Zero Trust Network Access for Air-Gapped Environments
Isolation reduces exposure, but it does not remove the need to control who can reach sensitive systems inside the isolated environment.
ZTXGate can operate inside fully air-gapped networks without depending on a CoreZT-hosted cloud control plane. Identity, device, resource, policy, authentication, and audit controls can remain inside the environment.
What Air-Gapped ZTNA Means
Air-gapped ZTNA is not a way to make an isolated system remotely reachable from the public Internet.
It is a way to apply Zero Trust access controls inside an isolated or disconnected environment.
Users, administrators, and devices that already have an approved path into that environment can still be subject to explicit policy before they reach protected applications and infrastructure.
That matters because network isolation alone does not answer questions such as:
- Which user should be able to reach this resource?
- Which enrolled device may be used?
- Should the permission exist permanently or only for a limited period?
- Should sensitive access require additional authentication?
- Can administrators determine who accessed a resource and when?
ZTXGate addresses those access-control questions without requiring its core operation to call out to a CoreZT cloud service.
Keep the Access Platform Inside the Boundary
A standalone ZTXGate deployment can operate entirely within the protected environment.
The core access path remains within the network boundary.
Standalone Operation
Customers do not need ZTXHub to operate ZTXGate, and core operation does not require a CoreZT-hosted control plane.
In a standalone air-gapped deployment:
- access policy is managed locally
- licensing is handled manually
- software updates are handled manually
- backups are managed locally
- audit data remains available within the deployment
This operating model is intentionally suitable for networks where external management connectivity is not allowed.
Optional ZTXHub for Connected Deployments
CoreZT also provides ZTXHub, an optional service owned and operated by CoreZT.
Connected ZTXGate deployments can use ZTXHub for centralized software update management and license management.
It is not required for a fully air-gapped installation. Customers that need strict isolation can omit it and retain the manual operating model.
This keeps centralized management a deployment choice rather than a prerequisite for ZTXGate to function.
Explore the control-plane model
ZTXBAS Works in Air-Gapped Environments
Step-up authentication often becomes difficult in disconnected environments because many MFA products depend on an Internet-hosted service.
When licensed with ZTXGate, ZTXBAS is tightly integrated as a library and works across ZTXGate deployment models, including fully air-gapped networks, without requiring a separate ZTXBAS server deployment.
That keeps phishing-resistant biometric authentication available inside the same isolated environment rather than requiring access to an external push-authentication service.
Connected deployments can still use supported alternatives such as Okta Verify or Duo when those services are reachable.
Identity Inside an Isolated Environment
An air-gapped deployment can only use identity systems that are reachable from within that environment.
If an organization operates a compatible internal identity provider or directory integration, ZTXGate can use the services available inside the network boundary.
An Internet-hosted identity provider cannot participate in authentication unless the environment intentionally provides connectivity to it.
The same principle applies to every external integration: ZTXGate does not pretend that a disconnected network can reach a cloud service that is physically unavailable.
Device Identity and Policy
ZTXGate enrolls devices individually and can use device identity as part of access policy.
Policies can combine factors such as:
- user identity
- role
- enrolled device
- locally available posture information
- network location
- time
- protected resource
- access duration
Where an MDM or EDR service is hosted outside the isolated environment, its posture data will not be available without connectivity. Policy should therefore be designed around the signals available inside the environment.
Client and Clientless Access
Air-gapped environments may contain both network services and browser-based applications.
Managed endpoints can use WireGuard-based access through ZTXGate for authorized resources.
HTTP and HTTPS applications can also use ZTXGate's clientless proxy where browser-based access is appropriate, allowing access policy and audit controls to be applied without requiring tunnel software on that endpoint.
Local Audit and Visibility
Disconnected environments still need investigation and accountability.
ZTXGate maintains access, authentication, and policy records locally. Where an internal SIEM or log platform exists inside the isolated network, ZTXGate can forward events using supported formats and transports.
Cloud-hosted SIEM services require connectivity and therefore are not part of a strictly air-gapped architecture.
Software Updates and Licensing
A fully air-gapped standalone deployment uses manual workflows for licensing and software updates.
This is different from a connected deployment using optional ZTXHub, where license and software update management can be centralized.
The manual model allows the customer or MSP operating the deployment to control when software or licensing material enters the isolated environment according to its operational procedures.
Backup and Disaster Recovery
ZTXGate does not use conventional HA clustering.
The administration portal supports periodic backups. If a deployment is lost, a backup can be restored into a fresh ZTXGate installation to recover the configured environment.
For an air-gapped deployment, the customer or MSP should store protected backup copies and maintain a documented process for provisioning replacement infrastructure inside the isolated environment.
This is a disaster recovery model based on backup and restore, not continuous failover.
Connected vs Air-Gapped Capabilities
| Capability | Connected deployment | Fully air-gapped standalone deployment |
|---|---|---|
| ZTXGate core access | Yes | Yes |
| CoreZT-hosted cloud control plane required | No | No |
| ZTXBAS | Yes | Yes |
| Okta Verify / Duo | When service is reachable | No, unless connectivity is intentionally provided |
| Cloud identity provider | When service is reachable | No, unless connectivity is intentionally provided |
| Cloud MDM / EDR posture | When service is reachable | No, unless connectivity is intentionally provided |
| Cloud SIEM | When service is reachable | No, unless connectivity is intentionally provided |
| License management | Manual or optional CoreZT-operated ZTXHub | Manual |
| Software updates | Manual or optional CoreZT-operated ZTXHub | Manual |
| Backup / restore DR | Yes | Yes |
Where Air-Gapped ZTNA Fits
This model can be relevant to environments such as:
- isolated research and development networks
- restricted operational environments
- sensitive internal infrastructure
- networks with intentionally limited Internet connectivity
- organizations whose architecture requires local security services
The suitability of a particular deployment still depends on the organization's security requirements and surrounding controls.
Frequently Asked Questions
Does air-gapped ZTNA provide remote Internet access to an isolated network?
No. The purpose is to enforce Zero Trust access within the isolated environment, not bypass the air gap.
Does ZTXGate need ZTXHub in an air-gapped deployment?
No. ZTXHub is optional and is owned and operated by CoreZT. A fully air-gapped ZTXGate deployment does not use ZTXHub and can use manual licensing and software update workflows.
Can biometric MFA still work without Internet access?
Yes. When licensed with ZTXGate, integrated ZTXBAS provides phishing-resistant biometric authentication in fully air-gapped deployments without a separate ZTXBAS server deployment.
What happens to cloud integrations?
They are available only if the corresponding services are reachable. A strictly air-gapped environment should use the identity, authentication, posture, logging, and management services available inside its boundary.
Does ZTXGate provide HA for isolated environments?
Not in the conventional clustering sense. The supported resilience model is periodic backup and restoration into a fresh deployment after a disaster.
Apply Zero Trust Without Breaking the Air Gap
Keep the access platform, authentication option, policy, and audit path inside the isolated environment operated by the customer or MSP.
Compare Air-Gapped Operating Models
For current architecture comparisons, see ZTXGate vs Cloudflare Access, ZTXGate vs Zscaler Private Access, and ZTXGate vs Tailscale.