{"id":9322,"date":"2025-06-11T17:04:13","date_gmt":"2025-06-11T15:04:13","guid":{"rendered":"https:\/\/testing.eight25sites.com\/en-us\/?p=9322"},"modified":"2025-06-11T17:04:13","modified_gmt":"2025-06-11T15:04:13","slug":"whats-new-in-sophos-ztna-new-features-and-insights-for-june-2025","status":"publish","type":"post","link":"https:\/\/testing.eight25sites.com\/en-us\/2025\/06\/products\/whats-new-in-sophos-ztna-new-features-and-insights-for-june-2025\/","title":{"rendered":"What\u2019s New in Sophos ZTNA: New Features and Insights for June 2025"},"content":{"rendered":"<p>Sophos ZTNA has received a couple of important updates to ease deployment and enhance performance.\u00a0 There is also an important End-of-Life announcement for earlier versions of the Sophos ZTNA gateway that may require some of you to plan an upgrade soon.<\/p>\n<p>&nbsp;<\/p>\n<h2>Important: End-of-Life for all ZTNA Gateways prior to v2.1<\/h2>\n<p>ZTNA gateways on VMware ESXi and Hyper-V versions earlier than 2.1 will no longer be supported starting October 1, 2025. ZTNA gateways running on firewalls with SFOS versions older than 20.0 MR2 are also not supported, as these <a href=\"https:\/\/support.sophos.com\/support\/s\/article\/KBA-000003353?language=en_US#xgfirewallsoftware\" target=\"_blank\" rel=\"noopener\">SFOS versions<\/a> are already end of life.<\/p>\n<p>Customers who have gateway deployments on the versions mentioned above are required to upgrade to the latest versions via Sophos Central. Customers with firewalls functioning as ZTNA gateways should always upgrade their firewalls to the <a href=\"https:\/\/community.sophos.com\/sophos-xg-firewall\" target=\"_blank\" rel=\"noopener\">latest version of SFOS<\/a>.<\/p>\n<p>As a reminder, Sophos maintains a <a href=\"https:\/\/support.sophos.com\/support\/s\/article\/KBA-000003353?language=en_US#xgfirewallsoftware\" target=\"_blank\" rel=\"noopener\">retirement calendar<\/a> for all network security products outlining the latest supported versions.\u00a0 Sophos ZTNA is near the bottom of this page.<\/p>\n<p>&nbsp;<\/p>\n<h2>New On-Premise Network Detection<\/h2>\n<p>This highly requested new feature addresses a key challenge with the ZTNA-as-a-service deployment mode, where a ZTNA device in an office on the same trusted network as the ZTNA application will route access via the Sophos Cloud or through the WAN interface of the gateway. While this maintains a uniform user experience and security posture, hairpinning has also introduced significant latency, especially for applications such as CIFS file shares and RDP.<\/p>\n<p>The ZTNA agent will now assess whether it is on a trusted network based on the DNS configuration and decide whether to intercept the traffic.\u00a0 This is an optional configuration that customers can enable according to their specific use cases.<\/p>\n<p>Note: To make use of this new feature, the ZTNA agent needs to be upgraded to a new build:\u00a0 <a href=\"https:\/\/docs.sophos.com\/central\/Customer\/help\/en-us\/ManageYourProducts\/ZeroTrustNetworkAccess\/ZTNASettings\/index.html\" target=\"_blank\" rel=\"noopener\">Documentation<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9323 size-full\" src=\"https:\/\/testing.eight25sites.com\/en-us\/wp-content\/uploads\/sites\/3\/2025\/06\/sophos-ztna-on-premise-traffic.png\" alt=\"\" width=\"1637\" height=\"288\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Domain Controller as a ZTNA Resource<\/h2>\n<p>This enhancement facilitates seamless user access to resources behind a domain controller.<\/p>\n<p>This addresses a limitation where ZTNA agents could not intercept these\u00a0DNS-SRV\u00a0records, leading to connectivity issues, particularly when users accessed resources like file shares remotely. We developed a temporary workaround for this issue, and a\u00a0corresponding\u00a0<a href=\"https:\/\/support.sophos.com\/support\/s\/article\/KBA-000008481?language=en_US\" target=\"_blank\" rel=\"noopener\">Knowledge Base Article\u00a0<\/a>was published.<\/p>\n<p>To better address this issue, we are now rolling out the first phase of updates, which makes it easier to add a domain controller (DC) as a ZTNA resource on Sophos Central. Along with the addition of the DC, we automatically add commonly used\u00a0DNS-SRV\u00a0records under the \u201cAdvanced Settings\u201d section and provide an option for administrators to add or modify these records. This prevents administrators from having to create multiple\u00a0DNS-SRV\u00a0records for individual ZTNA resources, as was the case with the previous workaround.