Application-aware access
Publish narrow, named destinations instead of broad networks.
Publish an application boundary#
- Enroll a gateway that can reach the application.
- Add a service with a recognizable name, narrow destination, protocol, and port.
- Assign only gateways that can serve it.
- Optionally assign a private DNS name.
- Grant the service to a group or other deliberate subject scope.
- Simulate and test access.
Prefer a hostname or narrow CIDR over a broad private range. A Gateway Host service publishes a TCP port on the gateway host itself.
Named services make grants, revocation, topology, and investigation easier to understand. Firewall still controls L3/L4 traffic at the gateway, and Secure Web filters internet hosts; neither substitutes for the named access grant.