Where Zscaler Zero Trust Gateway fits
Organisations already standardised on Zscaler for user traffic who want the same egress policy and inspection applied to cloud workloads, without running Cloud Connector VMs.
Zero Trust Gateway is Zscaler’s fully hosted inspection service: the Gateway Load Balancer and connector fleet run in Zscaler’s own cloud account, and you attach by placing a Gateway Load Balancer endpoint in your VPC and pointing route tables at it. No appliances, no image lifecycle, no patching — a genuinely good answer to the operational cost of self-hosted inspection. What it is not is a fabric. A Gateway Load Balancer endpoint is a bump in the wire, not a router: traffic returns to the same endpoint, and the next hop is whatever that subnet’s route table says. Reaching another VPC still needs a Transit Gateway you own and operate. Zscaler removed the appliance, not the network engineering. Available on AWS, with Google Cloud in customer preview via Network Security Integration; no Azure equivalent announced.
Organisations already standardised on Zscaler for user traffic who want the same egress policy and inspection applied to cloud workloads, without running Cloud Connector VMs.
Real operational and commercial wins we do not dispute. Because traffic egresses from Zscaler’s account rather than yours, customer Data Transfer Out and NAT Gateway charges disappear entirely — at 10 TB/month and above that is material. Add fifteen years of operating one of the world’s largest security clouds, deep L7 egress inspection through Zscaler Internet Access, and one policy surface shared with the user estate. For internet egress security, this is strong ground.
| capability | Telaron | Zscaler ZTGW |
|---|---|---|
| Encryption & throughput | WireGuard ChaCha20; throughput not yet published | GENEVE, 10 Gbps per gateway |
| Spoke compute | None in workload VPCs; edge tier in customer-owned central VPCs | None — a gateway endpoint per VPC |
| Control plane | SaaS (app.dev.telaron.io) | SaaS (Zscaler); data plane in their account |
| Dynamic routing | iBGP/eBGP via FRR — you own the overlaycoming | None — inspection only, not transit |
| Kubernetes required | No | No |
| Open source | Gateway data plane (Apache 2.0), Terraform provider (MPL 2.0) | No |
| Data sovereignty | Config metadata only | Traffic transits Zscaler’s tenancy |
| Pricing model | Per-gateway tiered; Community free | Per-GB metered, plus per-gateway |
One secure fabric across every cloud — identity-aware policy, encrypted end to end, and no agents in your workloads. Start on the free Community tier; no sales call to get going.