# Zero Trust + Zscaler — map the Exchange first

Source: https://ai.techclick.in/blog_zscaler_b11_01_foundation
Markdown: https://ai.techclick.in/blog_zscaler_b11_01_foundation.md
Publisher: Techclick Infosec Pvt Ltd

Whiteboard Zero Trust vs SASE vs SSE, pick ZIA vs ZPA vs ZDX for a ticket, map Central Authority / Public Service Edge / Nanolog, and prove cloud + serving edge with ip.zscaler.com.

Quick answer (say this out loud)

    Zero Trust  is the rule: never trust the network, connect a user to an app after identity and context.  SSE  is the security slice (SWG + ZTNA + CASB + FWaaS).  SASE  is SSE plus the networking half (SD-WAN). The  Zero Trust Exchange  is Zscaler’s cloud platform that brokers those connections.  ZIA  is user → internet/SaaS.  ZPA  is user → private app (App Connector egresses TCP 443; no inbound VIP).  ZDX  measures the hop-by-hop experience. Policy lives on the  Central Authority . The  Public Service Edge  enforces.  Nanolog  stores transaction logs. First proof:  https://ip.zscaler.com  from the user’s device, then confirm Cloud Name on Administration → Company Profile.

## 1. Why the foundation ticket exists

 Every Zscaler interview and every messy design review opens with the same three questions: what is Zero Trust, what is the difference between ZIA and ZPA, and where does Zscaler sit in SASE. If those three answers are fuzzy, SSL inspection, App Connectors, and DLP never get a fair hearing.

 On the job the same map stops bad defaults. “Give me VPN to staging” is not a port-open request. “Outlook is slow” is not a URL-filter ticket. “We’re going SASE” is not “sign ZIA and we are done.”

   Visual · request → edge → policy → access

   The user never talks to every app directly. A Public Service Edge (or a ZPA Service Edge + App Connector) sits in the middle and applies policy first.

   Interview framing

   Do not recite NIST SP 800-207. Say:  the network is hostile. Identity and context are the perimeter. Access is per application, re-checked on the request — never once at the building door.

## 2. Mental model — three planes, three products

 Pre-train these words before any Admin click. They are official Zscaler / Gartner names, not classroom slang.

#### Zero Trust

 Principle. Least privilege. User-to-app, not user-to-network. Continuous verification of identity, device, app, and content.

#### Zero Trust Exchange

 Zscaler’s multitenant cloud platform. It brokers user-to-app, app-to-app, and machine-to-machine connections using business policy.

#### SSE

 Security Service Edge — the security slice of SASE: ZTNA, SWG, CASB, FWaaS. Zscaler positions the Exchange as this platform.

#### SASE

 Secure Access Service Edge = networking (SD-WAN) + SSE. Full SASE needs both halves. They are not synonyms.

   Flow 1 · three planes of the Zscaler cloud

       Central Authority is control plane. Public Service Edge is data plane. Nanolog is log plane.

