Hello! Very interested in OpenZiti and moving towards implementation. I do have several questions that I couldn’t get a strong handle on from the documentation and will provide our office setup for a description.
We are a small mac shop doing paperwork services for clients and government entities. We have 20 laptops, 20 apple phones given to each employee. Our west coast office is 5 laptops and 5 apple phones. We have a few employees who work from home, we also have 1 network attached printer in the main office. Our office setup is fairly standard of a small business, all our endpoints connect to a switch, which connects to a router, which connects to the modem protected by a firewall. We do not have or use a VPN. We have webhosting we pay for and do not manage, we occasionally give access to our webhosted sites to freelancers for their services (webdev, content, etc).
I’m interested in using OpenZiti for ZTN implementation but what I am having a hard time wrapping my head around is what type of hardware I will need or what steps I need to take to keep our remote employees communicating without issues. My understanding is that I will need to install tunneler apps on the macs and the phones obviously, and setup a controller opening one port for a rest api and another for management. Any Edge routers will have two inbound ports open one for fabric link and another for edge connections. Fabric routers will have a single inbound port open for fabric link.
But what type of hardware is needed for the controller, and edge & fabric routers? What about the west coast office & the work from home employees? I mean I guess they have no reason to get on our local network because we just communicate through email and apps like asana / photo-shelter but yeah, it still feels strange for them to just be left out there relying on their home setup. I surmise I would need to also stand up a controller and edge router at the west coast office at a minimum.
Essentially though what would our small network setup look like? Macs and phones equipped with tunneler apps connecting to a controller and an edge router w/ the edge router connecting to a modem connecting to the internet and from there accessing our non-zitified webservers as normal? Employees working from home or travelling still need to have their openziti app configured to dial in to our open-ziti controller first? If that was the case then I would need a server or host for the controller in the cloud correct?
Final questions, Is there a list of apps which have implemented OpenZiti? I think I saw something about OpenZiti undergoing a security audit, is that available if so?
I know you’re probably asking why I would consider this for a business of our size because a ZTN may seem like overkill but it comes down to government regulation and that I have the opportunity to do this while I believe in the principles behind ZTN. My questions may seem dunce-level but I have read quite a bit, and am just starting to put together something to package up to the executive team who will have similar questions and then also need convincing as to whether we should self-host or use NetFoundry’s cloudziti.