- Network Security
- Product
- Solution
How Hillstone and Sophos Are Building Their Own Take on ZTNA
By Pivithuru Milan Perera4 min read

Sophos ZTNA: Built Around the EndpointSophos approached ZTNA as a natural extension of its endpoint and firewall ecosystem rather than as a standalone bolt-on product. Sophos ZTNA is designed to provide transparent, secure application access by combining device posture checks, its Synchronized Security framework, and Workspace Protection features to protect users wherever they work.
A few things stand out about how Sophos has positioned this:
- Built for the cloud from the start, Sophos ZTNA is fully delivered and managed through Sophos Central. Organizations already using Sophos Firewall or Intercept X can manage ZTNA policies from the same centralized console, simplifying administration and improving visibility across their security environment.
- Deep integration with the Sophos security ecosystem. Sophos ZTNA works seamlessly with Sophos Endpoint, Sophos Firewall, and Sophos Workspace Protection. Unlike traditional access solutions that only verify user identity, Sophos ZTNA also evaluates the security posture of the device before granting access. This ensures that only authenticated users on healthy, compliant devices can connect to corporate resources.
- Perhaps the most distinctive feature is how Sophos handles a compromised device. Device health information is shared across Sophos Endpoint, Sophos Firewall, and ZTNA so that if a device shows signs of an active threat, it's automatically isolated and contained until it's cleaned up, preventing ransomware from spreading further across the network.
- The platform supports clientless access to browser-based web apps, plus a client-based option for "thick" applications like SSH, VNC, and RDP, with access policies that can be based on user groups or on Synchronized Security health checks. On the infrastructure side, Sophos also expanded into a fully cloud-brokered "ZTNA-as-a-Service" model, in addition to the existing on-premises gateway options across VMware, Hyper-V, and other platforms.
For organizations already using Sophos solutions, Sophos ZTNA integrates seamlessly with their existing security infrastructure. Managed through the same platform and leveraging the same security intelligence, it extends the benefits of Sophos Synchronized Security without requiring a separate management framework or significant additional training.
Hillstone Networks ZTNA: Built on the Firewall FoundationHillstone takes a different starting point. Rather than building ZTNA around endpoint telemetry, it builds it on top of its existing next-generation firewall (NGFW) line and centralized management platform.
- Hillstone's ZTNA solution combines its Hillstone Security Management (HSM) platform with its NGFW product line, supporting a wide range of authentication schemes along with popular enterprise devices and operating systems. For existing Hillstone customers, this has a practical upside: the ZTNA capability can often be enabled on existing next-gen firewalls with a software upgrade, letting customers adopt a zero-trust strategy with minimal additional cost or effort.
- Hillstone describes its core principle as authenticating the user and checking the endpoint's health status before granting access privileges to specific apps or services on a need-to-know basis. That continuous evaluation is framed almost like an extension of Hillstone's SD-WAN logic: just as SD-WAN continuously monitors links to optimize routing, the ZTNA component continuously monitors the context around an endpoint to decide, moment to moment, whether access should be granted or blocked.
- The client agent evaluates a range of device signals operating system patch levels, MAC address binding, hardware and software certificates, antivirus status, and browser security and patch levels and weighs all of that against policy before granting access rights.
- Policy management is centralized and pushed out to distributed ZTNA gateways, giving administrators global visibility through a single operational view, with zero-touch provisioning to simplify large deployments.
- Hillstone leans into two specific buyer profiles. On one end, it positions ZTNA as an extra layer of protection for government entities and enterprises facing strict compliance requirements, where policies can require multi-factor authentication and trusted devices for remote employees. On the other end, it's also pitched at service providers helping smaller businesses many of which have little in-house IT expertise secure remote and work-from-anywhere access to company resources.
In short, Hillstone's story is "zero trust without ripping out your firewall." If your security architecture already revolves around Hillstone's NGFW and HSM, ZTNA becomes an incremental capability rather than a new platform to deploy and manage.
The TakeawayNeither Sophos nor Hillstone is trying to out-feature the ZTNA market leaders on raw scale both are leaning into what they already do well. Sophos leverages its endpoint telemetry and Synchronized Security story to make ZTNA feel like a natural extension of a product you might already be running. Hillstone leverages its firewall install base and management platform to make ZTNA feel like an upgrade rather than a migration.
When selecting a ZTNA solution, organizations should consider not only the features offered but also how well the solution integrates with their existing security infrastructure. Vendors with an established presence in the environment, such as through firewalls, endpoint protection, or centralized management platforms, can simplify deployment, reduce operational complexity, and accelerate adoption.
Disclosure: this post draws on publicly available vendor documentation and marketing materials from Sophos and Hillstone Networks. As with any vendor comparison, it's worth validating current feature sets and licensing details directly with each vendor, since ZTNA products in this space are evolving quickly.
Keep reading
More articles
Explore other writeups on network security, firewalls, and practical engineering.

Reflecting on My BSc (Hons) in Information Technology Specializing in Computer Systems & Network Engineering at SLIIT (2021–2025)
When I look back at my journey starting from July 2021 all the way to completing my final requirements, enrolling in the BSc (Hons) in Information Technology specializing in Computer Systems and Network Engineering (CSNE) at the Sri Lanka Institute of Information Technology (SLIIT) was one of the most defining choices of my professional life.

The Hidden Vulnerabilities of Public Wi-Fi: Why Open Networks Are a Trap
Ever logged onto a coffee shop's "free" Wi-Fi and did your office work while enjoying a good cup of coffee freely and happily, did you feel completely safe on free Wi-Fi? Think again. Behind that open connection lies a silent playground for hackers where passwords don't even need to be cracked, because your active sessions are stolen in plain sight. Discover why multi-factor authentication isn't enough and what you can do right now to protect your data before your next public login. Read the full post to uncover the hidden traps of unsecured networks!

Urgent Security Alert: Active Exploitation of SonicWall SMA1000 Vulnerabilities Threatens Enterprise Infrastructures
Enterprise environments are facing significant security threats after the confirmation that ransomware operators are actively exploiting two high-severity zero-day vulnerabilities affecting SonicWall Secure Mobile Access (SMA) 1000 appliances.

VLAN Basics: Why We Split One Switch Into Many
Tags, ports, PVIDs, and trunks explained from the ground up, starting with the problem VLANs actually solve