Skip to content →
Log in

Application-aware access

Publish narrow, named destinations instead of broad networks.

Publish an application boundary#

  1. Enroll a gateway that can reach the application.
  2. Add a service with a recognizable name, narrow destination, protocol, and port.
  3. Assign only gateways that can serve it.
  4. Optionally assign a private DNS name.
  5. Grant the service to a group or other deliberate subject scope.
  6. Simulate and test access.

Prefer a hostname or narrow CIDR over a broad private range. A Gateway Host service publishes a TCP port on the gateway host itself.

Named services make grants, revocation, topology, and investigation easier to understand. Firewall still controls L3/L4 traffic at the gateway, and Secure Web filters internet hosts; neither substitutes for the named access grant.