{"id":108973,"date":"2022-12-30T09:23:44","date_gmt":"2022-12-30T08:23:44","guid":{"rendered":"https:\/\/www.avanet.com\/kb\/how-to-set-up-sophos-ztna-zero-trust-network-access\/"},"modified":"2024-02-02T16:24:42","modified_gmt":"2024-02-02T15:24:42","slug":"how-to-set-up-sophos-ztna-zero-trust-network-access","status":"publish","type":"kb","link":"https:\/\/www.avanet.com\/en\/kb\/how-to-set-up-sophos-ztna-zero-trust-network-access\/","title":{"rendered":"How to set up Sophos ZTNA (Zero Trust Network Access)"},"content":{"rendered":"\n<p>This article explains how to set up Sophos Zero Trust Network Access, or ZTNA.\nThis will give you an insight into how the software works. <\/p>\n\n<div class=\"wp-block-yoast-seo-table-of-contents yoast-table-of-contents\"><h2>Table of contents<\/h2><ul><li><a href=\"#h-voraussetzungen-fur-sophos-zero-trust\" data-level=\"2\">Prerequisites for Sophos Zero Trust<\/a><\/li><li><a href=\"#h-sophos-central-ztna-aktivieren\" data-level=\"2\">Activate Sophos Central ZTNA<\/a><\/li><li><a href=\"#h-wildcard-zertifikat\" data-level=\"2\">Wildcard certificate<\/a><\/li><li><a href=\"#h-ztna-einrichten\" data-level=\"2\">Set up ZTNA<\/a><\/li><\/ul><\/div>\n\n<h2 class=\"wp-block-heading\" id=\"h-voraussetzungen-fur-sophos-zero-trust\">Prerequisites for Sophos Zero Trust<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Sophos Central Account<a href=\"https:\/\/www.sophos.com\/de-de\/products\/sophos-central\/free-trial?id=0013000001EjyeY\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sophos Central CreateSophos Central 30 days free trial account<\/a>)<\/li>\n\n\n\n<li>Azure Active Directory with users and groups<\/li>\n\n\n\n<li>VMware ESXi, Microsoft Hyper-V or Amazon Cloud AWS environment for new VM<\/li>\n\n\n\n<li><span style=\"color: var(--ast-global-color-3); font-size: 1rem; background-color: var(--ast-global-color-5);\">Fixed IP address for VM<\/span><\/li>\n\n\n\n<li>Wildcard certificate<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"h-sophos-central-ztna-aktivieren\">Activate Sophos Central ZTNA<\/h2>\n\n<p>If you haven&#8217;t already tested Zero Trust Network Access, feel free to do so with a new or existing Central Account.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1433\" data-id=\"80907\" src=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled.jpg\" alt=\"\" class=\"wp-image-80907\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled-64x36.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-300x168.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-1024x573.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-768x430.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-1536x860.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-2048x1147.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-600x336.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/a><figcaption class=\"wp-element-caption\">Launch Sophos ZTNA Trial<\/figcaption><\/figure>\n<\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"h-wildcard-zertifikat\">Wildcard certificate<\/h2>\n\n<p>For ZTNA you need a wildcard certificate.\nI recommend using a certificate that is valid for longer than 3 months, like the Let&#8217;s Encrypt certificates are.\nBut often you want to test the ZTNA solution during the 30 days trial period and Let&#8217;s Encrypt is a good choice if you don&#8217;t already have a wildcard certificate.  <\/p>\n\n<p>If a certificate already exists, perfect.\nIf not, instructions: <a href=\"\">Create Let&#8217;s Encrypt Wildcard Certificate<\/a> <\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-ztna-einrichten\">Set up ZTNA<\/h2>\n\n<p>Now, in order to use ZTNA, you must first set up the following five things.<\/p>\n\n<ol class=\"wp-block-list\">\n<li>Add directory service: Azure AD Sync with Central to synchronize users and groups.<\/li>\n\n\n\n<li>Add identity providers: Set up the identity providers needed for authentication.<\/li>\n\n\n\n<li>Add gateway: Create a virtual gateway for each network location.<\/li>\n\n\n\n<li>Add policy: Set rules for resource access<\/li>\n\n\n\n<li>Add resource: Specify resources and user groups that are allowed to access the resources.<\/li>\n<\/ol>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1433\" data-id=\"80927\" src=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled.jpg\" alt=\"\" class=\"wp-image-80927\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled-64x36.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-300x168.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-1024x573.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-768x430.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-1536x860.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-2048x1147.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-600x336.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/a><figcaption class=\"wp-element-caption\">Sophos ZTNA Dashboard<\/figcaption><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">1. Synchronize user (set up directory sync)<\/h3>\n\n<p>Not only for ZTNA, but for Central in general, it is helpful to use a directory service that synchronizes the users and groups with Central.\nIn the case of ZTNA, however, you need Azure AD or Okta &#8211; a normal Windows Active Directory Sync is not sufficient here. <\/p>\n\n<p>This guide explains how to fulfill this requirement: <a href=\"https:\/\/www.avanet.com\/en\/kb\/add-sophos-central-azure-ad\/\">AddSophos Central Azure AD<\/a><\/p>\n\n<h3 class=\"wp-block-heading\">2. Add identity provider (Add identitv provider)<\/h3>\n\n<p>After setting up the Azure AD, you can now enter the corresponding data here: <strong>Client ID<\/strong>, <strong>Tenant ID<\/strong>, and <strong>Client secret<\/strong>.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1664\" height=\"1482\" data-id=\"99626\" src=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider.jpg\" alt=\"\" class=\"wp-image-99626\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider.jpg 1664w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-64x57.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-300x267.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-1024x912.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-768x684.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-1536x1368.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-600x534.jpg 600w\" sizes=\"auto, (max-width: 1664px) 100vw, 1664px\" \/><\/a><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">3. Add gateway \/ connector (Set up gateways)<\/h3>\n\n<p>The Sophos Zero Trust Network Access Gateway is a component of the ZTNA architecture.\nWith this gateway, you can provide secure and controlled access to applications and resources for users and devices. <\/p>\n\n<p>The article <a href=\"https:\/\/www.avanet.com\/en\/kb\/how-to-create-a-sophos-ztna-gateway-connector\/\">Create Sophos ZTNA Gateway<\/a> explains how to create the ZTNA On-Premise Gateway or ZTNA Cloud Gateway.<\/p>\n\n<h3 class=\"wp-block-heading\">4. Add policy (Add policy)<\/h3>\n\n<p>Instructions follow.\nWrite us via the <a href=\"\">contact form<\/a> if you want us to prioritize this. <\/p>\n\n<h3 class=\"wp-block-heading\">5. Add resource (Add resources)<\/h3>\n\n<p>Instructions follow.\nWrite us via the <a href=\"\">contact form<\/a> if you want us to prioritize this. <\/p>\n\n<h3 class=\"wp-block-heading\">6. Install ZTNA client on endpoints<\/h3>\n\n<p>Instructions follow.\nWrite us via the <a href=\"\">contact form<\/a> if you want us to prioritize this. <\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"template":"","format":"standard","kb_kategorie":[715],"class_list":["post-108973","kb","type-kb","status-publish","format-standard","hentry","kb_kategorie-zero-trust"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/kb\/108973","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=108973"}],"wp:term":[{"taxonomy":"kb_kategorie","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/kb_kategorie?post=108973"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}