- Do not put policy, packets, and logs in the same box Control plane Central Authority Hosts policy + config Admin Portal talks here Not in the user data path You edit a rule → CA pushes it Data plane Public Service Edge Nearest enforcement node Inspects + applies policy Proxy, then egresses User packets land here Log plane Nanolog cluster Stores transaction logs Feeds Insights reports NSS / Cloud NSS → SIEM Metadata — not full PCAP Products ride these planes — they are not extra boxes ZIA = internet/SaaS on a ZIA Public Service Edge · ZPA = private app via ZPA Service Edge + App Connector · ZDX = experience telemetry Read left → right. If a ticket asks “who blocked this URL?”, the answer is a Public Service Edge applying CA-pushed policy — not Nanolog, and not the Admin URL. Say this out loud The Central Authority stores the policy I click. The Public Service Edge is the node that actually sees the packet. Nanolog is how I prove what happened later. ## 3. Zero Trust vs SASE vs SSE These three get mashed together in vendor meetings. Separate the principle from the delivery model before you pick a SKU. Flow 2 · pick the word the RFP actually asked for Decision: Zero Trust is the principle. SSE is security. SASE is SSE plus SD-WAN. What did they actually ask for? principle · security slice · full stack Zero Trust Principle / architecture User → app, not network Identity + context NIST SP 800-207 idea SSE Security slice of SASE SWG + ZTNA + CASB + FWaaS (no SD-WAN) Zero Trust Exchange SASE SSE + networking Add SD-WAN / WAN edge One ops model for both SSE alone is not SASE Zscaler’s own split (do not flatten this) Zero Trust Exchange = SSE platform · Zero Trust SD-WAN = Zscaler’s networking half · Zero Trust SASE = those two together Diamond in words: if the RFP says “single-vendor SASE,” you must account for SD-WAN. If it says “SSE / SWG / ZTNA,” the Exchange is the right box. Term What it includes What it does not include Zscaler mapping Zero Trust Least-privilege, per-app access; identity and context before connect. A product SKU. You can do Zero Trust badly with a VPN. Design rule for ZIA, ZPA, and the Exchange. SSE SWG + ZTNA + CASB + FWaaS, cloud-delivered. Branch routing, underlay, circuit failover. Zero Trust Exchange. ZIA ≈ SWG/FWaaS/CASB/DLP. ZPA ≈ ZTNA. SASE SSE + SD-WAN (Gartner: networking and security as one cloud service). SSE by itself. Campus LAN switching. SSE today + an SD-WAN partner, or Zscaler Zero Trust SASE (Exchange + Zero Trust SD-WAN). Common mistake Saying “Zscaler is SASE, so we can cancel the WAN RFP.” Official Zscaler wording now splits three offers: the Exchange as SSE, Zero Trust SD-WAN as the networking half, and Zero Trust SASE as the combination. Most production tenants still pair ZIA/ZPA with an existing SD-WAN (Cisco, Aruba, Versa, Meraki). Correct the CTO: signing ZIA/ZPA buys the security slice. The underlay still needs an owner. ## 4. How to choose ZIA, ZPA, ZDX One platform, three tickets. Read the destination first, then the complaint. Product Destination Replaces (typical) If the ticket says… ZIA — Internet Access User → internet and SaaS On-prem SWG / web proxy (and often the internet firewall stack) “Block this URL,” “inspect TLS,” “stop this download,” “sanction Slack.” ZPA — Private Access User → a named private app Remote-access VPN (AnyConnect, GlobalProtect, Pulse, F5 APM) “VPN to staging.internal,” “open 443 to Jira,” “contractor needs RDP.” ZDX — Digital Experience Telemetry: device → Wi-Fi → ISP → Exchange → app Hop-by-hop DEM for a Zero Trust path (not a block engine) “Outlook is laggy,” “Teams audio is bad,” “is it us or M365?” ### ZIA in 60 seconds Zscaler Internet Access is the cloud SWG / SSE path for web and SaaS. Client Connector, a PAC file, GRE, or IPSec forwards the session to a ZIA Public Service Edge . That edge is a proxy: it terminates the user side, runs policy (URL, SSL/TLS inspection, malware, DLP, Cloud App Control — Zscaler’s Single Scan, Multi-Action engine), then opens its own connection to the destination. The laptop does not talk to YouTube directly. ### ZPA in 60 seconds Zscaler Private Access is ZTNA. The user is not placed on the corporate network. A ZPA App Connector inside the DC or VPC egresses TCP 443 to Zscaler Service Edges and also reaches the ports of the configured apps. The Exchange stitches one user to one application segment. Help: App Connectors must be able to egress to port 443 for Service Edge connections — there is no inbound VIP to “open for ZPA.” ### ZDX in 60 seconds Zscaler Digital Experience scores the path the user actually felt: