Initiative 01 • Zero Trust Network Access

Explicit Proxy Configuration

Simplifying enterprise-grade Zero Trust security through intuitive proxy configuration and management

8 months
Lead Product Designer
Enterprise Security
Explicit Proxy Configuration Interface

The Challenge

Complex Configuration Process

Setting up explicit proxy for Zero Trust Network Access required customers to navigate through multiple disconnected workflows:

  • Manual POP selection across global regions
  • Complex CNAME validation with unclear error messages
  • Disconnected authentication and security rule configuration
  • No visibility into provisioning status or progress

The Impact

2-3 weeks
Average setup time per proxy
60%
Configuration errors requiring support
85%
Customers requiring provisioning team assistance

Design Process

We broke down the complex proxy configuration into a guided, step-by-step workflow that reduces cognitive load and provides clear feedback at every stage.

1

Setup Access Points

Choose POPs, configure user distribution, and specify dedicated IP requirements

Create Proxy - Basic Information and POP Selection
Key Features
  • Smart POP recommendations based on user location
  • Visual map showing selected POPs and coverage
  • Real-time validation of user count vs subscription limits
Design Decisions
  • Grouped POPs by region for easier selection
  • Added warning when exceeding 5 POPs (additional charges)
  • Inline help text explaining dedicated IP benefits
2

Proxy Configuration Overview

Centralized view of proxy settings with guided additional configuration steps

Proxy Configuration with Additional Configuration Cards
Progressive Disclosure

We organized the configuration into logical steps that unlock sequentially, preventing users from getting overwhelmed while ensuring they complete required steps in the correct order.

Validate Domains
Available after proxy domain assigned
AIM Configuration
Available after domain validation
Auth Rules
Available after AIM setup
3

CNAME Validation

Real-time DNS validation with detailed troubleshooting information

CNAME Validation with DNS Query Results
Improved Error Handling

Instead of generic error messages, we show the actual DNS query results, making it easy for network administrators to diagnose and fix issues.

Before
"CNAME validation failed. Please check your DNS settings."
After
Shows full DNS query with ANSWER SECTION, query time, and server details
4

Proxy Management Dashboard

Centralized view of all proxies with quick access to management actions

Proxy Management Table with Actions
At-a-Glance Information
Proxy Name
Quick identification
Aryaka Domain
Copy with one click
PAC Files
Count and manage
Total POPs
Coverage visibility

Remote Users Integration

Explicit Proxy is part of the broader Remote Users access strategy, alongside VPN Client options.

Remote Users Page showing Explicit Proxy and VPN Client options

Explicit Proxy

PAC file-based proxy configuration for transparent traffic routing through Aryaka's security stack

  • No client software installation required
  • Automatic traffic routing based on PAC rules
  • Integrated with Aryaka Identity Management
  • Support for multiple domains and authentication methods

VPN Client

NCP VPN client for secure remote access with full network encryption

  • Full tunnel encryption for all traffic
  • Client software with automatic updates
  • Support for split tunneling configurations
  • Ideal for highly mobile workforce

Key UX Improvements

Design decisions that transformed the proxy configuration experience

Smart Defaults

Pre-populated fields based on customer profile and subscription, reducing manual data entry by 60%

Real-Time Validation

Instant feedback on configuration errors with actionable suggestions for resolution

Visual POP Selection

Interactive map showing coverage and latency, helping customers make informed decisions

Provisioning Status

Clear visibility into each configuration step with estimated completion times

Contextual Help

Inline documentation and tooltips explaining technical concepts in plain language

Multi-Domain Support

Manage multiple proxy domains with individual CNAME validation and configuration

Impact & Results

Measurable improvements in configuration time, error rates, and customer satisfaction

75%
Reduction in Setup Time
From 2-3 weeks to 3-5 days
80%
Fewer Configuration Errors
Through validation and smart defaults
90%
Self-Service Completion
Without provisioning team support
4.8/5
Customer Satisfaction
Post-launch survey results

Customer Feedback

"The new proxy configuration workflow is night and day compared to the old process. We were able to set up 12 proxies across our global offices in less than a week."

— IT Director, Fortune 500 Financial Services

"The CNAME validation with actual DNS query results saved us hours of troubleshooting. We could see exactly what was wrong and fix it immediately."

— Network Engineer, Global Manufacturing Company