T Techclick ← All lessons
Zscaler · ZPA · Migration program

GP → ZPA migration plan — prereq, implement, rollback

This page is the program, not the theory. Concept lives in the Rahul / ERP lesson. Here you run one training company — Apex Freight — through prerequisites, a numbered implement plan, five data scenarios, and a rollback you can execute at 02:00.

18 min read·L2 primary·Quiz at end

After this page you can

The Friday cutover ticket

Ticket: “Turn off GlobalProtect this weekend. ZPA is installed.” That is not a migration. A migration has a data pack, a wave list, pass/fail numbers, and a rollback owner. Zscaler’s own VPN-to-Zero-Trust sequence is assess → map apps → least-privilege policy → deploy → IAM → test. You do not skip to “disable the portal.”

Hero · plan before cutover
War-room plan connecting a user through a broker to one app, with the old VPN gateway unused
Cutover is a wave, not a company-wide switch. The old GlobalProtect portal stays committed until the last wave has proof.
Quick answer

Do not migrate “the VPN.” Migrate named applications to named groups. For Apex Freight (training sample): 200 GP users, 2 DCs, 12 publishable apps. Week 0 freeze GP. Week 1 IdP+SCIM+connectors. Week 2 ERP/jump/WMS as defined segments plus a discovery wildcard. Week 3 dual-run 20 Finance users. Week 4 next wave only if P1–P7 pass. Rollback unit = one IdP group. Discovery dies last.

Apex Freight data pack (training sample)

All numbers below are a classroom scenario, not a live customer. Use them as the sheet you would actually build from GlobalProtect logs, firewall rules, and the IdP.

Inventory · apps into groups into policy
Pipeline of inventory cards flowing into identity groups and a policy engine
If a row has no owner group and no ports, it is not ready to become an Application Segment.
FactTraining valueWhy it matters
CompanyApex Freight (sample)Two DCs: Mumbai HQ apps, Pune warehouse apps
GP users200 always-on clientsNever move all 200 on day one
IdP groupsFinance 35 · Ops 80 · HQ 70 · Contractor 15SCIM must show these counts before policy
SitesMumbai DC + Pune DCOne connector group per site, same geo inside a group
GP objects to keepPortal gp.apexfreight.example + gateways gp-mum, gp-punRollback path. RFC-style names only
Discovery (temporary)*.apexfreight.internal + authenticated-employee AllowSafety net. Not the end state

Application inventory extract (do not publish the last two rows)

AppFQDN / targetTCP/UDPSiteOwner groupClass
ERPerp.apexfreight.internal80, 443, 8443MumbaiFinanceCrown jewel — define week 2
Finance filesfinfiles.apexfreight.internal445MumbaiFinanceCrown jewel
Jump hostjump-mum.apexfreight.internal3389 TCP+UDPMumbaiOpsCrown jewel — ICMP from connectors
AD / DFSdc01.apexfreight.internal88, 135, 389, 445, 636MumbaiHQCrown jewel — local connector group
WMSwms.apexfreight.internal443PuneOpsDefine before Pune wave
Vendor portalvendors.apexfreight.internal443PuneContractorTight Allow + Block anything else
Intranetintranet.apexfreight.internal443MumbaiHQKnown app — week 4
HRhr.apexfreight.internal443MumbaiHQKnown app
Printer VLAN10.40.12.0/24anyPuneDo not publish — not an application
Camera VLAN10.40.20.0/24anyPuneDo not publish — old VPN habit
Data rule

If the inventory row is a subnet with no owner, it is not a ZPA application. Publishing 10.40.12.0/24 rebuilds GlobalProtect inside ZPA.

Prerequisites (gate, not a wish list)

Week 1 does not start until every row is green. A red row is a stop, not a “we will fix it in the pilot.”

GateApex Freight passFail = stop
ZPA license / tenantZPA edition that includes App Connectors is liveNo connectors, no path
SAML IdPEntra (or Okta/Ping) app for ZPA; same NameID style as GPUsers cannot authenticate
SCIM first cycleFinance 35, Ops 80, HQ 70, Contractor 15 visible in ZPADo not write group policy yet. Source: Access Policy deployment guide
Connector hosts2× Mumbai + 2× Pune. Min 4 GB / 2 CPU; Zscaler recommends 8 GB RAM. Plan ~500 Mbps each, N+1Single VM = no rollback inside the site
Connector networkOutbound TLS 443 to ZPA. Internal DNS. App ports. ICMP to servers (mandatory for UDP)User sees “app down”
No ZIA hairpinConnector outbound does not go via ZIA PSEZscaler does not recommend this
ZCC + bypassApp Profile lists gp.apexfreight.example, gp-mum, gp-pun in VPN Gateway BypassDual-run flaps
GP stay-alivePortal + both gateways still committed, licensed, certs > 60 daysNo parachute

Implement plan (4 weeks)

Journey · prereq → dual-run → wave → rollback ready
Four glass panels for Prerequisites, Dual-run, Wave, Rollback
Rollback is a column on the plan, not an appendix you write after the outage.
Flow 1 · Apex Freight weeks
Week 0–1 Freeze GP · IdP · SCIM Week 2 4 connectors · ERP/WMS Week 3 20 Finance dual-run Week 4+ Ops / Pune / contractors GP portal stays live through every box. Discovery wildcard dies after week 8–12, not week 3.

