# ZIA operator path forward, inspect, prove

Source: https://ai.techclick.in/blog_zscaler_zia_operator_complete
Markdown: https://ai.techclick.in/blog_zscaler_zia_operator_complete.md
Publisher: Techclick Infosec Pvt Ltd

Complete ZIA operator path: forwarding, identity, firewall-then-web policy, SSL inspect, ATP/DLP, Web Insights proof, 8 scenario MCQs.

## The ticket

 Priya at Apex Freight: “Outlook on the web spins. Teams is fine. ZCC is green.” That is a  ZIA  ticket, not a ZPA ticket. ZCC green only means the client is alive.

  Hero · ZIA internet path
  User → forwarding (ZCC or GRE/PAC) → ZIA Public Service Edge → policy → internet/SaaS.
  Quick answer

 ZIA is the internet and SaaS path. Traffic must hit a Public Service Edge, then firewall, then SSL, then web engines. If it never arrives, policy will not save you.

## Mental model — three parts

- Forwarding — how packets reach ZIA (GRE, IPSec, PAC, ZCC).

- Identity — who is on the wire (SAML/SCIM, location, surrogate IP).

- Policy stack — firewall first, then SSL inspect, then ATP / URL / cloud app / DLP.

  Flow 1 · ZIA packet path

   User to internet through ZIA

- User + ZCC or GRE/PAC Public SE known location? Policy stack FW → SSL → ATP URL / Cloud App DLP → allow/block Internet / SaaS Firewall module first, then web module. If firewall blocks, URL policy never runs. Source: ZIA Policy Leading Practices — Order of Operations. Hard words: Public Service Edge (PSE) is the ZIA enforcement node. Known location is a source IP you configured under Administration → Location Management. Surrogate IP maps an internal IP to a user after auth — it needs no NAT in front of the tunnel. ## How to choose forwarding Forwarding feel Zscaler recommends GRE as the site method when the router supports it. IPSec when GRE is not possible. PAC and ZCC cover users and roamers. Mix them; do not pick one for the whole company. Method Use when Trap GRE (primary + backup PSE) HQ/branch router, static public IP MTU/MSS; NAT hiding internal IPs IPSec No GRE, or SD-WAN mandate Phase-1/2 mismatch; extra subscription in some designs PAC Browser explicit proxy, known vs remote port Users disable PAC; remote users hit 9443 and always inspect ZCC (Z-Tunnel 1.0 / 2.0) Roaming and laptops Trusted Network true → traffic skips ZIA Source: Choosing Traffic Forwarding Methods and ZIA traffic-forwarding reference architecture (GRE recommended). ## Runbook — Side A / B / C ### Side A · edge (router or ZCC) #### Site Build two GRE tunnels to two ZIA PSEs. Keep internal IPs visible (no PAT in front). Clamp MSS if users report slowness after cutover.

- #### Roamer Install ZCC (Intune/GPO). Confirm enrol user, tunnel up, forwarding profile. Do not declare success on icon colour alone.

### Side B · ZIA Admin

- #### Location Administration → Location Management. Map the public IP. Enable authentication if you need user policy.

- #### SSL pilot Policy → SSL Inspection → Add SSL Inspection Rule. Decrypt only grp-ssl-pilot first. Distribute Zscaler root CA with Intune.

- #### URL / Cloud App Policy → URL Filtering and Cloud App Control. Remember: firewall can still block a URL you allowed.

     admin.zscaler.net · Policy → SSL Inspection → Add SSL Inspection Rule

     Training mock · not live

       Policy / SSL Inspection / Add SSL Inspection Rule

### Add SSL Inspection Rule

          Rule Order  2

          Rule Name  Pilot-Inspect-Users

          Locations  HQ-Pune · Bangalore-Branch

          Users / Groups  grp-ssl-pilot

        Action  Decrypt

        Cancel  Save

   Official path: Policy → SSL Inspection. Rules evaluate in ascending order. Pilot a group before org-wide Decrypt. Source: help.zscaler.com configuring SSL Inspection policy.

### Side C · prove

- #### Web Insights Analytics → Web Insights. Filter user Priya + URL outlook.office.com. Quote action, rule name, location.

- #### SSL If the browser shows a name-mismatch or unknown CA, the client does not trust the inspect CA — that is Side A, not a URL block.

## Runtime path after go-live

  Runtime feel
  SSL traffic: CONNECT/SNI first, then decrypt if the inspect rule hits. Source: Understanding Policy Enforcement.
  Inspect feel
  Pinned apps and banking categories usually stay exempt. Pilot an exemption; do not disable inspect for the org on a P1.

## Traps and proof

   Symptom  First check  Do not

  No ZIA logs, ZCC green  Trusted Network, PAC, forwarding profile  Add a block rule “to test”
  Cert warning on one app  Inspect CA on the device, exemption list  Org-wide Disable Decrypt
  URL allow, still blocked  Firewall Control / DNS Control hit  Keep editing URL only
  Whole branch slow after GRE  MTU 1400/1476, DF bit, MSS clamp  “Disable Zscaler”

  Pilot checklist

- One user in grp-ssl-pilot can open OWA. Web Insights shows the allow rule.

- One known-bad URL is blocked with EUN. Rule name matches.

- IdP (login.microsoftonline.com) is not hairpinned into a SAML loop.

  Unsafe path

 Disabling ZCC for the company to “prove it is Zscaler.” You lose the only evidence channel.

  Next: troubleshooting desk →  ·  Or start ZPA path →

## Knowledge check

   Eight field tickets. Pick the first safe move.

      Q1  Zscaler’s recommended site tunnel when the router supports it?

    Always IPSec     GRE primary + backup PSE     PAC only     Browser Isolation
 Correct:  b . Reference architecture: GRE when possible; two tunnels to two DCs.

  Q2  Web module never runs if…

    URL category is Allow     Firewall module already blocked     ZCC is green     Sandbox is off
 Correct:  b . Order of operations: firewall then web.

  Q3  Remote PAC users typically hit which PSE port for inspect?

    80     9443     443 only     500/4500
 Correct:  b . Known location often 80; remote 9443 always inspects.

  Q4  SSL inspect rule path?

    Administration → Authentication     Policy → SSL Inspection → Add SSL Inspection Rule     Analytics → Sandbox     Policy → DLP
 Correct:  b . Documented ZIA admin path.

  Q5  Priya cert warning after Decrypt. First?

    Disable Decrypt org-wide     Check Zscaler root CA on the laptop / Intune     New GRE     Delete URL filtering
 Correct:  b . Trust the inspect CA before touching policy.

  Q6  No ZIA logs, ZCC green. First suspect?

    ATP signature     Trusted Network or forwarding profile skip     App Connector group     Browser Access cert
 Correct:  b . Traffic never arrived at ZIA.

  Q7  URL allow, still blocked. Next policy to open?

    Only Cloud App     Firewall Control / DNS Control     Timeout Policy     PRA
 Correct:  b . FW can block what URL allowed.

  Q8  Whole branch slow the morning GRE went live. First?

    Disable Zscaler     MTU/MSS clamp on the GRE     Turn off ATP     New ZPA segment
 Correct:  b . Classic GRE MTU ticket.

       Check answers
       Reset

## Sources

- Choosing Traffic Forwarding Methods
- Best Practices for Traffic Forwarding
- Configuring SSL Inspection Policy
- Understanding Policy Enforcement
- ZIA Policy Leading Practices

 Related:  Path hub  ·  GRE/IPSec deep  ·  Entra SAML  ·  Troubleshooting desk

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
