Back to Blog
Legal Compliance

How to Combine Zero Trust with Law No. 5651 Compliance (2026)

How to Combine Zero Trust with Law No. 5651 Compliance (2026)
Zero Trust and 5651 together: identity, segmentation, Captive Portal, NAT/DHCP logs, ZTNA, and the evidence chain in one architecture.
Published
August 04, 2026
Updated
August 04, 2026
Reading Time
14 min read
Author
LeonX Expert Team

Combining Zero Trust with Law No. 5651 compliance means building “never trust by default” access control in the same architecture that produces legally usable internet-access evidence. Short answer: Zero Trust narrows identity and access; 5651 preserves who–when–which IP/port with integrity. One is a security model, the other a legal logging discipline—they do not conflict when designed together. “We deployed ZTNA, so 5651 is done” or “we bought a logger, so we have Zero Trust” are both wrong.

This guide is written for:

  • Network and security teams starting a Zero Trust / ZTNA journey
  • IT leaders who must own 5651 logging and evidence technically
  • Ops teams running guest Wi-Fi and remote access together
  • CISOs who want security transformation and legal compliance in one program

Quick Summary

  • Zero Trust: verify, least privilege, continuous monitor; 5651: produce access evidence, protect integrity, retain it.
  • Shared spine: strong identity, segmentation, central logs, NTP, timestamps.
  • ZTNA shrinks VPN exposure but does not remove DHCP/NAT/identity logging needs.
  • Guest Wi-Fi under Zero Trust needs a separate zone + Captive Portal; under 5651 it needs a separate log scope.
  • 5651 basics: What Is 5651?; evidence: IT Perspective.
  • Fortinet ZTNA example: Zero Trust Network Architecture with Fortinet.

Table of Contents

Zero Trust and 5651 compliance

Image: Wikimedia Commons - The Gathering 2019 Switch, server and firewall (identity/access control and log-source context).

Why Zero Trust and 5651 Belong Together

Zero Trust does not trust the network by default; it verifies identity, device posture, and policy every session. 5651 requires organizations that share internet access to keep evidentiary access records. The overlap is identity and traceability.

Short definition:

Zero Trust + 5651 is an integrated design that binds least-privilege access to identity while protecting NAT/DHCP/timestamped records in a legal archive.

5651 overview: What Is 5651?. Logging scope: 5651 Logging.

Shared Architecture Map

LayerZero Trust contribution5651 contribution
IdentityMFA, IdP, device trustUser↔session mapping
NetworkZones/VLANs, microsegDHCP lease separation, guest isolation
AccessZTNA / app-level allowVPN/ZTNA session + NAT logs
MonitoringContinuous telemetryCentral archive + timestamps
GovernancePolicy / least privilegeRetention 2-year frame, delete rights

Network pitfalls: 5651 Network Architecture. Integrity: Log Integrity.

Identity, Device, and Access

Under Zero Trust, “I’m on the LAN” is not trust. For 5651, shared accounts and anonymous guest Wi-Fi weaken the evidence chain.

  1. One person, one account—no shared admins
  2. MFA (especially remote access)
  3. Device posture (EMS / MDM where possible)
  4. Guests: Captive Portal + separate DHCP pool
  5. Logging on for every critical allow

FortiGate access control: Access Control ISO 27001. SSL VPN: FortiGate SSL VPN.

Pro Tip: Add a “5651 evidence output” column to every Zero Trust project card: list which log sources each new path (ZTNA, Wi-Fi, VPN) produces.

Segmentation, Wi-Fi, and NAT Logs

Zero Trust segmentation makes 5651 easier:

  • Separate staff / server / guest / mgmt zones
  • Default-deny from guest to internal servers
  • Mandatory NAT/PAT logs on a single public IP
  • DHCP lease duration and logs in IPAM/SIEM

VLAN: FortiGate VLAN. Policy: Policy Configuration. Evidence chain: 5651 Evidentiary Value IT.

ZTNA, VPN, and the Evidence Chain

ZTNA grants app-level access and shrinks classic SSL VPN surface. Still:

  • ZTNA session logs must reach SIEM
  • If egress is still NATed, NAT logs remain mandatory
  • App-level access does not erase DHCP needs (especially campus Wi-Fi)
  • During VPN→ZTNA migration, do not close old tunnel logging before the new path is proven

Fortinet ZTNA design: Zero Trust with Fortinet. Firewall logging: FortiGate Logging.

