AppGate ZTNA, an industry-leading Zero Trust Network Access (ZTNA) solution, puts your people first with simple, fast, secure connections to multi-cloud, on-prem, or legacy applications - from anywhere. AppGate ZTNA is a cloud-native, unified, API-enabled solution which delivers valuable security, efficiency and user experience benefits. Each user has a one-to-one encrypted network segment to each location where resources have been explicitly granted. Developers enjoy concurrent and automated access to multiple, disparate environments without waiting for manual access approvals. Admins can easily ensure that users have access to necessary resources, regardless of physical location or virtual segmentation.
AppGate ZTNA, an industry-leading Zero Trust Network Access (ZTNA) solution, puts your people first with simple, fast, secure connections to multi-cloud, on-prem, or legacy applications - from anywhere. AppGate ZTNA is a cloud-native, unified, API-enabled solution which delivers valuable security, efficiency and user experience benefits. Each user has a one-to-one encrypted network segment to each location where resources have been explicitly granted. Developers enjoy concurrent and automated access to multiple, disparate environments without waiting for manual access approvals. Admins can easily ensure that users have access to necessary resources, regardless of physical location or virtual segmentation.
Highlights
Enable all users: Consistent secure multi-tunnel access for anyone working from anywhere, whether in the office or remote
Secure all devices: Reliable, easy secure access from managed or unmanaged devices of all makes and models
Protect all workloads: Unified, multi-tunnel secure access for multi-cloud, on-premises and even your tried-and-true core legacy apps
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 15 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for AppGate ZTNA running on your chosen Amazon EC2 instance type. Pricing is usage-based, so the hourly rate depends only on the instance size you deploy. The many options span several EC2 families: general-purpose (m, t), compute-optimized (c), and memory-optimized (r). Within each family, rates scale with instance size, from smaller instances up to larger multi-xlarge configurations. You match instance size to the performance and scale your deployment needs. There is no upfront commitment; you are billed for the hours each instance runs.
Top-of-mind questions for buyers
What software runs on the EC2 instance I pay for by the hour?
Each instance runs an AppGate ZTNA appliance. Appliances take roles in what AppGate calls the collective. The Controller acts as the policy engine and decision point. The Gateway enforces access to protected resources. You size the instance to the role and scale your deployment requires.
Am I charged when an instance is stopped or powered off?
The software rate meters running instance-hours only. A fully stopped instance does not accrue hourly software charges. Underlying AWS storage fees may still apply while the instance exists. You are billed only for the hours each instance actually runs.
Can I run several instance types together, and how do the charges combine?
Yes. A deployment can include multiple appliances in different roles, such as Controller and Gateway. Each running instance bills at its own hourly rate for its chosen size. The charges add together on one invoice. Larger or more instances raise the combined hourly total.
www.appgate.com
Helpful?
Vendor refund policy
We do not currently support refunds at this time
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Identity-based, role-driven access policies with device verification, location-aware post-authentication checks, and Access Control Lists for network segmentation and lateral movement prevention.
Multi-Factor Authentication and Flexible Authentication
Support for multiple authentication methods including SAML, LDAP, RADIUS, PAM, local authentication, built-in TOTP-based multi-factor authentication, and X.509 PKI with external PKI support.
Kernel-Accelerated Data Encryption
OpenVPN Data Channel Offload (DCO) technology that moves encryption and decryption operations into the OS kernel for improved throughput and reduced CPU processing overhead.
Application-Aware Traffic Routing
Domain name-based and IP CIDR-based routing policies for defining access controls to cloud-hosted, SaaS, and internal applications with support for split-tunnel and full-tunnel configurations.
High Availability and Scalability
Multi-node clustering across multiple Access Server instances with DNS-based traffic distribution for load balancing and increased capacity to support demanding AWS workloads.
Zero Trust Architecture
Cloud-native zero trust platform that applies zero trust principles to eliminate attack surface and prevent lateral movement across users, applications, and infrastructure.
AI-Powered Threat Detection
AI-powered cyberthreat and data loss prevention services that detect and prevent advanced threats, accidental exposure, theft, and ransomware attacks.
Next-Generation Network Access
Next-generation zero trust network access (ZTNA) platform enabling seamless and secure connectivity to private applications, services, and operational technology devices.
Data Loss Prevention
Data protection capabilities preventing data loss from users, SaaS applications, and public cloud infrastructure through comprehensive loss prevention policies.
End-to-End Digital Experience Monitoring
End-user perspective monitoring and visibility across device, ISP, cloud proxy, and application layers to optimize performance and identify application, network, and device issues.
Zero trust access has strengthened remote connectivity and secures diverse office devices
Reviewed on Aug 12, 2026
Review provided by PeerSpot
What is our primary use case?
Appgate SDP is used for user connectivity both in the office and outside the office for remote connectivity. When outside the office, we connect to office resources, and when in the office, we connect to Appgate SDP before accessing our resources. This provides a zero trust approach to security.
What is most valuable?
Compared to Cisco AnyConnect, Appgate SDP is lighter and offers perfect support that is always timely. The moment a ticket is raised, it receives immediate attention. The application discovery feature is effective, and the IoT connectors are particularly valuable. These connectors allow us to enforce security policies on devices where we cannot install the Appgate SDP clients, such as desk phones, cameras, and printers.
Previously, with AnyConnect, we experienced frequent issues. In comparison to that solution, we have seen significant improvement and minimum downtime.
What needs improvement?
Appgate SDP support is always available to assist, which is the primary strength. However, there are areas for improvement. When a user is unable to connect, the platform should display detailed information such as the user's IP address, MAC address, and specific reasons for connection failure. Currently, aside from invalid username and password errors, Appgate SDP provides generic errors related to policy, such as a policy admin error. The system should provide deeper diagnostics to explain why a user cannot connect.
The dashboard could also be enhanced with additional features and logins to provide better visibility. Sometimes there is no immediate clarity about what is happening. After using Appgate SDP for a long time and experiencing various errors, we have learned where to investigate, but this would be problematic for new users trying to resolve issues. The dashboard could display user connection times, failure reasons, and other relevant information.
The user activity logs and accounting features should be improved in particular.
For how long have I used the solution?
Appgate SDP has been in use for approximately four years.
What do I think about the stability of the solution?
There is a single point of failure as only Appgate SDP is being used. There have been one or two instances of downtime approximately two years ago. The issue involved a CPU reaching 100% utilization, but this was internal and network-related rather than an issue with Appgate SDP itself.
What do I think about the scalability of the solution?
Appgate SDP is very scalable.
How are customer service and support?
Appgate SDP is currently in use. Before a user connects to Appgate SDP, several checks are performed through created policies. There is a policy for MacBooks, another for Linux, and another for Windows. On Windows, the system verifies that antivirus is installed and up to date, that Windows is updated, and that other security measures such as SentinelOne are installed. Many requirements must be met before a user is able to connect.
Which solution did I use previously and why did I switch?
Initially, Cisco AnyConnect was used. Compared to Cisco AnyConnect, Appgate SDP is lighter, and the support is perfect.
Previously with Cisco AnyConnect, we experienced frequent issues. In comparison, we have seen significant improvement and minimum downtime.
How was the initial setup?
The initial setup was not complicated because everything was explained in detail, including the different approaches available. The implementation team explained which approaches were recommended and which ones were preferred. When they noticed concerns with a particular approach, they provided best practices and guidance.
What about the implementation team?
The implementation team consisted of approximately 19 or 20 members, and I was part of that team.
Which other solutions did I evaluate?
The contract with the previous vendor expired, and MTN Group decided to switch vendors after working with Cisco for many years. Appgate SDP won the RFP at that time, so the decision to work with them was made at the group level rather than by our team specifically.
Luciana S.
Robust Zero-Trust Remote Access with Flexible Deployment and Great Visibility
Reviewed on May 27, 2026
Review provided by G2
What do you like best about the product?
Appgate SDP gives zero trust or tolerance to network access and this ensures there is robust network security more than any traditional VPNs The software provides detailed access controls and this revolves device posture, user identity, context and location. Appgate is helpful in offering secure remote access and no internal network exposure experienced The program issues scalable security support, more so on remote and distributed workforces The deployment for Appgate is flexible, and it can work on cloud, on premises or hybrid without problems The configuration process is simple and it has a user friendly access encounter Appgate provides brilliant visibility, more so on network activity and user access
What do you dislike about the product?
Appgate has complex architecture planning, which makes the initial set up challenging The tool demands some expertise on security and networking more so during the deployment phase
What problems is the product solving and how is that benefiting you?
