external/anthropic-cybersecurity-skills/skills/configuring-zscaler-private-access-for-ztna/SKILL.md
Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring access policies based on user identity and device posture, and integrating with IdPs.
npx skillsauth add seikaikyo/dash-skills configuring-zscaler-private-access-for-ztnaInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Do not use for applications requiring raw UDP access (ZPA primarily supports TCP), for providing full network-level access equivalent to site-to-site VPN (use ZPA AppProtection or branch connector instead), or when the organization requires on-premises-only access control without cloud dependency.
App Connectors establish outbound-only tunnels to the ZPA cloud, providing access to internal applications.
# Download and install App Connector on Linux VM
# Obtain provisioning key from ZPA Admin Portal > Administration > App Connectors
# For RHEL/CentOS
sudo yum install -y https://yum.private.zscaler.com/yum/el7/zpa-connector-latest.rpm
# For Ubuntu/Debian
curl -sS https://dist.private.zscaler.com/apt/pubkey.gpg | sudo apt-key add -
echo "deb https://dist.private.zscaler.com/apt stable main" | sudo tee /etc/apt/sources.list.d/zpa.list
sudo apt update && sudo apt install -y zpa-connector
# Configure the connector with provisioning key
sudo /opt/zscaler/bin/zpa-connector configure \
--provision-key "PROVISIONING_KEY_FROM_PORTAL"
# Start the connector service
sudo systemctl enable zpa-connector
sudo systemctl start zpa-connector
# Verify connector status
sudo systemctl status zpa-connector
sudo /opt/zscaler/bin/zpa-connector status
# Deploy second connector for HA (minimum 2 per site)
# Repeat on second VM with same App Connector Group provisioning key
Map internal applications to server groups and create application segments.
ZPA Admin Portal Configuration:
1. Server Groups:
Navigate to: Administration > App Connectors > Server Groups
- Name: "DC-East-Servers"
- App Connector Group: "DC-East-Connectors"
- Servers:
- hr-portal.internal.corp (10.1.1.50, TCP 443)
- finance-app.internal.corp (10.1.1.51, TCP 443)
- git.internal.corp (10.1.2.10, TCP 22, 443)
2. Application Segments:
Navigate to: Resources > Application Segments > Add Application Segment
- Name: "HR Applications"
- Domain/URL: hr-portal.internal.corp
- TCP Ports: 443
- Server Group: DC-East-Servers
- Health Reporting: Continuous
- Bypass Type: Never (force all traffic through ZPA)
- Name: "Engineering Tools"
- Domain/URL: git.internal.corp, ci.internal.corp, wiki.internal.corp
- TCP Ports: 22, 80, 443
- Server Group: DC-East-Servers
- Segment Group: "Engineering Segment Group"
Define who can access which application segments based on identity and device posture.
ZPA Admin Portal > Policies > Access Policy:
Rule 1: HR Team Access
- Name: "HR Portal Access"
- Action: ALLOW
- Criteria:
- User Groups: "HR-Department" (from IdP)
- Application Segment: "HR Applications"
- Device Posture Profile: "Corporate Managed Device"
- Client Type: Zscaler Client Connector
- Conditions:
- SAML Attribute: department = "Human Resources"
- Device Trust Level: "HIGH" (CrowdStrike ZTA score > 70)
Rule 2: Engineering Access
- Name: "Engineering Tools Access"
- Action: ALLOW
- Criteria:
- User Groups: "Engineering-Team", "DevOps-Team"
- Application Segment: "Engineering Tools"
- Device Posture Profile: "Developer Workstation"
- Conditions:
- Machine Group: "Engineering Laptops"
Rule 3: Contractor Limited Access
- Name: "Contractor Wiki Access"
- Action: ALLOW
- Criteria:
- User Groups: "External-Contractors"
- Application Segment: "Wiki Only"
- Client Type: Zscaler Client Connector OR Browser Access
- Conditions:
- Time Window: Mon-Fri 08:00-18:00 EST
Rule 4: Default Deny
- Name: "Block All Other Access"
- Action: DENY
- Criteria: All Users, All Applications
- Log: Enabled
Integrate device posture signals from endpoint security tools.
ZPA Admin Portal > Administration > Device Posture:
Profile 1: Corporate Managed Device
- CrowdStrike Falcon: Running, ZTA Score >= 60
- OS: Windows 10 21H2+, macOS 13+, Ubuntu 22.04+
- Disk Encryption: Enabled (BitLocker/FileVault)
- Firewall: Enabled
- Screen Lock: Enabled
Profile 2: Developer Workstation
- Inherits: Corporate Managed Device
- CrowdStrike Falcon: ZTA Score >= 70
- Patch Level: Within 30 days of latest
- Certificate: Valid corporate certificate present
Profile 3: BYOD Device
- OS: Latest minus 1 version
- Browser: Chrome 120+ or Edge 120+
- Antivirus: Any recognized AV running
Configure Browser Access for users without Zscaler Client Connector installed.
