SOURCINGBLOX DEMake an appointment
Menu
← Back to Blog Network Transformation · Site connection

Zscaler Branch Connector: Replace MPLS and use micro-segmentation

SD-WAN and Zscaler Branch Connector solve different tasks. If you plan transport, zero trust security and East-West micro-segmentation together, you can replace MPLS in a controlled manner and at the same time protect locations at a more granular level.

SourcingBlox GmbH · Reading time approx. 8 minutes
Site connection via SD-WAN and Zero Trust, symbolic

Anyone who modernizes site connectivity today quickly comes across two terms that are often lumped together: SD-WAN and the Zscaler Branch Connector. Both are advertised as a way to Replace expensive MPLS cables. This leads to the false assumption that these are competing products for which you have to choose one. In fact, they start at different points. The difference determines what makes sense in your environment.

SD-WAN: Intelligent control of transport

SD-WAN thinks from the grid. The core is to bundle several lines, such as broadband, LTE or remaining MPLS routes, and to direct traffic over the best route in each case in an application-conscious manner. If one line fails, another takes over. For the company, this means more reliability and lower transport costs than with pure MPLS, because low-cost broadband connections bear part of the load. SD-WAN is strong when it comes to line diversity, prioritization, and availability.

What SD-WAN does not have at its core is the security layer. The protection functions must be supplemented, classically via local firewalls per location or via an additional security platform. This is exactly where the second approach comes in.

Zscaler Branch Connector: Access and Security from the Cloud

The Zscaler way thinks from the point of view of access and security. The location is directly connected to the cloud-based Zero Trust Exchange that sits inline in the data stream. Protection features such as cloud firewall, IPS, sandboxing, DLP and SSL inspection are already included, instead of being operated as a separate appliance at each location. New locations can be connected via plug-and-play without having to set up a complex security infrastructure on site. About ZIA for Internet access, and ZPA end-to-end Zero Trust security including micro-segmentation is created for access to internal applications.

The core difference in one sentence: SD-WAN optimizes how traffic is transported. The Zscaler Branch Connector determines how securely and rule-based targets are accessed. One does not automatically replace the other.

Zscaler Branch and Micro-Segmentation: The /32 Advantage

In classic site architectures, micro-segmentation is often planned via additional VLANs, firewall zones, access lists or separate overlay technology. The claim makes sense: A compromised device should not automatically reach other systems at the site or in other networks. In practice, however, segmentation often remains crude, because each additional network and each new rule increases operational overhead.

Zscaler explicitly describes a basis for Branch Connector for East-West segmentation, which can limit lateral movement. The decisive architectural change is that a device or location does not receive blanket access to a network, but only to the required applications and destinations. ZPA hides private applications behind application-related access paths; ZIA and the branch policies control Internet, SaaS and other defined connections.

An additional advantage arises when devices or sources are deliberately modeled as individual host addresses in the site design. A single IPv4 address is technically equivalent to a /32 Prefix. Instead of treating an entire /24 or VLAN segment as a common policy unit, each source can be assigned to its own, narrowly defined communication relationship. The desired micro-segmentation is thus not set up as a separate network project, but can be created as part of the branch transformation.

Important demarcation: The Branch Connector doesn't automatically create full micro-segmentation just by installing it. The /32 approach requires a resilient device-to-IP mapping, defined target relationships, appropriate ZIA/ZPA policies, common infrastructure treatment, and a pilot with negative test cases. Whether and how host addresses are provided must be verified in the specific DHCP, routing and branch design.

Comparison at a glance

CriterionSD-WANZscaler Branch Connector
Primary FocusTransport, line control, availabilityAccess and security from the cloud
Security featuresTo be added separately (on-premises or cloud)included inline (firewall, IPS, SSL inspection, DLP, sandbox)
On-site firewallusually still necessaryoften dispensable because it is centrally located in the cloud
Rollout of new locationsConfiguration per locationPlug-and-play connection to the cloud
Micro-segmentationadditional segmentation and policy layer requiredEast-West segmentation and application-based policies; can be implemented with clean /32 modeling in a host-specific manner

When which approach fits

The honest answer is: it depends on the primary goal.

Important when deciding: Calculate not only the line, but the total costs including local firewalls, their maintenance, patch cycles and the personnel costs per location. This is exactly where the hidden costs arise, which pure line comparisons overlook.

The path of MPLS to the right combination

  1. Location inventory: How many locations, which lines, what local security infrastructure is in use?
  2. Clarify goals: Is transportation costs and availability the most important, or Zero Trust security and rollout speed?
  3. Calculate total costs: Compare lines, appliances, maintenance and operation per location, not just the line price.
  4. Define the target image: SD-WAN, Zscaler branch, or a combination tailored to the site profiles.
  5. Migrate gradually: start with non-critical locations, gain experience, then scale.

You can find out how the switch pays off in concrete terms with our MPLS to Zero Trust Cost Calculator play through it yourself. It works with your own, editable assumptions and deliberately does not require invented vendor prices.

Find the right path for your locations

We analyze your site landscape and show where SD-WAN, where the Zscaler Branch Connector and where a combination works the most. Neutral, oriented towards your goals and your cost structure.

Make an appointment for a consultation

Frequently Asked Questions

What is the difference between SD-WAN and the Zscaler Branch Connector?

SD-WAN primarily optimizes transport: It bundles and controls cables in order to connect sites flexibly and more cost-effectively than with pure MPLS. The Zscaler Branch Connector brings the site directly and securely to the cloud-based Zero Trust Exchange, which already includes protection.

Does Zero Trust replace the on-premises firewall?

In many cases, yes. Because traffic goes through the Zero Trust Exchange, firewall, IPS, sandbox, and DLP capabilities are centrally available. For smaller and medium-sized locations, this can make the local appliance superfluous. For special local requirements, a residual function can remain useful.

Do I have to choose between SD-WAN and Zscaler?

Not necessarily. Both approaches can be combined: SD-WAN optimizes transport, the Zscaler path provides security and access from the cloud. The primary goal is decisive, often a coordinated combination is the best answer.

Does Zscaler Branch Connector automatically generate micro-segmentation?

It creates a strong foundation with application-oriented policies and East-West segmentation. If devices or sources are deliberately modeled as individual /32 host addresses, relationships can be limited very granularly. However, IP assignment, policies, exceptions and negative test cases must be checked in the concrete design.

Sources & Further Reading: