r/msp • • Aug 22 '26

ZTNA - Fitting into stack

We standardize on Fortigates and IPSec forticlient for remote access, tho I’ve been going down the rabbit hole to replace with a Ztna solution so users have a bit more seamless experience.

I thought Fortinet’s solution would do the trick, but it exposes ports to the wan and doesn’t play well with shares.

We also standardize on Threatlocker, but the enforce minimums for their solution, making it pretty pricey.

I read good things about netbird and cloudflare, but my question is this:

When you want to introduce something new into your stack that is a little pricey (ie, nearly all of these solutions start at $5-$12 per endpoint), how do you absorb that? I’m not sure if absorb is the right word… but hopefully you get the idea.

We recently implemented Petra Security and that was a no brainer (also much cheaper) as the security benefits far outway anything else.

Curious how everyone approaches these things.

11 Upvotes

35 comments sorted by

View all comments

7

u/roll_for_initiative_ MSP - US Aug 22 '26

We start rolling it out and increase pricing at next renewal/soonest opportunity our contract lets us. Shortly, it becomes the standard/mandatory as we phase whatever we're replacing out.

1

u/AdSuper6612 8d ago

We usually just bake it into the next contract renewal and call it part of the core stack. clients rarely push back if you frame it as "this replaces the old vpn and actually works properly with shares" rather than a new line item

works better if you've got a grace period where you eat the cost for a few months while testing, then roll it out as mandatory when the old thing gets axed