Zero Trust is the rule: never trust the network, connect a user to an app after identity and context. SSE is the security slice (SWG + ZTNA + CASB + FWaaS). SASE is SSE plus the networking half (SD-WAN). The Zero Trust Exchange is Zscaler’s cloud platform that brokers those connections. ZIA is user → internet/SaaS. ZPA is user → private app (App Connector egresses TCP 443; no inbound VIP). ZDX measures the hop-by-hop experience. Policy lives on the Central Authority. The Public Service Edge enforces. Nanolog stores transaction logs. First proof: https://ip.zscaler.com from the user’s device, then confirm Cloud Name on Administration → Company Profile.
1. Why the foundation ticket exists
Every Zscaler interview and every messy design review opens with the same three questions: what is Zero Trust, what is the difference between ZIA and ZPA, and where does Zscaler sit in SASE. If those three answers are fuzzy, SSL inspection, App Connectors, and DLP never get a fair hearing.
On the job the same map stops bad defaults. “Give me VPN to staging” is not a port-open request. “Outlook is slow” is not a URL-filter ticket. “We’re going SASE” is not “sign ZIA and we are done.”
Do not recite NIST SP 800-207. Say: the network is hostile. Identity and context are the perimeter. Access is per application, re-checked on the request — never once at the building door.
2. Mental model — three planes, three products
Pre-train these words before any Admin click. They are official Zscaler / Gartner names, not classroom slang.
Zero Trust
Principle. Least privilege. User-to-app, not user-to-network. Continuous verification of identity, device, app, and content.
Zero Trust Exchange
Zscaler’s multitenant cloud platform. It brokers user-to-app, app-to-app, and machine-to-machine connections using business policy.
SSE
Security Service Edge — the security slice of SASE: ZTNA, SWG, CASB, FWaaS. Zscaler positions the Exchange as this platform.
SASE
Secure Access Service Edge = networking (SD-WAN) + SSE. Full SASE needs both halves. They are not synonyms.
Read left → right. If a ticket asks “who blocked this URL?”, the answer is a Public Service Edge applying CA-pushed policy — not Nanolog, and not the Admin URL.
The Central Authority stores the policy I click. The Public Service Edge is the node that actually sees the packet. Nanolog is how I prove what happened later.
3. Zero Trust vs SASE vs SSE
These three get mashed together in vendor meetings. Separate the principle from the delivery model before you pick a SKU.
Diamond in words: if the RFP says “single-vendor SASE,” you must account for SD-WAN. If it says “SSE / SWG / ZTNA,” the Exchange is the right box.
| Term | What it includes | What it does not include | Zscaler mapping |
|---|---|---|---|
| Zero Trust | Least-privilege, per-app access; identity and context before connect. | A product SKU. You can do Zero Trust badly with a VPN. | Design rule for ZIA, ZPA, and the Exchange. |
| SSE | SWG + ZTNA + CASB + FWaaS, cloud-delivered. | Branch routing, underlay, circuit failover. | Zero Trust Exchange. ZIA ≈ SWG/FWaaS/CASB/DLP. ZPA ≈ ZTNA. |
| SASE | SSE + SD-WAN (Gartner: networking and security as one cloud service). | SSE by itself. Campus LAN switching. | SSE today + an SD-WAN partner, or Zscaler Zero Trust SASE (Exchange + Zero Trust SD-WAN). |
Saying “Zscaler is SASE, so we can cancel the WAN RFP.” Official Zscaler wording now splits three offers: the Exchange as SSE, Zero Trust SD-WAN as the networking half, and Zero Trust SASE as the combination. Most production tenants still pair ZIA/ZPA with an existing SD-WAN (Cisco, Aruba, Versa, Meraki). Correct the CTO: signing ZIA/ZPA buys the security slice. The underlay still needs an owner.
4. How to choose ZIA, ZPA, ZDX
One platform, three tickets. Read the destination first, then the complaint.
| Product | Destination | Replaces (typical) | If the ticket says… |
|---|---|---|---|
| ZIA — Internet Access | User → internet and SaaS | On-prem SWG / web proxy (and often the internet firewall stack) | “Block this URL,” “inspect TLS,” “stop this download,” “sanction Slack.” |
| ZPA — Private Access | User → a named private app | Remote-access VPN (AnyConnect, GlobalProtect, Pulse, F5 APM) | “VPN to staging.internal,” “open 443 to Jira,” “contractor needs RDP.” |
| ZDX — Digital Experience | Telemetry: device → Wi-Fi → ISP → Exchange → app | Hop-by-hop DEM for a Zero Trust path (not a block engine) | “Outlook is laggy,” “Teams audio is bad,” “is it us or M365?” |
ZIA in 60 seconds
Zscaler Internet Access is the cloud SWG / SSE path for web and SaaS. Client Connector, a PAC file, GRE, or IPSec forwards the session to a ZIA Public Service Edge. That edge is a proxy: it terminates the user side, runs policy (URL, SSL/TLS inspection, malware, DLP, Cloud App Control — Zscaler’s Single Scan, Multi-Action engine), then opens its own connection to the destination. The laptop does not talk to YouTube directly.