SIEM: Security + Legal Archive

TierPurposeTypical duration
Hot (SOC)Alerting / IR30–90 days
Legal / 5651Evidence archivepolicy; often 2 years
Access controlWho may delete?Separate role + audit

A shared syslog pipe is fine; a deletable hot index ≠ legal archive. Architecture: SIEM and 5651. Archiving: 5651 Archiving. ISO monitoring: FortiGate Logging ISO 27001.

90-Day Joint Roadmap

PeriodZero Trust5651
Days 1–30Zone + identity inventoryDHCP/NAT log inventory, NTP
Days 31–60MFA + guest Captive PortalTimestamp + central archive test
Days 61–90Pilot ZTNA / narrowed VPNLegal-request procedure + review

NTP target: offset <1–2 s. Write the retention policy down.

Most Common Mistakes

  • Treating ZTNA as a 5651 exemption
  • Leaving guest Wi-Fi as an “open zone” outside Zero Trust
  • Claiming least privilege with identity-less VPN
  • Using the SOC SIEM as the only 5651 archive
  • Declaring a Zero Trust project without segmentation
  • Expecting evidence from traffic logs without NAT

Related Articles

Checklist

  • Identity (MFA) + device-trust policy defined.
  • Staff / guest / server / mgmt zones separated.
  • Captive Portal or equivalent guest identity exists.
  • DHCP + NAT/PAT land in a central archive.
  • NTP aligned (<1–2 s); timestamping active.
  • ZTNA/VPN session logs in SIEM.
  • SOC hot index separated from legal archive (2-year frame).
  • Legal-request procedure written.
  • Zero Trust project cards list 5651 log outputs.

Next Step with LeonX

Combining Zero Trust with 5651 is identity + segmentation + evidence—not a single appliance. LeonX finds gaps via Cybersecurity Assessment and connects ZTNA/access with legal archives through Network Security, Firewall and IPS/IDS and SIEM Integration. Start at Contact.

Frequently Asked Questions

Does Zero Trust automatically satisfy 5651?

No. Zero Trust narrows access; 5651 still needs DHCP/NAT, timestamps, and retention.

If we have ZTNA, do we still need VPN logs?

During migration, log both paths. In the steady state, ZTNA sessions plus the NAT/identity chain must cover the required scope.

Does guest Wi-Fi conflict with Zero Trust?

No—guests need a separate trust zone + Captive Portal + separate log scope.

Can one SIEM serve both?

Yes as a shared pipe. Separate hot SOC index from legal-archive policy: SIEM and 5651.

How does KVKK fit?

Three frames (Zero Trust security, 5651 evidence, KVKK personal data) have different purposes: 5651 vs KVKK.

Sources

Internal Link Path

Continue to the most relevant service pages

Use the links below to move from this article to the primary service, the most relevant detail page and the contact flow.

Share this article

Related Posts

Discover more on similar topics

Law No. 5651, Cybersecurity, and Evidentiary Value: An IT View (2026)
Legal Compliance
2026-08-03
13 min read

Law No. 5651, Cybersecurity, and Evidentiary Value: An IT View (2026)

How IT should read 5651 logs for cybersecurity and evidentiary value: chain of custody, NTP, NAT/DHCP, timestamps, SIEM, and a practical checklist.

Read Article
What Is Law No. 5651? A Short, Clear Guide for Companies (2026)
Legal Compliance
2026-08-02
12 min read

What Is Law No. 5651? A Short, Clear Guide for Companies (2026)

What is Turkey’s Law No. 5651 for companies? Who is obligated, which logs, timestamps, retention, KVKK differences, and a practical checklist.

Read Article
Common Mistakes in Designing 5651 Compliant Network Architecture
Legal Compliance
2026-07-10
9 min read

Common Mistakes in Designing 5651 Compliant Network Architecture

We examine the most common technical and architectural mistakes made when designing network infrastructure to ensure compliance with Law No. 5651, their cybersecurity risks, and correct solutions.

Read Article

Subscribe to Our Newsletter

Get the latest insights, trends, and expert advice delivered directly to your inbox. Join our community of IT professionals.

We respect your privacy. Unsubscribe at any time.