This page describes the Zero-Trust deployment options Access Gate supports, full or partial coverage and three placements (inline peer of your router, in place of your router, or an aggregation switch), and how your network's routing, on-network devices, and switch type determine which one applies.
Access Gate does not require you to redesign your network. It adapts to what is already there, DNS, routers, managed or unmanaged switches, even non-routed and exotic setups, and deploys the strongest Zero-Trust posture your topology allows.
Use the explorer below to see the recommended deployment for your environment: where the Access Gate sits, how much Zero-Trust coverage you get, and the migration path to get there.
Full vs partial Zero-Trust
| Coverage | When it applies | Scope |
|---|---|---|
| Full Zero-Trust | The Access Gate can see and broker every relevant flow, typically a routed network with DNS or a managed switch to steer traffic through the overlay | Every relevant flow |
| Partial Zero-Trust | Some traffic stays purely at layer 2 and never reaches the Access Gate, for example unmanaged switches or non-routed, exotic protocols | Everything the Access Gate sees, with L2 filtering by EtherType or MAC; flows it never observes are out of scope |
What drives the decision
Three properties of your existing network determine the deployment:
- Routing: whether communications are routed and routable, or non-routed (exotic and custom).
- What is on the network: DNS, a router (no DNS), or a switch only (no DNS or router).
- Switch type: managed (supports PVLAN and VLAN steering) or unmanaged.
From these, the Access Gate is positioned as an inline peer of your router, in place of your router, or as an aggregation switch, and the Secure Twin overlay carries the migrated assets without touching production.
Next steps
- Quick start: stand up an Access Gate and one protected enclave in about 15 minutes.
- Architecture overview: the deployment modes in depth.