Zscaler Branch Connector: Replace MPLS and use micro-segmentation
SD-WAN and Zscaler Branch Connector solve different tasks. If you plan transport, zero trust security and East-West micro-segmentation together, you can replace MPLS in a controlled manner and at the same time protect locations at a more granular level.
Anyone who modernizes site connectivity today quickly comes across two terms that are often lumped together: SD-WAN and the Zscaler Branch Connector. Both are advertised as a way to Replace expensive MPLS cables. This leads to the false assumption that these are competing products for which you have to choose one. In fact, they start at different points. The difference determines what makes sense in your environment.
SD-WAN: Intelligent control of transport
SD-WAN thinks from the grid. The core is to bundle several lines, such as broadband, LTE or remaining MPLS routes, and to direct traffic over the best route in each case in an application-conscious manner. If one line fails, another takes over. For the company, this means more reliability and lower transport costs than with pure MPLS, because low-cost broadband connections bear part of the load. SD-WAN is strong when it comes to line diversity, prioritization, and availability.
What SD-WAN does not have at its core is the security layer. The protection functions must be supplemented, classically via local firewalls per location or via an additional security platform. This is exactly where the second approach comes in.
Zscaler Branch Connector: Access and Security from the Cloud
The Zscaler way thinks from the point of view of access and security. The location is directly connected to the cloud-based Zero Trust Exchange that sits inline in the data stream. Protection features such as cloud firewall, IPS, sandboxing, DLP and SSL inspection are already included, instead of being operated as a separate appliance at each location. New locations can be connected via plug-and-play without having to set up a complex security infrastructure on site. About ZIA for Internet access, and ZPA end-to-end Zero Trust security including micro-segmentation is created for access to internal applications.
Zscaler Branch and Micro-Segmentation: The /32 Advantage
In classic site architectures, micro-segmentation is often planned via additional VLANs, firewall zones, access lists or separate overlay technology. The claim makes sense: A compromised device should not automatically reach other systems at the site or in other networks. In practice, however, segmentation often remains crude, because each additional network and each new rule increases operational overhead.
Zscaler explicitly describes a basis for Branch Connector for East-West segmentation, which can limit lateral movement. The decisive architectural change is that a device or location does not receive blanket access to a network, but only to the required applications and destinations. ZPA hides private applications behind application-related access paths; ZIA and the branch policies control Internet, SaaS and other defined connections.
An additional advantage arises when devices or sources are deliberately modeled as individual host addresses in the site design. A single IPv4 address is technically equivalent to a /32 Prefix. Instead of treating an entire /24 or VLAN segment as a common policy unit, each source can be assigned to its own, narrowly defined communication relationship. The desired micro-segmentation is thus not set up as a separate network project, but can be created as part of the branch transformation.
Comparison at a glance
| Criterion | SD-WAN | Zscaler Branch Connector |
|---|---|---|
| Primary Focus | Transport, line control, availability | Access and security from the cloud |
| Security features | To be added separately (on-premises or cloud) | included inline (firewall, IPS, SSL inspection, DLP, sandbox) |
| On-site firewall | usually still necessary | often dispensable because it is centrally located in the cloud |
| Rollout of new locations | Configuration per location | Plug-and-play connection to the cloud |
| Micro-segmentation | additional segmentation and policy layer required | East-West segmentation and application-based policies; can be implemented with clean /32 modeling in a host-specific manner |
When which approach fits
The honest answer is: it depends on the primary goal.
- Is transport in the foreground, such as multiple lines per site, high availability requirements or time-consuming prioritization of real-time applications, SD-WAN shows its strengths.
- Focus on security and access, such as end-to-end Zero Trust protection, fewer on-premises appliances and an easy rollout of many locations, the Zscaler path leads faster to the goal.
- In many real-world projects It's a coordinated combination: SD-WAN provides robust, low-cost transport, while the Zscaler Branch Connector delivers security and access from the cloud and reduces on-premises firewalls.
The path of MPLS to the right combination
- Location inventory: How many locations, which lines, what local security infrastructure is in use?
- Clarify goals: Is transportation costs and availability the most important, or Zero Trust security and rollout speed?
- Calculate total costs: Compare lines, appliances, maintenance and operation per location, not just the line price.
- Define the target image: SD-WAN, Zscaler branch, or a combination tailored to the site profiles.
- Migrate gradually: start with non-critical locations, gain experience, then scale.
You can find out how the switch pays off in concrete terms with our MPLS to Zero Trust Cost Calculator play through it yourself. It works with your own, editable assumptions and deliberately does not require invented vendor prices.
Find the right path for your locations
We analyze your site landscape and show where SD-WAN, where the Zscaler Branch Connector and where a combination works the most. Neutral, oriented towards your goals and your cost structure.
Make an appointment for a consultationFrequently Asked Questions
SD-WAN primarily optimizes transport: It bundles and controls cables in order to connect sites flexibly and more cost-effectively than with pure MPLS. The Zscaler Branch Connector brings the site directly and securely to the cloud-based Zero Trust Exchange, which already includes protection.
In many cases, yes. Because traffic goes through the Zero Trust Exchange, firewall, IPS, sandbox, and DLP capabilities are centrally available. For smaller and medium-sized locations, this can make the local appliance superfluous. For special local requirements, a residual function can remain useful.
Not necessarily. Both approaches can be combined: SD-WAN optimizes transport, the Zscaler path provides security and access from the cloud. The primary goal is decisive, often a coordinated combination is the best answer.
It creates a strong foundation with application-oriented policies and East-West segmentation. If devices or sources are deliberately modeled as individual /32 host addresses, relationships can be limited very granularly. However, IP assignment, policies, exceptions and negative test cases must be checked in the concrete design.
- Zscaler: What Is Zscaler Branch Connector? – Application-based access, east-west segmentation, and lateral movement limitation.
- Zscaler: Configuring Traffic Forwarding Rules – Individual source IP addresses, subnets and IP ranges as control criteria.
- SourcingBlox, cost calculator MPLS to Zero Trust (editable assumptions, without invented vendor prices).
- SourcingBlox, article "Replacing MPLS with Zero Trust: Costs, Procedures, Pitfalls".
