Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

Zero Trust Network Access (ZTNA) is a security model that governs access to applications and services based on user identity and contextual factors, rather than network location. In the NETGEAR Exium platform, ZTNA is used to enforce granular, policy-based access controls to private applications and network resources.

In traditional network architectures, users within the corporate network perimeter are typically considered trusted, while external users are not. NETGEAR Exium ZTNA removes this implicit trust model by assuming that no user or device is trusted by default. Each access request is verified against defined security policies, ensuring that users are granted access only to the specific resources they are authorized to use.

This article details the following tasks:

  • Configure workspace level or group level ZTNA policies
  • Configure ZTNA to limited policies
  • Configure workspace or group level ZTNA limited policies
  • Configure user level ZTNA limited policies

Configure workspace level or group level ZTNA policies

You can define ZTNA policies at workspace level which will be applied to all users in the workspace.

  1. Log in to Insight at insight.netgear.com
  2. Select the Organizations tab, and click the name of the organization.
  3. Select the Security Center tab, and click the Security Configurations button. The Exium Security page displays.
  4. From the left menu, click Sites > Zero-Trust Paths.
  5. From the dropdown menu, select the serial number of the PR60X/PR460X.
  6. Click the Add Trust Path button or search for an existing trust path.
  7. In the Allowed User Groups section, select the workspace or group.
  8. Click the Update button.

The system applies ZTNA policies to all users in the workspace or group immediately upon submission. All users in the workspace can then access any services within the specified network subnet.

Configure ZTNA to limited policies

You can configure limited access to network services by defining IP-based policies at the workspace, group, or user level. To enforce restricted access, leave the Trust Path field empty at both the workspace and group levels. This sets a default “deny all” mode, where users cannot access any services unless explicitly allowed through defined policies. The following steps describe how to configure access without assigning a trust path at the workspace or group level.

  1. Log in to Insight at insight.netgear.com
  2. Select the Organizations tab, and click the name of the organization.
  3. Select the Security Center tab, and click the Security Configurations button. The Exium Security page displays.
  4. From the left menu, click Sites > Zero-Trust Paths.
  5. From the dropdown menu, select the serial number of the PR60X/PR460X.
  6. Click the Add Trust Path button or search for an existing trust path.
  7. Ensure there are no groups or workspaces configured in the Allowed User Groups section.
  8. Click the Update button.

Exium configures routing to the specified network subnet, but no users in the workspace can access these resources.

Configure workspace or group level ZTNA limited policies

You can define limited ZTNA policies at workspace level which is applied to all users in the workspace.

  1. Log in to Insight at insight.netgear.com
  2. Select the Organizations tab, and click the name of the organization.
  3. Select the Security Center tab, and click the Security Configurations button. The Exium Security page displays.
  4. From the left menu, click Zero-Trust Policies > Rules.
  5. From the dropdown menu, select workspace or group, and click the Add Rule button.
  6. In the Name field, add a name.
  7. In the Type section, select IP.
  8. In the Action section, click Allow. By default, Block is selected.
  9. In the IP field, enter the subnet or a specific IP address.
  10. Optional: Select a protocol type and port to give access only to specific service within that IP address and port. 
  11. Click the Save button.

The system applies limited ZTNA policies to all users in the workspace or group immediately. All users in the workspace or group can access only the specific services defined in the policy.

Configure user level ZTNA limited policies

You can configure ZTNA policies at the user level to apply them to a specific user.

Before you create the user level policy, select All Rules in the Policies table.

  1. Log in to Insight at insight.netgear.com
  2. Select the Organizations tab, and click the name of the organization.
  3. Select the Security Center tab, and click the Security Configurations button. The Exium Security page displays.
  4. From the left menu, click Users and Devices > Users.
  5. Select a user name, and from the Policies menu, select a policy.
  6. Click the Update button.

After you submit the changes, the system applies the ZTNA policies to the user immediately and grants access to the specific services defined in the policy.

Last Updated:05/22/2026 | Article ID: 000070718

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email