Zero Trust Strategy: A Network Security Model Built on Verification
As enterprise environments grow more complex, organizations must adopt a more precise and flexible approach to network security. Traditional perimeter-based security no longer provides sufficient protection. This shift is driving organizations toward zero trust, increasing the need for practical ways to verify and control users, devices, access conditions, and privileges. In this article, we explore how organizations can build a zero trust architecture on existing network security infrastructure using our next-generation firewall, AhnLab XTG.

Cybersecurity Trends
Cyber incidents are increasing in both frequency and impact, affecting organizations of every size across industries worldwide. Adversaries are also using a wider range of techniques. Social engineering attacks remain persistent and continue to evolve, taking new forms, from malware delivered through emails and attachments that impersonate legitimate organizations to phishing campaigns and fake websites designed to steal personal information.
AI is adding further complexity to this landscape. Adversaries now use deepfakes and AI-generated voices to enhance fraud and impersonation attacks. As techniques continue to evolve, traditional security approaches are proving less effective and exposing the limits of perimeter-based protection.
Limitations of Traditional Security Models
Traditional security models are built around the perimeter. Many organizations still treat the internal network as trusted and focus their security controls on blocking external threats. However, once an adversary gains access, lateral movement inside the network is difficult to detect or control.
Enterprise environments have also changed drastically. Cloud services, mobile access, and remote work have made the perimeter-based model unreliable. Remote access makes these limitations even more apparent. Many organizations still rely on SSL VPNs to open internal systems to external users, yet VPNs continue to face critical vulnerabilities that are actively exploited. Consequently, organizations are moving away from implicit trust and toward a zero trust framework.
Understanding Zero Trust
Unlike traditional security models, zero trust never grants trust by default. It requires organizations to verify every user, device, and access request before allowing access.
Zero Trust is built on three core principles.
- Explicit verification: Every access request is verified based on user identity, device security posture, location, and application context.
- Least privilege access: Access is limited to the systems and services each user is authorized to access.
- Continuous verification: Security controls continuously monitor users, devices, and access conditions instead of relying on a single authentication event.
To implement these principles, organizations need security controls that can verify access, enforce policy, and continuously reassess trust in real-time.
A Phased Approach to Zero Trust Adoption
For most organizations, the question is no longer whether to adopt zero trust, but how to implement it effectively within existing infrastructure, operating models, and security priorities. NIST defines zero trust as an architectural approach instead of a single product. This implies that full infrastructure replacement isn’t necessary.
By building on existing infrastructure and strengthening controls incrementally, organizations can improve security maturity over time. In this context, firewall-based ZTNA (Zero Trust Network Access) is an ideal starting point. It strengthens access control without requiring a total network redesign.
Firewall-Based ZTNA
Unlike traditional VPN-based remote access, ZTNA requires organizations to verify each connection request before granting access. It evaluates every access request based on identity, device security posture, and policy before it is granted.
Traditional VPNs often grant users broader access than their roles require. ZTNA reduces this attack surface by design, providing organizations with tighter control over resource access.

Figure 1. Zero trust architecture
A firewall-based model simplifies adoption. Since firewalls are already core components of most enterprise environments, organizations can build on their existing infrastructure.
Our ZTNA Architecture
We provide a ZTNA implementation approach based on AhnLab XTG, our next-generation firewall.
The architecture includes three main components:
- ZTNA client installed on the user device.
- ZTNA Manager that serves as the Policy Decision Point (PDP).
- ZTNA Gateway that acts as the Policy Enforcement Point (PEP).

Figure 2. AhnLab’s ZTNA architecture
When a user attempts to access a server, the client sends authentication data and device posture information to the ZTNA Manager. The Manager evaluates the request against security policies and determines whether to allow access. The Gateway then controls the traffic path to the server. Together, these components enforce zero trust access control.
Explicit verification
AhnLab XTG verifies every access request before a connection is established. It goes beyond basic user authentication and evaluates a broader set of device security conditions, including OS and browser information, antivirus installation and engine update status, and real-time protection status. Based on these signals, AhnLab XTG enforces access policies with greater precision.
Least privilege access
When a user attempts to access a server, the client provides authentication data and device security posture to the Manager. The Manager verifies this against the policy and grants the minimum level of access required, ensuring users can only reach authorized resources.
Continuous verification
AhnLab XTG continuously verifies device security posture after access is granted. It reevaluates posture at defined intervals and adjusts access if conditions change. For example, if a user disables their antivirus after connecting, AhnLab XTG will block access during the next verification cycle. Once the device returns to a compliant state, access is automatically restored.
How AhnLab XTG Supports Zero Trust Adoption
AhnLab XTG helps organizations put zero trust into operation without a costly overhaul of their environment. It leverages the firewall infrastructure they already use, strengthening access control while maintaining existing network security functions.
Minimal Infrastructure Change
AhnLab XTG extends access control without disrupting the network security functions that existing firewalls already provide. Organizations can apply it at the current firewall layer and deploy clients to user endpoints, enabling them to implement zero trust without redesigning the surrounding network environment.
It also gives organizations flexibility in how they structure the architecture. In an ideal deployment, the PDP and PEP operate as separate components. In early-stage deployments, however, organizations can run both roles on a single appliance. This approach allows them to start with minimal infrastructure change and expand the model over time.
Stronger Security for IPsec VPN and SSL VPN
AhnLab XTG integrates seamlessly with existing network functions. Organizations can apply ZTNA-based access control to IPsec VPN traffic between offices and to SSL VPN access for remote work. By verifying identity and posture before allowing a connection, AhnLab XTG significantly strengthens legacy VPN security.
Microsegmentation
AhnLab XTG supports microsegmentation, allowing organizations to classify users and devices by security level. For instance, users with higher security clearance can access a broader set of servers, while those with lower levels are restricted. This enables more precise policy application based on the specific risk level of the user and device.
Zero Trust Through Solution Integration
We have extended zero trust beyond the network layer by integrating endpoint security and threat intelligence platforms:
- V3, EDR, and EPP for endpoint threat detection and response
- XDR and TI platforms for threat analysis and coordinated response
- Firewall-based ZTNA for network access control
By integrating our security platforms, we share security context with organizations in real time. If abnormal behavior is detected on the endpoint, the ZTNA solution can immediately block access. Organizations can also automate response by updating firewall policies based on XDR analysis.
Conclusion
Zero trust is not a security model that organizations complete with a single solution. It is a long-term strategy that they need to build in stages based on their environment and level of security maturity.
As cloud migration, remote work, and branch operations continue to expand, perimeter-based security can no longer provide the necessary level of control. Organizations need a model that verifies every request and continuously reassesses trust based on real-time conditions.
Firewall-based ZTNA provides a practical path for this transition. By using existing infrastructure to first strengthen access control and device verification, organizations can then expand their architecture over time through EDR, XDR, and threat intelligence integration. With AhnLab XTG, we support this phased approach through a unified security architecture that connects network security, endpoint security, and threat intelligence.
- AhnLab