device health, local Wi-Fi, last-mile ISP, the Zscaler cloud, and the app (including UCaaS). It does not grant Jira. It tells helpdesk whether to blame the home AP or Office 365. Choose-when If X is a public URL or SaaS → ZIA . If X is a private FQDN the internet cannot resolve → ZPA . If X is “it works but it is slow” → ZDX first, then the product that owns the hop you found. ## 5. CA, Public Service Edge, Nanolog Zscaler Help names three key components of the Internet & SaaS cloud: the Central Authority , Public Service Edges , and Nanolog clusters . Do not invent a fourth box. ### Central Authority (CA) The CA hosts customer policy and configuration. It monitors the cloud and is the place software and policy updates are coordinated from. When you log into the ZIA Admin Portal and save a URL Filtering rule, you are editing the CA. The CA then distributes that policy to Service Edges. It is not the node that proxies YouTube. ### Public Service Edge (PSE) A Public Service Edge for Internet & SaaS is the enforcement node the user actually reaches. Traffic is steered to a nearby PSE (Client Connector, PAC, GRE, or IPSec — later lessons). A Private Service Edge is the on-premises extension of the same architecture; it still talks to the CA, cloud routers, and Nanolog. ZPA has its own Service Edges. Same idea — different product plane. Do not draw one PSE that “does ZIA and ZPA and ZDX as one process.” ### Nanolog Nanolog clusters store transaction logs and feed reports. The Admin Portal Insights views read from Nanolog. Nanolog Streaming Service (NSS) is the family that streams those events to a SIEM (web, firewall, DNS, and other feed types). Cloud NSS is the Zscaler-hosted variant. Nanolog is compressed transaction metadata. It is not a packet capture appliance. admin.zscalerthree.net · Administration → Company Profile Training mock · not live Administration / Company Profile / Organization ### Company Profile Organization Name Techclick Lab Cloud Name zscalerthree.net Company ID 00000000 Domains lab.example.com Admin portal URL (read the host) https://admin.zscalerthree.net Cancel Save Source: Zscaler Help — About the Company Profile / What Is My Cloud Name for ZIA? Cloud Name is also in the admin URL ( admin.zscalerthree.net → zscalerthree.net ). Unified Admin may show Administration → Account Management. Lab values only. Cloud name is a production object Commercial clouds include names such as zscaler.net , zscalerone.net , zscalertwo.net , zscalerthree.net , zscloud.net , and zscalerbeta.net , plus government clouds. Your tenant lives on exactly one. PSE hostnames, tunnel VIPs, and config.zscaler.com/ /cenr lists are per cloud. Allowlisting the wrong cloud is a connectivity outage, not a “policy didn’t save” ticket. ## 6. Runtime path of one request Flowchart first. Two healthy paths share the same idea: identity and policy at the Exchange, then a one-to-one connection to the destination. Flow 3 · youtube.com vs jira.internal ZIA path to internet versus ZPA path to a private app User + ZCC or PAC / GRE / IPSec Internet or private? destination decides the plane ZIA path 1. Hit ZIA Public Service Edge 2. Auth + CA policy (SSMA) 3. PSE egresses to internet/SaaS 4. Transaction → Nanolog Proof: ip.zscaler.com + Web Insights ZPA path 1. Hit ZPA Service Edge 2. App Connector already egressed 443 3. Stitch user ↔ one app segment 4. No inbound DC port opened Proof: Connector status + ZPA logs ZDX overlay Does not forward Scores each hop Device / Wi-Fi / ISP Exchange / app Proof: ZDX Score + path Broken ZIA: traffic never reaches a PSE (wrong cloud allowlist, PAC miss, Client Connector down). Broken ZPA: Connector cannot egress 443 or cannot reach the app ports — not “open inbound 443 from Zscaler.” Read the diamond first. Internet/SaaS stays on ZIA. A private FQDN is ZPA. ZDX watches both; it never becomes the path. Ops · proof is a log line, not a screenshot of Activate Green in the Admin Portal is not closure. Closure is ip.zscaler.com plus an Insights or ZPA log that names the user and the action. ## 7. Runbook — diagnose a new tenant You inherited a tenant at 09:00. Do not touch URL Filtering yet. Confirm the cloud, prove forwarding, then prove a log. Each side cites one primary Help article. ### Side A — Identity the cloud (control plane) Primary source: What Is My Cloud Name for ZIA? and About the Company Profile . #### Read the Admin URL before any allowlist If you sign in at admin.zscalerthree.net , the cloud name is zscalerthree.net . Do not guess from a colleague’s PAC file. Government and beta clouds are different hosts.