Each arrow is a gate. If SCIM counts are wrong, you do not install ZCC on Finance laptops.

  1. Week 0 — Freeze GlobalProtect

    Export portal/gateway config. Snapshot HIP and split-tunnel. No “clean up unused gateways” this week. Source: GlobalProtect Overview.

  2. Week 1 — Identity

    Stand SAML. Run SCIM. Do not write Access Policy on groups until the first cycle shows 35/80/70/15. Source: Access Policy deployment guide.

  3. Week 2 — Connectors + first segments

    Groups DC-Mumbai and DC-Pune, N+1 each. Define ERP, finfiles, jump, WMS. Add discovery *.apexfreight.internal under them. Crown jewels get Allow + Block Any. Source: ZPA Leading Practices.

  4. Week 3 — Dual-run wave 1

    IdP group zpa-wave-finance = 20 of 35 Finance. ZCC via Intune. VPN Gateway Bypass complete. GP still on the laptop. Run P1–P7 for five business days.

  5. Week 4+ — Expand only on numbers

    Wave 2 = 40 Ops (Mumbai jump + later Pune WMS). Wave 3 = contractors on vendor portal only. After 60–90 days or ~60% entitled users, turn discovery off. Source: same leading-practices guide.

Do — Side A / B / C

Side A — IdP and GP stay-alive

  1. Confirm SCIM counts match the data pack

    If Finance shows 12 not 35, stop. Policy will deny the missing 23 and they will look like a ZPA outage.

  2. Create wave groups in the IdP

    zpa-wave-finance, zpa-wave-ops, zpa-wave-contractor. These are the rollback units. Nested under the department groups.

Side B — ZPA objects for Apex Freight

https://admin.zscaler.com · Policies → Access Control → Private Applications → Defined Application Segments
Training mock · not live

Policies → Access Control → Private Applications → Defined Application Segments → Add

Add Application Segment

ERP-Production
80, 443, 8443
erp.apexfreight.internal
DC-Mumbai
Dynamic discovery

Copy every port from the inventory (8443 included). Path: Configuring Defined Application Segments. Sample FQDN only.

Access Policy order for Apex Freight (first-match)
1 Allow  ERP-Production              memberOf = Finance
2 Block  ERP-Production              Any
3 Allow  WMS-Production              memberOf = Ops
4 Allow  Vendor-Portal               memberOf = Contractor
5 Block  Vendor-Portal               Any
6 Allow  *.apexfreight.internal      authenticated employees   ← discovery
7 Block  Any                         memberOf = Contractor     ← contractors stay in their box
8 Block  Any                         Any                       ← enable only after discovery ends

Source: Configuring Access Policies. Most-specific segment wins; missing ports do not fall back to row 6. Understanding Application Access.

Side C — Dual-run

ZCC App Profile: VPN Gateway Bypass = portal + both gateways. Do not use forwarding-profile Tunnel on a VPN-trusted network. Assign ZCC only to the current wave group. Source: Configuring ZCC App Profiles.

Five data scenarios

Use these in class or in a design review. Numbers are from the Apex Freight pack.

S1 — Greenfield wave 1 (Finance)

Given: 200 on GP, ZPA built, discovery on, ERP defined with 80/443/8443. When: 20 Finance laptops get ZCC. Then: P2 = https://erp.apexfreight.internal shows policy Allow ERP-Production and connector DC-Mumbai. A contractor who types the same URL hits rule 2 Block. GP still works for the other 180.

S2 — Discovery leftover (the recruiter hire)

Given: Someone left *.apexfreight.internal as the only segment for 90 days. When: you are hired to “create the rest of the app segments.” Then: export discovery, carve ERP/WMS/vendor first, put group Allows above discovery, copy every live port, do not delete the wildcard this week. Full script: recruiter ticket on the concept lesson.

S3 — Missing port after carve-out

Given: You created ERP-Production with only TCP 443. Users also open 8443 (from the inventory). When: Finance hits 8443. Then: more-specific segment wins; 8443 is not listed; session drops. It does not use discovery. Fix = add 8443 to the defined segment, not “open the wildcard again.”

S4 — Pune site down

Given: Both DC-Pune connectors Offline (outbound 443 blocked after a firewall change). Mumbai healthy. When: Ops cannot open WMS. ERP still works. Then: rollback unit is zpa-wave-ops only if they have no GP fallback — or leave them on GP for Pune apps. Do not disable ZPA company-wide. Restore connector egress, then re-test WMS from a Pune connector: dig + curl.

