What is our primary use case?
Appgate SDP is used for user connectivity both in the office and outside the office for remote connectivity. When outside the office, we connect to office resources, and when in the office, we connect to Appgate SDP before accessing our resources. This provides a zero trust approach to security.
What is most valuable?
Compared to Cisco AnyConnect, Appgate SDP is lighter and offers perfect support that is always timely. The moment a ticket is raised, it receives immediate attention. The application discovery feature is effective, and the IoT connectors are particularly valuable. These connectors allow us to enforce security policies on devices where we cannot install the Appgate SDP clients, such as desk phones, cameras, and printers.
Previously, with AnyConnect, we experienced frequent issues. In comparison to that solution, we have seen significant improvement and minimum downtime.
What needs improvement?
Appgate SDP support is always available to assist, which is the primary strength. However, there are areas for improvement. When a user is unable to connect, the platform should display detailed information such as the user's IP address, MAC address, and specific reasons for connection failure. Currently, aside from invalid username and password errors, Appgate SDP provides generic errors related to policy, such as a policy admin error. The system should provide deeper diagnostics to explain why a user cannot connect.
The dashboard could also be enhanced with additional features and logins to provide better visibility. Sometimes there is no immediate clarity about what is happening. After using Appgate SDP for a long time and experiencing various errors, we have learned where to investigate, but this would be problematic for new users trying to resolve issues. The dashboard could display user connection times, failure reasons, and other relevant information.
The user activity logs and accounting features should be improved in particular.
For how long have I used the solution?
Appgate SDP has been in use for approximately four years.
What do I think about the stability of the solution?
There is a single point of failure as only Appgate SDP is being used. There have been one or two instances of downtime approximately two years ago. The issue involved a CPU reaching 100% utilization, but this was internal and network-related rather than an issue with Appgate SDP itself.
What do I think about the scalability of the solution?
Appgate SDP is very scalable.
How are customer service and support?
Appgate SDP is currently in use. Before a user connects to Appgate SDP, several checks are performed through created policies. There is a policy for MacBooks, another for Linux, and another for Windows. On Windows, the system verifies that antivirus is installed and up to date, that Windows is updated, and that other security measures such as SentinelOne are installed. Many requirements must be met before a user is able to connect.
Which solution did I use previously and why did I switch?
Initially, Cisco AnyConnect was used. Compared to Cisco AnyConnect, Appgate SDP is lighter, and the support is perfect.
Previously with Cisco AnyConnect, we experienced frequent issues. In comparison, we have seen significant improvement and minimum downtime.
How was the initial setup?
The initial setup was not complicated because everything was explained in detail, including the different approaches available. The implementation team explained which approaches were recommended and which ones were preferred. When they noticed concerns with a particular approach, they provided best practices and guidance.
What about the implementation team?
The implementation team consisted of approximately 19 or 20 members, and I was part of that team.
Which other solutions did I evaluate?
The contract with the previous vendor expired, and MTN Group decided to switch vendors after working with Cisco for many years. Appgate SDP won the RFP at that time, so the decision to work with them was made at the group level rather than by our team specifically.
Which deployment model are you using for this solution?
On-premises