- #### Confirm Company Profile ZIA Admin: Administration → Company Profile (Unified Admin may say Administration → Account Management ). Note Organization Name, Domains, Cloud Name, and Company ID on the Organization tab. Write the cloud name on the runbook before you open config.zscaler.com .

- #### Pull that cloud’s Service Edge list only Help: locate Public Service Edge hostnames and IPs at https://config.zscaler.com/ /cenr . Lab example for a zscalerthree.net tenant: https://config.zscaler.com/zscalerthree.net/cenr . Never paste a zscaler.net JSON onto a zscalerthree.net firewall.

### Side B — Prove the user is on a Public Service Edge

 Primary source:  Verifying a User’s Traffic is Being Forwarded to the Zscaler Service .

- #### From the user’s device, open ip.zscaler.com Zscaler Help: on the user’s device, go to https://ip.zscaler.com . The My IP Address page reports whether traffic is going to the Zscaler service and gives the details you need for first-line triage (cloud / serving edge / forwarded or not). Browser is the intended path. Plain curl without a browser User-Agent can return less useful HTML — if you automate it, send a Mozilla UA, then still confirm in a real browser.

- #### If it says you are not going through Zscaler, stop designing policy Fix forwarding first (Client Connector, PAC, GRE/IPSec, Trusted Network). A URL Filtering rule cannot fire on traffic the PSE never saw.

- #### Match the serving edge to the cloud you wrote down The PSE name or egress IP should sit in that cloud’s config.zscaler.com/ /cenr set. Wrong cloud here is the same class of failure as a wrong firewall allowlist.

### Side C — Prove a transaction landed in Nanolog

 Primary source:  About Insights Logs  / Web Insights.

- #### Browse one known URL from the same device Use a lab destination you control (example: https://example.com ). Do not hunt production DLP on day one.

- #### Open Web Insights Analytics → Insights → Web (label may read Web Insights Logs). Filter the test user and the last few minutes. You want a row with the username and the URL. That row is Nanolog, not a screenshot of Activate.

- #### If the SOC needs a stream, that is NSS — later CSV export from Insights is not the production SIEM path. NSS or Cloud NSS reads Nanolog and pushes web / firewall / DNS feeds. Do not install a forwarder “inside the PSE.”

     admin.zscalerthree.net · Analytics → Insights → Web

     Training mock · not live

       Analytics / Insights / Web

### Web Insights Logs

          User  priya@lab.example.com

          URL  https://example.com

          Policy Action  Allowed

          Location  Lab-Known-Office

        Export CSV  Search

    Source:  Zscaler Help — About Insights Logs. Username + URL on the row is the Side C green. CSV here is a snapshot; NSS is the SIEM pipe.

   Pilot commands — no admin login required for the first two
   https://ip.zscaler.com
https://config.zscaler.com/zscalerthree.net/cenr
https://config.zscaler.com/zscaler.net/cenr

## 8. Traps + proof checklist

       Symptom  Wrong reflex  Right first check  Evidence that closes it

         CTO: “SASE is signed, cancel the WAN vendor.”
         Agree. Call ZIA/ZPA “full SASE.”
         Split SSE vs SASE. Ask who owns SD-WAN / Zero Trust SD-WAN.
         Architecture note: Exchange = SSE. SASE still needs the networking half.

