惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
腾讯CDC
D
Docker
The Cloudflare Blog
量子位
爱范儿
爱范儿
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Jamf Blog

Jamf Nation Live 2026 London and Berlin: AI Governance and DDM 5 Mac Security Gaps Hiding in Your Apple Fleet Classroom Management Tools and Student Learning Outcomes Mobile forensics, minutes not weeks Turn Security Signals into Action with Jamf and Amplifier Security Jamf AI Assistant Now Available: Smarter Apple Device Management and Security MacBook Neo: The New Enterprise Entry Point for Mac at Scale Boost Employee Productivity in the Enterprise with Jamf Platform Authentication and Declarative Device Management: The Future of Apple Management Automation for Small IT Teams: Save Time Managing Macs What a lower-cost MacBook Neo means for education Where Apple Meets the Enterprise: Jamf’s Interoperability Advantage for Secure, Automated Access Control Simplify access, secure your apps: why SSO matters for K-12 Inside Predator’s kernel engine RSA Conference 2026 recap: AI security, enterprise mobile security and the shift to connected security platforms ClickFix technique uses Script Editor instead of Terminal on macOS Why Mac configurations fall out of sync — and how to fix them G2 names Jamf in its 2026 Best Software Awards across three categories Empowering Mac users: How Jamf Self Service+ reduces tier one support overhead for enterprise IT teams Privacy by default, flexible when required: introducing limited privacy in Jamf Safe Internet From arrival to discharge: how iOS is reimagining the healthcare journey Federated Identity Management for K-12 Education Identity and access management in K-12 schools OpenClaw: the helpful AI that could quietly become your biggest insider threat Get Started with Scripting Series: macOS Terminal, Scripting and Jamf Pro API Managing Apple devices at Black Hat Europe with Jamf Scaling device deployments without scaling your IT team How Predator spyware defeats iOS recording indicators Making Mac work in a PC world The hidden costs of manual device provisioning
Strengthen Jamf Zero Trust Network Access With Dedicated ...
Sean Smith · 2026-04-16 · via Jamf Blog

Security and IT teams want to make it easy for users to access company resources. At the same time, they must make sure that all company traffic is secure. Using dedicated gateways to route traffic builds upon existing zero-trust models, providing extra security at the network layer.

Introducing dedicated internet gateway

A dedicated internet gateway allows organizations using Jamf’s Zero-Trust Network Access (ZTNA) to route traffic using two IP addresses specific to their environment. This means that only traffic from that specific IP address can access company applications and resources. It’s an important layer to access policies.

Dedicated internet gateways do not exist in isolation. They're one piece of a broader ZTNA architecture that continuously verifies both user identity and device health before granting access to any resource.

Jamf’s ZTNA already ensures that:

  • Devices access resources only after successful user authentication and verification that the device is free from threats.
  • Each app, service and data request requires verification before access is granted.
  • Data is secured independently of the device or authentication credentials alone.

Whereas Zero-Trust Network Access verifies which user and what device is attempting to access resources, a dedicated internet gateway controls how that access happens. With a unique egress route to match access policies, a dedicated internet gateway allows you to allowlist traffic targeting organizational resources, ensuring that access requests are recognized as trusted traffic.

By routing traffic through a fixed pair of IP addresses tied exclusively to your environment, you can:

  • Restrict access to high-value resources to only trusted, policy-compliant devices.
  • Maintain IP-based allowlisting without sacrificing the flexibility of a distributed workforce.
  • Reduce the risk of unauthorized access within the zero-trust architecture.
  • Simplify firewall and access policy management: add two IPs to your organization’s allowlist and you're done.

If you're in a regulated industry, managing access to sensitive financial or healthcare data, or want to simplify how you manage IP allowlists across a distributed workforce, dedicated internet gateways are here to help.

Creating your own dedicated internet gateway is currently available to customers as an add-on in Jamf for Mac and Jamf for Mobile. You can learn how by visiting our technical documentation here.