Skip to main content

Zero Trust Network Access for Air-Gapped Environments

Isolation reduces exposure, but it does not remove the need to control who can reach sensitive systems inside the isolated environment.

ZTXGate can operate inside fully air-gapped networks without depending on a CoreZT-hosted cloud control plane. Identity, device, resource, policy, authentication, and audit controls can remain inside the environment.

What Air-Gapped ZTNA Means

Air-gapped ZTNA is not a way to make an isolated system remotely reachable from the public Internet.

It is a way to apply Zero Trust access controls inside an isolated or disconnected environment.

Users, administrators, and devices that already have an approved path into that environment can still be subject to explicit policy before they reach protected applications and infrastructure.

That matters because network isolation alone does not answer questions such as:

  • Which user should be able to reach this resource?
  • Which enrolled device may be used?
  • Should the permission exist permanently or only for a limited period?
  • Should sensitive access require additional authentication?
  • Can administrators determine who accessed a resource and when?

ZTXGate addresses those access-control questions without requiring its core operation to call out to a CoreZT cloud service.

Keep the Access Platform Inside the Boundary

A standalone ZTXGate deployment can operate entirely within the protected environment.

Air-gapped ZTXGate access flow showing an approved user and device reaching a protected resource through identity, device, policy, authentication, enforcement, and audit controls kept inside the isolated network boundary

The core access path remains within the network boundary.

Standalone Operation

Customers do not need ZTXHub to operate ZTXGate, and core operation does not require a CoreZT-hosted control plane.

In a standalone air-gapped deployment:

  • access policy is managed locally
  • licensing is handled manually
  • software updates are handled manually
  • backups are managed locally
  • audit data remains available within the deployment

This operating model is intentionally suitable for networks where external management connectivity is not allowed.

Optional ZTXHub for Connected Deployments

CoreZT also provides ZTXHub, an optional service owned and operated by CoreZT.

Connected ZTXGate deployments can use ZTXHub for centralized software update management and license management.

It is not required for a fully air-gapped installation. Customers that need strict isolation can omit it and retain the manual operating model.

This keeps centralized management a deployment choice rather than a prerequisite for ZTXGate to function.

Explore the control-plane model

ZTXBAS Works in Air-Gapped Environments

Step-up authentication often becomes difficult in disconnected environments because many MFA products depend on an Internet-hosted service.

When licensed with ZTXGate, ZTXBAS is tightly integrated as a library and works across ZTXGate deployment models, including fully air-gapped networks, without requiring a separate ZTXBAS server deployment.

That keeps phishing-resistant biometric authentication available inside the same isolated environment rather than requiring access to an external push-authentication service.

Connected deployments can still use supported alternatives such as Okta Verify or Duo when those services are reachable.

Explore ZTXBAS

Identity Inside an Isolated Environment

An air-gapped deployment can only use identity systems that are reachable from within that environment.

If an organization operates a compatible internal identity provider or directory integration, ZTXGate can use the services available inside the network boundary.

An Internet-hosted identity provider cannot participate in authentication unless the environment intentionally provides connectivity to it.

The same principle applies to every external integration: ZTXGate does not pretend that a disconnected network can reach a cloud service that is physically unavailable.

Device Identity and Policy

ZTXGate enrolls devices individually and can use device identity as part of access policy.

Policies can combine factors such as:

  • user identity
  • role
  • enrolled device
  • locally available posture information
  • network location
  • time
  • protected resource
  • access duration

Where an MDM or EDR service is hosted outside the isolated environment, its posture data will not be available without connectivity. Policy should therefore be designed around the signals available inside the environment.

Client and Clientless Access

Air-gapped environments may contain both network services and browser-based applications.

Managed endpoints can use WireGuard-based access through ZTXGate for authorized resources.

HTTP and HTTPS applications can also use ZTXGate's clientless proxy where browser-based access is appropriate, allowing access policy and audit controls to be applied without requiring tunnel software on that endpoint.

Explore Clientless ZTNA

Local Audit and Visibility

Disconnected environments still need investigation and accountability.

ZTXGate maintains access, authentication, and policy records locally. Where an internal SIEM or log platform exists inside the isolated network, ZTXGate can forward events using supported formats and transports.

Cloud-hosted SIEM services require connectivity and therefore are not part of a strictly air-gapped architecture.

Software Updates and Licensing

A fully air-gapped standalone deployment uses manual workflows for licensing and software updates.

This is different from a connected deployment using optional ZTXHub, where license and software update management can be centralized.

The manual model allows the customer or MSP operating the deployment to control when software or licensing material enters the isolated environment according to its operational procedures.

Backup and Disaster Recovery

ZTXGate does not use conventional HA clustering.

The administration portal supports periodic backups. If a deployment is lost, a backup can be restored into a fresh ZTXGate installation to recover the configured environment.

For an air-gapped deployment, the customer or MSP should store protected backup copies and maintain a documented process for provisioning replacement infrastructure inside the isolated environment.

This is a disaster recovery model based on backup and restore, not continuous failover.

Connected vs Air-Gapped Capabilities

CapabilityConnected deploymentFully air-gapped standalone deployment
ZTXGate core accessYesYes
CoreZT-hosted cloud control plane requiredNoNo
ZTXBASYesYes
Okta Verify / DuoWhen service is reachableNo, unless connectivity is intentionally provided
Cloud identity providerWhen service is reachableNo, unless connectivity is intentionally provided
Cloud MDM / EDR postureWhen service is reachableNo, unless connectivity is intentionally provided
Cloud SIEMWhen service is reachableNo, unless connectivity is intentionally provided
License managementManual or optional CoreZT-operated ZTXHubManual
Software updatesManual or optional CoreZT-operated ZTXHubManual
Backup / restore DRYesYes

Where Air-Gapped ZTNA Fits

This model can be relevant to environments such as:

  • isolated research and development networks
  • restricted operational environments
  • sensitive internal infrastructure
  • networks with intentionally limited Internet connectivity
  • organizations whose architecture requires local security services

The suitability of a particular deployment still depends on the organization's security requirements and surrounding controls.

Frequently Asked Questions

Does air-gapped ZTNA provide remote Internet access to an isolated network?

No. The purpose is to enforce Zero Trust access within the isolated environment, not bypass the air gap.

Does ZTXGate need ZTXHub in an air-gapped deployment?

No. ZTXHub is optional and is owned and operated by CoreZT. A fully air-gapped ZTXGate deployment does not use ZTXHub and can use manual licensing and software update workflows.

Can biometric MFA still work without Internet access?

Yes. When licensed with ZTXGate, integrated ZTXBAS provides phishing-resistant biometric authentication in fully air-gapped deployments without a separate ZTXBAS server deployment.

What happens to cloud integrations?

They are available only if the corresponding services are reachable. A strictly air-gapped environment should use the identity, authentication, posture, logging, and management services available inside its boundary.

Does ZTXGate provide HA for isolated environments?

Not in the conventional clustering sense. The supported resilience model is periodic backup and restoration into a fresh deployment after a disaster.

Apply Zero Trust Without Breaking the Air Gap

Keep the access platform, authentication option, policy, and audit path inside the isolated environment operated by the customer or MSP.

Compare Air-Gapped Operating Models

For current architecture comparisons, see ZTXGate vs Cloudflare Access, ZTXGate vs Zscaler Private Access, and ZTXGate vs Tailscale.