<\/p>\n<p>Accounts that have already deployed the workaround can also migrate to the new approach by simply adding a new resource of type DC. Both these approaches can co-exist until we phase out the workaround.<\/p>\n<p>While this new implementation addresses the majority of customer use cases, there are additional specific instances, such as support for multiple domain controllers, that we want to address via a ZTNA agent update in the next phase.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9324 size-full\" src=\"https:\/\/testing.eight25sites.com\/en-us\/wp-content\/uploads\/sites\/3\/2025\/06\/sophos-ztna-domain-controller.png\" alt=\"\" width=\"2042\" height=\"1596\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9325 size-full\" src=\"https:\/\/testing.eight25sites.com\/en-us\/wp-content\/uploads\/sites\/3\/2025\/06\/sophos-ztna-advanced-domain-controller.png\" alt=\"\" width=\"1984\" height=\"920\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Documentation<\/h2>\n<p>The latest online documentation is\u00a0<a href=\"https:\/\/docs.sophos.com\/central\/ZTNA\/startup\/en-us\/index.html\" target=\"_blank\" rel=\"noopener\">here<\/a>, and the updated known issues list can be found\u00a0<a href=\"https:\/\/docs.sophos.com\/support\/kil\/index.html?product=ztna\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Get Started with ZTNA for Free<\/h2>\n<p>If your customers are not already using <a href=\"https:\/\/sophos.com\/ztna\" target=\"_blank\" rel=\"noopener\">Sophos ZTNA<\/a>, they can get started for free. There\u2019s a <a href=\"https:\/\/www.sophos.com\/en-us\/products\/zero-trust-network-access\/free-trial\" target=\"_blank\" rel=\"noopener\">free trial<\/a> available via Sophos Central. Sophos Firewall customers can get <a href=\"https:\/\/testing.eight25sites.com\/en-us\/2024\/08\/products\/free-sophos-ztna-licenses-for-sophos-firewall-customers\/\" target=\"_blank\" rel=\"noopener\">three free one-year licenses<\/a>\u00a0and take advantage of the\u00a0<a href=\"https:\/\/testing.eight25sites.com\/en-us\/2023\/10\/products\/sophos-ztna-on-sophos-firewall-now-available\/\" target=\"_blank\" rel=\"noopener\">ZTNA gateway integrated into your firewall<\/a>.<\/p>\n<p>Check out the\u00a0<a href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/b4rqjhc6cmhrff56ss45cqw\/sophos-ztna-deployment-checklist.pdf\" target=\"_blank\" rel=\"noopener\">Deployment Checklist<\/a>\u00a0for other considerations when deploying ZTNA and the latest\u00a0<a href=\"https:\/\/docs.sophos.com\/central\/ZTNA\/startup\/en-us\/setup\/IdentityProvider\/index.html#__tabbed_1_1\" target=\"_blank\" rel=\"noopener\">online documentation<\/a>.<\/p>\n<p>If you are starting your ZTNA journey, view our updated initial setup video here:<\/p>\n<p><iframe loading=\"lazy\" class=\"vidyard_iframe\" title=\"Sophos ZTNA: Initial Setup\" src=\"\/\/play.vidyard.com\/GmXGBALTAcTrdeVQsRp9hq.html?\" width=\"640\" height=\"360\" frameborder=\"0\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophos ZTNA has received a couple of important updates to ease deployment and enhance performance.\u00a0 There is also an important End-of-Life announcement for earlier versions of the Sophos ZTNA gateway that may require some of you to plan an upgrade [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":3000004271,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[135],"coauthors":[58],"class_list":["post-9322","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-sophos-ztna"],"_links":{"self":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts\/9322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/comments?post=9322"}],"version-history":[{"count":3,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts\/9322\/revisions"}],"predecessor-version":[{"id":9329,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts\/9322\/revisions\/9329"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/media?parent=9322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/categories?post=9322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/tags?post=9322"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=9322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}