VPNs might finally be dead thanks to Twingate, startup built by Dropbox alums
techcrunch.com
techcrunch.com
No properly set up corp vpn would push a default route.
That said, we're big fans of ZS and think they are doing the world a huge favor by getting folks off traditional VPN :)
(see my answer above)
You can also apply granular controls over how each connection is routed based on security and access policies. These policies are tied to your identity (via your IDP - Okta, Gsuite, etc) for easy user mgmt. You're essentially able to setup identity-based access controls on any destination address whether it's a web app, database, ssh server, etc. Very flexible by design and we get a ton of folks in devops & infra using it.
On the network side, we also eliminate the need for a public VPN gateway so there's no public attack surface on your private network/resources. Our connectors sit behind your firewall and are deployed as an overlay to your existing network topology so you don't have to reconfigure all your existing segmentation.
Sum it all up and it's much more powerful than just a split-tunnel VPN. Check it out for yourself at www.twingate.com - it's free to get started :)