         Developer wants “VPN to staging.internal.”
         Open inbound 443 or recreate AnyConnect.
         ZPA Application Segment + Connector outbound 443 + reach to the app ports.
         Connector enrolled; user hits only that segment; no inbound SG rule for Zscaler.

         “Outlook is slow — disable Zscaler.”
         Turn off Client Connector.
         ZDX hop-by-hop (device / Wi-Fi / ISP / Exchange / app).
         ZDX Score names the hop. ZIA Web Insights alone is not a path trace.

         Tunnel or ZCC never comes up after a firewall change
         Blame CRL or URL Filtering.
         Cloud Name vs  config.zscaler.com/&lt;that cloud&gt;/cenr  allowlist.
         ip.zscaler.com says traffic is  not  forwarded; egress IP missing from the right cloud list.

         SOC “has no Zscaler logs”
         Install a collector in the PSE. Poll the API every minute.
         Insights first (Nanolog is there). Then NSS or Cloud NSS.
         SIEM shows NSS web/firewall/DNS feeds. CSV from the UI is not the pipe.

         Security group review for a new App Connector
         Allow inbound 443 from “Zscaler.”
         Egress TCP 443 to Service Edges + app ports. No inbound for the Connector.
         Help: Connector deployment prerequisites — outbound 443, not an inbound VIP.

   Pilot checklist — lesson 1 is green when

- You can say Cloud Name from the admin host and from Company Profile. They match.

- https://ip.zscaler.com from a pilot device shows traffic going to the Zscaler service and a serving Public Service Edge on that cloud.

- A Web Insights row exists for a test URL with the pilot username.

- You can point at a whiteboard and label CA (policy), PSE (enforce), Nanolog (logs) without putting the CA in the data path.

- Given one sentence (“VPN to Jira” / “block YouTube” / “Teams is choppy”) you name ZPA, ZIA, or ZDX first.

## Knowledge check

   Six judgment questions. Same traps as the runbook. Check answers, then reset if you miss any.

       Q1
       Your CTO says: “We’re going SASE — sign Zscaler and cancel the WAN RFP.” What is the accurate correction?

           Correct — ZIA plus ZPA is complete single-vendor SASE, including campus switching.
           The Zero Trust Exchange is Zscaler’s SSE (SWG / ZTNA / CASB / FWaaS). SASE still needs the networking half — an existing SD-WAN or Zscaler Zero Trust SD-WAN.
           Zscaler is only a VPN replacement, so you still need a separate SWG vendor.
           SASE and SSE are the same Gartner term; the WAN RFP is irrelevant.

       Correct:  b . Re-read  Zero Trust vs SASE vs SSE . Official Zscaler split: Exchange = SSE, Zero Trust SD-WAN = networking, Zero Trust SASE = both. ZIA/ZPA alone do not cancel underlay ownership.

       Q2
       A developer asks for “VPN access to staging.internal.acme.com.” ZPA is in scope. What do you build?

           A ZPA Application Segment for that FQDN, an App Connector that can egress TCP 443 and reach the app ports, and a ZPA policy for that user.
           An inbound security-group rule allowing TCP 443 from the internet to the staging server.
           A ZIA URL Filtering allow for the private FQDN — ZIA proxies RFC1918 apps.
           A GRE tunnel from the laptop to the nearest ZIA Public Service Edge, then open the subnet.

       Correct:  a . Re-read  How to choose  and the ZPA runtime path. ZIA is user → internet/SaaS. ZPA stitches one user to one app. Connectors egress; they do not accept inbound Zscaler connections.

       Q3
       A Mumbai user says Outlook is laggy. Helpdesk needs to know whether it is Wi-Fi, the ISP, Zscaler, or Microsoft 365. Which product answers hop-by-hop?

           ZIA Web Insights — it logs the slow URL, which is the full path.
           Nanolog — export a packet capture of the Outlook session.
           ZPA Diagnostics — Outlook is a private app.
           ZDX — device, Wi-Fi, ISP, Exchange, and app scores. It is not a block engine.