S5 — Contractor lateral-move attempt

Given: Contractor is in SCIM group Contractor. Discovery Allow exists for employees. Rule 7 Blocks Any for Contractor. When: contractor tries erp.apexfreight.internal and dc01. Then: Vendor-Portal Allow may hit for the vendor URL; ERP and AD must hit Block. If they succeed, your discovery Allow is above the contractor Block — reorder tonight.

ScenarioFirst evidence fieldWrong first move
S1 Finance pilotDiagnostics: user, ERP-Production, DC-Mumbai, rule 1Disable GP for all 200
S2 Discovery leftoverDiscovered FQDN list + who touched itDelete wildcard Friday
S3 Missing 8443Segment ports vs client dest portRebuild SAML
S4 Pune downConnector group health, only WMS failingCompany-wide rollback
S5 ContractorPolicy name on the denyPublish printer VLAN so they “just work”

Rollback plan

Ops · rollback is a scored decision
Operations desk with abstract health checks for a rollback decision
Write the trigger numbers before wave 1. “It feels bad” is not a trigger.
Flow 2 · rollback unit
Trigger 1 user / 1 app → fix segment 1 wave → drop ZCC group 1 site / IdP down → that site GP portal + gp-mum + gp-pun still live ZPA connectors and policies stay standing

Apex Freight never rolls back “the company.” It rolls back a wave group or a site’s apps.

Trigger (write this in the CAB)ActionLeave standing
>10% of the current wave fail a P1 app for 30 minutesRemove that wave from ZCC assignment. GP reconnectsAll segments, all connectors
Connector group for one site N+1 gonePark only apps in that site; keep other site on ZPAOther site’s group
IdP outageUsers with valid ZPA session may ride timeout (default 7 days). New auth fails — use GPDo not delete the IdP app
P7 drill failed on a real userDo not start the next waveCurrent wave stays or rolls back
  1. Declare the trigger in the ticket

    Example: “WMS P1 fail 14/40 Ops for 35 minutes. S4. Rolling back zpa-wave-ops.”

  2. Stop the bleed

    Pull the wave group from ZCC. Optional: Access Policy Block for that group so half-connected laptops do not black-hole FQDNs.

  3. Prove GP

    Same users open ERP/WMS over GlobalProtect. HIP and old security rules still match.

  4. Fix ZPA, then re-enter the wave through P1–P7

    Do not invent a new weekend cutover.

  5. Retire GP last

    When every in-scope group has been on ZPA past the discovery deadline and P7 unused for 30 days: remove gateway DNS, then portal, then licenses — that order only.

Proof and traps

Wave exit (Apex Freight)
TrapApex Freight exampleFix
Migrating the networkPublishing printer + camera VLANsDelete those segments. Apps only
SCIM used too earlyFinance policy while SCIM shows 12Wait for 35, then wave
More-specific dropERP segment missing 8443Add the port. Do not delete the segment
Dual-run fightBypass missing gp-punAdd every gateway FQDN/IP
Discovery foreverWildcard still there after month 6Calendar kill + request path for new apps
Say this in CAB

“We are not replacing a VPN concentrator this weekend. Apex Freight moves 20 Finance users to named segments with GP still live. Rollback is remove zpa-wave-finance. Discovery stays until the long tail has owners.”

Knowledge check

Six items on the Apex Freight data. Check answers when done.

Q1

SCIM shows Finance = 12. The data pack says 35. Wave 1 is scheduled tomorrow. What do you do?

Correct: b. Re-read Prerequisites. Group policy on incomplete SCIM looks like a random outage.
Q2

Apex Freight has 200 GP users. What is the correct first implement wave?

Correct: a. Re-read Implement plan. Crown-jewel Finance + small ring. Pune is a second site and a second connector group.
Q3

Inventory has 10.40.12.0/24 printers and erp.apexfreight.internal 80/443/8443. What becomes Application Segments?

Correct: d. Re-read the data pack. A subnet with no owner is not an application.
Q4

You carved ERP-Production with TCP 443 only. Users still open 8443. What does ZPA do?

Correct: b. Re-read S3 and Understanding Application Access. Copy every inventory port onto the defined segment.
Q5

Both DC-Pune connectors go Offline. Mumbai is healthy. Who do you roll back?

Correct: c. Re-read S4 and Rollback. Blast radius = site or wave, never “burn GP.”
Q6

Week 12: 90% of entitled users hit defined segments. Discovery is still Allow Any employee. Next move?

Correct: b. Re-read Implement week 4+ and S2. Discovery without a deadline is a cloud VPN.

Sources

Related: Concept + Rahul + recruiter ticket · App Connectors · ZPA access policy · GlobalProtect lesson