ZPA in 60 seconds
Zscaler Private Access is ZTNA. The user is not placed on the corporate network. A ZPA App Connector inside the DC or VPC egresses TCP 443 to Zscaler Service Edges and also reaches the ports of the configured apps. The Exchange stitches one user to one application segment. Help: App Connectors must be able to egress to port 443 for Service Edge connections — there is no inbound VIP to “open for ZPA.”
ZDX in 60 seconds
Zscaler Digital Experience scores the path the user actually felt: device health, local Wi-Fi, last-mile ISP, the Zscaler cloud, and the app (including UCaaS). It does not grant Jira. It tells helpdesk whether to blame the home AP or Office 365.
If X is a public URL or SaaS → ZIA. If X is a private FQDN the internet cannot resolve → ZPA. If X is “it works but it is slow” → ZDX first, then the product that owns the hop you found.
5. CA, Public Service Edge, Nanolog
Zscaler Help names three key components of the Internet & SaaS cloud: the Central Authority, Public Service Edges, and Nanolog clusters. Do not invent a fourth box.
Central Authority (CA)
The CA hosts customer policy and configuration. It monitors the cloud and is the place software and policy updates are coordinated from. When you log into the ZIA Admin Portal and save a URL Filtering rule, you are editing the CA. The CA then distributes that policy to Service Edges. It is not the node that proxies YouTube.
Public Service Edge (PSE)
A Public Service Edge for Internet & SaaS is the enforcement node the user actually reaches. Traffic is steered to a nearby PSE (Client Connector, PAC, GRE, or IPSec — later lessons). A Private Service Edge is the on-premises extension of the same architecture; it still talks to the CA, cloud routers, and Nanolog. ZPA has its own Service Edges. Same idea — different product plane. Do not draw one PSE that “does ZIA and ZPA and ZDX as one process.”
Nanolog
Nanolog clusters store transaction logs and feed reports. The Admin Portal Insights views read from Nanolog. Nanolog Streaming Service (NSS) is the family that streams those events to a SIEM (web, firewall, DNS, and other feed types). Cloud NSS is the Zscaler-hosted variant. Nanolog is compressed transaction metadata. It is not a packet capture appliance.
Administration / Company Profile / Organization
Company Profile
Source: Zscaler Help — About the Company Profile / What Is My Cloud Name for ZIA? Cloud Name is also in the admin URL (admin.zscalerthree.net → zscalerthree.net). Unified Admin may show Administration → Account Management. Lab values only.
Commercial clouds include names such as zscaler.net, zscalerone.net, zscalertwo.net, zscalerthree.net, zscloud.net, and zscalerbeta.net, plus government clouds. Your tenant lives on exactly one. PSE hostnames, tunnel VIPs, and config.zscaler.com/<cloud>/cenr lists are per cloud. Allowlisting the wrong cloud is a connectivity outage, not a “policy didn’t save” ticket.
6. Runtime path of one request
Flowchart first. Two healthy paths share the same idea: identity and policy at the Exchange, then a one-to-one connection to the destination.
Read the diamond first. Internet/SaaS stays on ZIA. A private FQDN is ZPA. ZDX watches both; it never becomes the path.
7. Runbook — diagnose a new tenant
You inherited a tenant at 09:00. Do not touch URL Filtering yet. Confirm the cloud, prove forwarding, then prove a log. Each side cites one primary Help article.
Side A — Identity the cloud (control plane)
Primary source: What Is My Cloud Name for ZIA? and About the Company Profile.
-
Read the Admin URL before any allowlist
If you sign in at
admin.zscalerthree.net, the cloud name iszscalerthree.net. Do not guess from a colleague’s PAC file. Government and beta clouds are different hosts. -
Confirm Company Profile
ZIA Admin: Administration → Company Profile (Unified Admin may say Administration → Account Management). Note Organization Name, Domains, Cloud Name, and Company ID on the Organization tab. Write the cloud name on the runbook before you open
config.zscaler.com. -
Pull that cloud’s Service Edge list only
Help: locate Public Service Edge hostnames and IPs at
https://config.zscaler.com/<Zscaler Cloud Name>/cenr. Lab example for azscalerthree.nettenant:https://config.zscaler.com/zscalerthree.net/cenr. Never paste azscaler.netJSON onto azscalerthree.netfirewall.
Side B — Prove the user is on a Public Service Edge
Primary source: Verifying a User’s Traffic is Being Forwarded to the Zscaler Service.
-
From the user’s device, open ip.zscaler.com
Zscaler Help: on the user’s device, go to
https://ip.zscaler.com. The My IP Address page reports whether traffic is going to the Zscaler service and gives the details you need for first-line triage (cloud / serving edge / forwarded or not). Browser is the intended path. Plaincurlwithout a browser User-Agent can return less useful HTML — if you automate it, send a Mozilla UA, then still confirm in a real browser. -
If it says you are not going through Zscaler, stop designing policy
Fix forwarding first (Client Connector, PAC, GRE/IPSec, Trusted Network). A URL Filtering rule cannot fire on traffic the PSE never saw.