ZPA Admin Portal > Resources > Application Segments:
For "HR Applications" segment:
- Enable Browser Access: Yes
- Browser Access Type: HTTPS
- Custom Domain: hr.access.company.com
- Certificate: Upload TLS certificate for custom domain
- Authentication: SAML via corporate IdP
- Session Timeout: 4 hours
- Clipboard Control: Disabled for sensitive apps
- File Upload/Download: Restricted
For Browser Access Portal:
- Portal URL: access.company.com
- IdP: Microsoft Entra ID (SAML 2.0)
- MFA: Required
- Applications shown: Only authorized per user group
Set up log streaming for SIEM integration and continuous monitoring.
ZPA Admin Portal > Administration > Log Streaming Service:
Log Receiver Configuration:
- Name: "Splunk-SIEM"
- Type: Splunk (HEC)
- Destination: https://splunk-hec.company.com:8088
- HEC Token: "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
- Log Types:
- User Activity: Enabled
- App Connector Status: Enabled
- Audit Logs: Enabled
- Browser Access: Enabled
# Splunk search for ZPA access anomalies
index=zscaler_zpa sourcetype=zpa:useractivity
| where action="denied"
| stats count by user, application, policy_name
| where count > 10
| sort -count
| Term | Definition | |------|------------| | App Connector | Lightweight Linux service that creates outbound-only encrypted tunnels from internal networks to ZPA cloud, providing access to applications without inbound ports | | Application Segment | Logical grouping of internal applications defined by FQDN/IP and ports, mapped to server groups for access policy enforcement | | Server Group | Collection of application servers associated with App Connector groups that can serve requests for application segments | | Access Policy | Rules defining which users/groups can access which application segments under what conditions (device posture, time, location) | | Zscaler Client Connector | Endpoint agent installed on user devices that routes traffic to ZPA cloud for policy enforcement and application access | | Browser Access | Clientless ZTNA option allowing application access through a web browser without requiring Zscaler Client Connector installation |
Context: A financial services firm with 500 employees uses Cisco AnyConnect for remote access. VPN split-tunnel configuration creates security gaps, and full-tunnel mode causes performance issues. The firm needs application-level access control for SOX compliance.
Approach:
Pitfalls: App Connector DNS must resolve all internal FQDNs used in application segments. Wildcard domain segments can cause performance issues if too broad. Browser Access does not support all web application frameworks (WebSocket-heavy apps may require Client Connector). CrowdStrike ZTA integration requires Falcon sensor deployment on all endpoints before enforcing posture policies.
ZPA ZTNA Deployment Report
==================================================
Organization: FinanceCorp
Deployment Date: 2026-02-23
INFRASTRUCTURE:
App Connectors: 4 (2x DC-East, 2x DC-West)
Connector Status: All healthy
Connector Version: 24.1.2
APPLICATION COVERAGE:
Application Segments: 20
Total Applications: 45
Server Groups: 4
Segment Groups: 6
ACCESS POLICIES:
Total Rules: 12
Allow Rules: 11
Deny Rules: 1 (default deny)
Device Posture Profiles: 3
USER ACCESS (last 30 days):
Active Users: 487 / 500
Total Sessions: 124,567
Allowed Sessions: 123,890 (99.5%)
Denied Sessions: 677 (0.5%)
Browser Access Sessions: 2,341
VPN MIGRATION:
Users migrated to ZPA: 487 / 500
VPN decommission date: 2026-03-15
development
拋棄式 HTML mockup 比稿:產出 2 到 3 個設計立場不同的變體(密度 / 版式 / 強調軸,不是換色),各附取捨說明,最後給有立場的對比結論。適用:「畫個草圖」「比較 A 版 B 版」「先看方向再做」「給我看幾種做法」。要 production 元件或設計已定案時不適用。
tools
需求不明時的意圖萃取訪談:一次一題、每題附上自己的猜測、聽出「真正想要 vs 覺得應該要」,直到能預測使用者反應(約 95% 信心)才動工。適用:需求缺少對象 / 動機 / 成功標準 / 約束,或使用者點名「訪談我」「先確認一下」「我們確定嗎」。明確自足的指示、純資訊查詢、機械性操作不適用。
development
對非平凡決策啟動新鮮 context 對抗審查(找碴不背書),在修正還便宜的時候抓出錯誤方向。適用:高風險改動(production、資安敏感邏輯、不可逆操作)、不熟的程式碼、要宣稱「這樣是安全的 / 可行的」之前。機械性操作與一行修改不適用。
testing
Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Consult when authoring, reviewing, or pruning a SKILL.md.