COSGrid ZGrid

SASE Points of Presence for Security and SD-WAN

SD-WAN, NGFW, and encrypted tunnels in one vCPE — deployed anywhere, across any transport.

COSGrid ZGrid

What is COSGrid ZGrid?

When most applications lived in the corporate data centre, sending branch traffic back there to be inspected by a firewall was efficient. Now that most traffic goes to SaaS and public cloud, backhauling means sending a packet away from its destination to be inspected and then back again — a detour called hairpinning that adds latency to every session. A PoP-based architecture removes the detour: each site and user connects to the nearest cloud point of presence, and inspection happens there, close to the user and close to the internet exit, while policy stays centralised.

BUILT IN

FirewallWeb FilteringApplication ControlIntrusion PreventionInline CASBDLP

DEPLOYED AT

ZGrid is that fabric for COSGrid. It is a separate component from the branch gateway because its job is different: ReFleX-Edge secures one site at its physical edge, while ZGrid is the shared cloud tier where traffic from many sources — branches, remote users, cloud workloads, even third-party routers — lands and is inspected together, under one policy, before egress.

CONNECTS

Inside each PoP, firewall, web filtering, application control, intrusion prevention, inline CASB, and DLP run as a single-pass engine: a flow is decrypted and examined once, against one policy decision, rather than being handed from product to product with latency and disagreement at every hop.

AVAILABLE AS

India-Resident PoPs India-Resident PoPs
|
Self-Hosted / Air-Gapped Self-Hosted / Air-Gapped

How ZGrid Works

Steered to the nearest PoP
Steered to the nearest PoP
Connect
Traffic arrives over any path.
Traffic arrives over any path.
Secure the Path
Identified once.
Identified once.
Optimize Traffic
Inspected in a single pass.
Inspected in a single pass.
Govern Centrally
Enforced, egressed, and logged.
Enforced, egressed, and logged.
Govern Centrally
Optimal routing. 01
Steered to the nearest PoP

Anycast and GeoDNS send each site, user, and workload to the closest available PoP.

Role in the COSGrid Architecture

COSGrid ZGrid
COSGrid ZGrid
COSGrid GuiderCOSGrid Guider
COSGrid ReFleX-EdgeCOSGrid ReFleX-Edge
COSGrid MZA App ClientCOSGrid MZA App Client
COSGrid SARCOSGrid SAR
MicroZAccess (ZTNA) and ZT-NACMicroZAccess (ZTNA) and ZT-NAC

COSGrid Guider

COSGrid Guider (management plane) configures and monitors every PoP over an encrypted, mutually-authenticated control channel, pushing signed policy each PoP verifies before applying, and collecting its telemetry and running state.

COSGrid ReFleX-Edge

COSGrid ReFleX-Edge terminates its encrypted SD-WAN overlay on the nearest ZGrid PoP — the branch is one of the traffic sources the PoP inspects. Any third-party router speaking IPsec or GRE can also land on a PoP, so ZGrid does not require COSGrid at the branch.

COSGrid MZA App Client

COSGrid MZA App Client tunnels remote users to the nearest PoP, so an off-network user gets the same inspection and policy as a branch.

COSGrid SAR

COSGrid SAR consumes the flow, session, and threat telemetry the PoPs produce to baseline behaviour and detect threats, and automated responses are applied back at the PoP.

MicroZAccess (ZTNA) and ZT-NAC

Together with ReFleX-Edge, ZGrid is where MicroZAccess (ZTNA) and ZT-NAC (NAC) access decisions are enforced in the cloud tier — one policy plane across SD-WAN, SASE, and access.

Key Features of COSGrid ZGrid

Single-pass inspection
Firewall, secure web gateway, intrusion prevention, inline CASB, and DLP run in one traversal of a flow, against one policy decision — not a chain of products each decrypting, inspecting, and re-encrypting the same traffic. One decision, one log record.
Enforcement close to the user
Anycast routing sends each site, user, and workload to the nearest PoP, so traffic reaches the internet and SaaS directly instead of hairpinning through a central data centre. Inspection is near the user and near the exit.
India-resident, sovereignty-ready
India-resident PoPs inspect and log regulated traffic in-country, aligned to RBI and CERT-In requirements. For stricter boundaries, the same engine runs self-hosted or fully air-gapped — a deployment model the cloud-only SASE platforms do not offer.
Lands any source
Branches (ReFleX-Edge or any IPsec/GRE router), remote users (MZA App Client), and cloud workloads (AWS/Azure/GCP connectors) all terminate on the same PoP and get the same policy — so COSGrid security can be adopted without replacing existing branch equipment.
Session continuity and resilience
Preserves the client-facing IP across a link failure, so long-lived sessions — virtual desktop, VoIP, core banking — survive a WAN failover instead of dropping. Anycast re-establishes sessions at the next nearest PoP if one becomes unavailable; existing MPLS circuits can terminate alongside broadband and SD for site-to-site migration.

Technical specifications

Capability
India-resident enforcement
Deployment
Security services
Onboarding methods
TLS inspection
PoP failover
Session continuity
Management
Support
Yes — inspection and logging in-country
Cloud PoP fabric; self-hosted; fully air-gapped
FWaaS, SWG, IPS, anti-malware, inline CASB, DLP, RBI, DNS-layer filtering, DDoS/volumetric protection
SD-WAN peering (ReFleX-Edge), IPsec, GRE, MZA App Client, explicit proxy/PAC, DNS forwarding, cloud connector (AWS TGW / Azure vWAN / GCP NCC)
Selective, per-tenant CA, category bypass lists
Anycast/BGP reroute
Client-facing IP preserved across WAN failover
COSGrid Guider (cloud-hosted or self-hosted)

How Does It Work?

See how the product eases out to solution.

Contact Us