-
Match the serving edge to the cloud you wrote down
The PSE name or egress IP should sit in that cloud’s
config.zscaler.com/<cloud>/cenrset. Wrong cloud here is the same class of failure as a wrong firewall allowlist.
Side C — Prove a transaction landed in Nanolog
Primary source: About Insights Logs / Web Insights.
-
Browse one known URL from the same device
Use a lab destination you control (example:
https://example.com). Do not hunt production DLP on day one. -
Open Web Insights
Analytics → Insights → Web (label may read Web Insights Logs). Filter the test user and the last few minutes. You want a row with the username and the URL. That row is Nanolog, not a screenshot of Activate.
-
If the SOC needs a stream, that is NSS — later
CSV export from Insights is not the production SIEM path. NSS or Cloud NSS reads Nanolog and pushes web / firewall / DNS feeds. Do not install a forwarder “inside the PSE.”
Analytics / Insights / Web
Web Insights Logs
Source: Zscaler Help — About Insights Logs. Username + URL on the row is the Side C green. CSV here is a snapshot; NSS is the SIEM pipe.
https://ip.zscaler.com https://config.zscaler.com/zscalerthree.net/cenr https://config.zscaler.com/zscaler.net/cenr
8. Traps + proof checklist
| Symptom | Wrong reflex | Right first check | Evidence that closes it |
|---|---|---|---|
| CTO: “SASE is signed, cancel the WAN vendor.” | Agree. Call ZIA/ZPA “full SASE.” | Split SSE vs SASE. Ask who owns SD-WAN / Zero Trust SD-WAN. | Architecture note: Exchange = SSE. SASE still needs the networking half. |
| Developer wants “VPN to staging.internal.” | Open inbound 443 or recreate AnyConnect. | ZPA Application Segment + Connector outbound 443 + reach to the app ports. | Connector enrolled; user hits only that segment; no inbound SG rule for Zscaler. |
| “Outlook is slow — disable Zscaler.” | Turn off Client Connector. | ZDX hop-by-hop (device / Wi-Fi / ISP / Exchange / app). | ZDX Score names the hop. ZIA Web Insights alone is not a path trace. |
| Tunnel or ZCC never comes up after a firewall change | Blame CRL or URL Filtering. | Cloud Name vs config.zscaler.com/<that cloud>/cenr allowlist. |
ip.zscaler.com says traffic is not forwarded; egress IP missing from the right cloud list. |
| SOC “has no Zscaler logs” | Install a collector in the PSE. Poll the API every minute. | Insights first (Nanolog is there). Then NSS or Cloud NSS. | SIEM shows NSS web/firewall/DNS feeds. CSV from the UI is not the pipe. |
| Security group review for a new App Connector | Allow inbound 443 from “Zscaler.” | Egress TCP 443 to Service Edges + app ports. No inbound for the Connector. | Help: Connector deployment prerequisites — outbound 443, not an inbound VIP. |
- You can say Cloud Name from the admin host and from Company Profile. They match.
https://ip.zscaler.comfrom a pilot device shows traffic going to the Zscaler service and a serving Public Service Edge on that cloud.- A Web Insights row exists for a test URL with the pilot username.
- You can point at a whiteboard and label CA (policy), PSE (enforce), Nanolog (logs) without putting the CA in the data path.
- Given one sentence (“VPN to Jira” / “block YouTube” / “Teams is choppy”) you name ZPA, ZIA, or ZDX first.
Knowledge check
Six judgment questions. Same traps as the runbook. Check answers, then reset if you miss any.
Sources
- Understanding the Zscaler Cloud Architecture for Internet & SaaS — CA, Public Service Edges, Nanolog clusters.
- Understanding Public Service Edges for Internet & SaaS — enforcement nodes; CA hosts policy/config.
- Understanding Private Service Edge for Internet & SaaS — on-prem extension; talks to CA, cloud routers, Nanolog.
- Understanding Nanolog Streaming Service (NSS) — Nanolog → SIEM.
- About Insights Logs — Insights read Nanolog; NSS streams to SIEM.
- Verifying a User’s Traffic is Being Forwarded to the Zscaler Service —
ip.zscaler.com/ My IP Address. - Locating the Hostnames and IP Addresses for Public Service Edges —
config.zscaler.com/<cloud>/cenr. - What Is My Cloud Name for ZIA? — cloud name is the admin host.
- About the Company Profile — Organization Name, Domains, Cloud Name.
- App Connector Deployment Prerequisites — egress TCP 443 to Service Edges and to configured app ports.
- What Is the Zero Trust Exchange?
- SD-WAN vs SSE vs SASE — Zscaler’s own three-offer split.
- Zscaler Internet Access — SSE / SWG for internet and SaaS; SSMA.
- Zscaler Private Access — ZTNA; user-to-app, not user-to-network.
- Zscaler Digital Experience — hop-by-hop DEM.
- NIST SP 800-207 Zero Trust Architecture — principle, not a SKU.
Related: ZIA architecture · Zscaler authentication · ZIA GRE & IPSec · ZPA architecture · ZIA traffic flow