       Correct:  d . Re-read  How to choose ZIA, ZPA, ZDX . Web Insights is a transaction log. Nanolog is not PCAP. Outlook / M365 is not a ZPA private app.

       Q4
       You save a URL Filtering change in the Admin Portal. The next user request to youtube.com is blocked. Which component actually inspected that packet?

           The Public Service Edge. The Central Authority hosted the policy and pushed it; it is not in the user data path. Nanolog stored the log after the fact.
           The Central Authority — every user session is proxied through the CA.
           The Nanolog cluster — it rewrites the HTTP response.
           ip.zscaler.com — that host is the enforcement node for all clouds.

       Correct:  a . Re-read  CA, Public Service Edge, Nanolog  and Flow 1. Help’s three components: CA = policy/config, PSE = enforce, Nanolog = logs/reports.

       Q5
       You allowlist  config.zscaler.com/zscalerthree.net/cenr  on the egress firewall. The tenant’s admin URL is  admin.zscaler.net . What fails first?

           Nothing — Public Service Edge ranges are identical on every commercial cloud.
           Only Nanolog Streaming Service breaks; browsing still works.
           Outbound packets to the real cloud’s PSE / tunnel VIPs are dropped. Users see no internet or fall back to unprotected direct. The tunnel never establishes.
           The Central Authority refuses to save policy until the allowlist matches.

       Correct:  c . Re-read Side A and the cloud-name trap. Help: locate PSE hostnames/IPs at  config.zscaler.com/&lt;your cloud&gt;/cenr .  admin.zscaler.net  means the cloud is  zscaler.net .

       Q6
       You need three facts from a user’s laptop with no Admin login: which cloud, which Public Service Edge they hit, and whether traffic is forwarded to Zscaler. First move?

           Run  tracert zscaler.net  and treat the last hop as the PSE.
           Open yesterday’s SIEM dump and search for the user.
           On that device, open  https://ip.zscaler.com  (My IP Address).
           Go to Administration → Cloud Configuration (that menu is where cloud name always lives).

       Correct:  c . Re-read Side B. Official Help: verify forwarding on the user’s device at ip.zscaler.com. Traceroute is not the cloud map. “Cloud Configuration” is not the documented path — Company Profile / the admin host is. Yesterday’s SIEM is not now.

       Check answers
       Reset

## Sources

- Understanding the Zscaler Cloud Architecture for Internet & SaaS — CA, Public Service Edges, Nanolog clusters.

- Understanding Public Service Edges for Internet & SaaS — enforcement nodes; CA hosts policy/config.

- Understanding Private Service Edge for Internet & SaaS — on-prem extension; talks to CA, cloud routers, Nanolog.

- Understanding Nanolog Streaming Service (NSS) — Nanolog → SIEM.

- About Insights Logs — Insights read Nanolog; NSS streams to SIEM.

- Verifying a User’s Traffic is Being Forwarded to the Zscaler Service — ip.zscaler.com / My IP Address.

- Locating the Hostnames and IP Addresses for Public Service Edges — config.zscaler.com/ /cenr .

- What Is My Cloud Name for ZIA? — cloud name is the admin host.

- About the Company Profile — Organization Name, Domains, Cloud Name.

- App Connector Deployment Prerequisites — egress TCP 443 to Service Edges and to configured app ports.

- What Is the Zero Trust Exchange?

- SD-WAN vs SSE vs SASE — Zscaler’s own three-offer split.

- Zscaler Internet Access — SSE / SWG for internet and SaaS; SSMA.

- Zscaler Private Access — ZTNA; user-to-app, not user-to-network.

- Zscaler Digital Experience — hop-by-hop DEM.

- NIST SP 800-207 Zero Trust Architecture — principle, not a SKU.

 Related:  ZIA architecture  ·  Zscaler authentication  ·  ZIA GRE &amp; IPSec  ·  ZPA architecture  ·  ZIA traffic flow

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
