, Hyper-V, and other platforms.
For organizations already using Sophos solutions, Sophos ZTNA integrates seamlessly with their existing security infrastructure. Managed through the same platform and leveraging the same security intelligence, it extends the benefits of Sophos Synchronized Security without requiring a separate management framework or significant additional training.
Hillstone Networks ZTNA: Built on the Firewall FoundationHillstone takes a different starting point. Rather than building ZTNA around endpoint telemetry, it builds it on top of its existing next-generation firewall (NGFW) line and centralized management platform.
- Hillstone's ZTNA solution combines its Hillstone Security Management (HSM) platform with its NGFW product line, supporting a wide range of authentication schemes along with popular enterprise devices and operating systems. For existing Hillstone customers, this has a practical upside: the ZTNA capability can often be enabled on existing next-gen firewalls with a software upgrade, letting customers adopt a zero-trust strategy with minimal additional cost or effort.
- Hillstone describes its core principle as authenticating the user and checking the endpoint's health status before granting access privileges to specific apps or services on a need-to-know basis. That continuous evaluation is framed almost like an extension of Hillstone's SD-WAN logic: just as SD-WAN continuously monitors links to optimize routing, the ZTNA component continuously monitors the context around an endpoint to decide, moment to moment, whether access should be granted or blocked.
- The client agent evaluates a range of device signals operating system patch levels, MAC address binding, hardware and software certificates, antivirus status, and browser security and patch levels and weighs all of that against policy before granting access rights.
- Policy management is centralized and pushed out to distributed ZTNA gateways, giving administrators global visibility through a single operational view, with zero-touch provisioning to simplify large deployments.
- Hillstone leans into two specific buyer profiles. On one end, it positions ZTNA as an extra layer of protection for government entities and enterprises facing strict compliance requirements, where policies can require multi-factor authentication and trusted devices for remote employees. On the other end, it's also pitched at service providers helping smaller businesses many of which have little in-house IT expertise secure remote and work-from-anywhere access to company resources.
In short, Hillstone's story is "zero trust without ripping out your firewall." If your security architecture already revolves around Hillstone's NGFW and HSM, ZTNA becomes an incremental capability rather than a new platform to deploy and manage.
The TakeawayNeither Sophos nor Hillstone is trying to out-feature the ZTNA market leaders on raw scale both are leaning into what they already do well. Sophos leverages its endpoint telemetry and Synchronized Security story to make ZTNA feel like a natural extension of a product you might already be running. Hillstone leverages its firewall install base and management platform to make ZTNA feel like an upgrade rather than a migration.
When selecting a ZTNA solution, organizations should consider not only the features offered but also how well the solution integrates with their existing security infrastructure. Vendors with an established presence in the environment, such as through firewalls, endpoint protection, or centralized management platforms, can simplify deployment, reduce operational complexity, and accelerate adoption.
Disclosure: this post draws on publicly available vendor documentation and marketing materials from Sophos and Hillstone Networks. As with any vendor comparison, it's worth validating current feature sets and licensing details directly with each vendor, since ZTNA products in this space are evolving quickly.
Keep reading
More articles
Explore other writeups on network security, firewalls, and practical engineering.

VLAN Basics: Why We Split One Switch Into Many
Tags, ports, PVIDs, and trunks explained from the ground up, starting with the problem VLANs actually solve

Why CCNA, CCNP, AWS, Azure, and ISC2 Certifications Are Important for IT Professionals (Part 2).
with AI tools automating more technical work, do certifications still carry weight? The data says yes, and arguably more than before. Read the Part 2 of our previous conversation about certification courses.

A New Defender Zero-Day Is Out in the Wild And Microsoft Is Racing to Patch It.
If you thought Windows Defender was the one piece of your security stack that couldn't be turned against you, this week's news might change your mind. Microsoft has confirmed it's building an emergency fix for a freshly disclosed vulnerability in its own malware-scanning engine. The bug is being called RoguePlanet. Read the complete article here.

Why CCNA, CCNP, AWS, Azure, and ISC2 Certifications Are Important for IT Professionals (Part 1)
If you're trying to break into IT in 2026, you've probably noticed the same five acronyms showing up everywhere: CCNA, CCNP, AWS, Azure, and ISC2. They come from different vendors, cover different skills, and lead to different jobs, but they all share one thing in common: employers are actively paying more for people who hold them. The challenge for beginners isn't whether certifications matter (they clearly do), it's figuring out which one to chase first when you can't realistically pursue all five at once. This guide breaks down what each certification actually does for your career, what the current salary and demand data looks like, and most importantly, how to decide where to start. let's understand the certification path in depth for a better career path.