Appgate gives secure network access to authorized users and this happens to different applications, internal infrastructure and sensitive systems The program gives protection to hybrid and remote work, helping employees to have secure access from any working environment Appgate manages complex access permissions and this includes user authentication, device trust validation and among others The program is designed to protect sensitive data and applications, for instance, cloud workloads, financial systems, and administrative systems Appgate eliminates exposure to to any attacks that may be internet based and this includes launching unauthorized scans There is zero trust security measures and this allows proper trust verification, identity centric monitoring among others
Brandon G.
Smart, Secure Remote Access with AppGate SDP
Reviewed on May 22, 2026
Review provided by G2
What do you like best about the product?
I find AppGate a smart solution for remote access and micro-segmentation that assimilates with your centralized user security structure very well. I love the inherent DOS security features of the system such as no open scannable ports on their appliances. I find the site, collective and user management approach of the system very practical and effective. Since changing our remote access to AppGate literally all of our network engineers have complimented on the intuitiveness of the client and resiliency of the connections. SPA key coupled with MFA and with continuous IdP re-authentication represents a strong security posture imo. AppGate SDP is a very flexible system and has a lot of cool features from a security engineering perspective. The AppGate team has been very responsive and helpful and have continuously proven their proficiency of ZTNA and network security. Also, I find the per user pricing structure of the product a value. I highly recommend the product.
What do you dislike about the product?
As with all new products that take a different approach, there will be a learning curve. AppGate is no different. The product heavily relies on how well thought through your Identity Provider and DNS systems are and requires the customer to be prepared to implement such a system. Ultimately, it is for the better.
What problems is the product solving and how is that benefiting you?
Remote access, micro segmentation and ZTNA preparedness are just a few. Also, use cases for integrating access across IPv4/IPv6 dual-stacked networks and bridging those with legacy systems.
Rajeev_Ranjan
Zero-trust access has improved our secure VPN connectivity and protected internet usage
Reviewed on May 20, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for Appgate SDP is for security purposes. We are trying to use it to connect with our VPNs and the network so that we can improve our organization's security.
A specific example of how we use Appgate SDP for security and with our VPNs is that Danfoss security team has implemented a no-trust policy, requiring everybody to install Appgate SDP with a default account. Whenever we start our system, it will automatically connect to the different VPNs through which our network is going. If it is disabled, we are unable to access the internet, as all our network goes through a firewall. If Appgate SDP is not connected to all of the VPNs, then we are not able to browse the internet.
What is most valuable?
In my experience, the best features Appgate SDP offers are reliable connectivity across different environments and strong policy-based access.
When I mention strong policy-based features, I mean that if I want to secure all the systems in my organization, I can apply a particular policy through which all the network has to go, making it easy to implement security compliance throughout the organization.
Appgate SDP has positively impacted my organization, as we are using it to securely access the internet after the cyber attack. After the implementation of Appgate SDP, I did not hear about any security incidents.
What needs improvement?
If I could change or improve anything about Appgate SDP, it would be to enhance the user experience by improving the UI so that it is more explanatory. Currently, the UI feels as though it is doing something behind the scenes, and at first sight, nobody can understand what this application is for. I think that is the main thing regarding needed improvements.
For how long have I used the solution?
I have been using Appgate SDP for around two years.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that this whole thing is managed by the security team, and there are different teams involved, so I do not have knowledge about cost. I think it is important for security because if a security incident happens, you lose more money than you save.
What other advice do I have?
I do not have anything else to add about my main use case or how it is set up for my team. I do not have anything else about the features I find valuable.
My advice for others looking into using Appgate SDP is to use it, as it is a good application.
T Nagesh K.
Appgate SDP Delivers True Zero Trust with Fast, Direct Access
Reviewed on Apr 23, 2026
Review provided by G2
What do you like best about the product?
I like Appgate SDP best because it enforces true Zero Trust by making applications invisible and granting fast, direct access only to explicitly authorized users—without exposing the network
What do you dislike about the product?
I don’t have any specific dislikes at this time; it has effectively met our security and access needs.
What problems is the product solving and how is that benefiting you?
Appgate SDP addresses the issue of overly broad, VPN‑based network access by enforcing true Zero Trust access only to authorized applications. For us, this translates into a reduced attack surface, stronger security, and seamless access for users.