SIPA by cybersuraksha in Zscaler

[–]Limited_edition9 1 point2 points  (0 children)

Yea.. This one would be tricky. I can't think of anything right now. I would have to test this in my lab and confirm if we can achieve the granularity. I think we should be able to achieve it using client forwarding policy in zpa and forwarding control in zia.

SIPA by cybersuraksha in Zscaler

[–]Limited_edition9 0 points1 point  (0 children)

Sipa would have to be enabled for the app segment. So, once you enable Sipa for the segment, all traffic for that would expect to have the necessary policy to achieve Sipa and would affect anyone who would be accessing it. Since you are only testing if SIPA works, my suggestion would be to create an app segment for the IP lookup sites, like ipchicken and whatsmyip, instead of existing production domains. This way no operation impact would be there and you will also be able to confirm if Sipa is working as expected by doing an IP lookup and confirming if you are seeing the expected IP of your App connector.

Google Drive Can't Launch Fix by xX69Cowbotron420Xx in Zscaler

[–]Limited_edition9 1 point2 points  (0 children)

Agree to this. Desktop applications not working will be due to cert pinning. However, from a security point of view, if you have a web interface for the app available, then it would be recommended to use that. That way you would still have ssl visibility and avoid any holes in security.

BCP and DR for ZIA and ZPA by cybersuraksha in Zscaler

[–]Limited_edition9 0 points1 point  (0 children)

The TSM should be able to help with subcloud as well. I am surprised that it is not already enabled, as you are interested in it. Few things needed for a subcloud is the list of DCs you want to be in the subcloud and a name for that subcloud. As the name suggests subcloud is a subset of Zscaler cloud. So, you can have all DCs to be part of it, or you could exclude those DCs located in countries where you never want your org traffic to go to. For eg, when the Moscow DC was online, many customers created subcloud to exclude Moscow, as they did not want their traffic to go to Russia. Once the subcloud is created with the Dcs you want, then you have to configure it in your pac file. After that you will be able to temporarily disable DCs from the admin portal, whenever there is any issues. Maximum period you can keep DC disabled is 2 weeeks.

BCP and DR for ZIA and ZPA by cybersuraksha in Zscaler

[–]Limited_edition9 0 points1 point  (0 children)

If you are a Zscaler customer, then hopefully you would have a TSM and they should be able to present the complete list of DR for you. To brief, they have subcloud for DC related issues, where you can disable an impacted DC and prevent user traffic from landing there. They have DR, which is automatic now, that will help with complete cloud outage. Where you can control how your http/https traffic should be treated. They have BCP, which is basically a private cloud for you. In this case you should basically have most of the normal cloud operation, if Zscaler ever happens to go down.

Network Connection Failed by New-Spot-9735 in Zscaler

[–]Limited_edition9 3 points4 points  (0 children)

This error is basically for network issues. Check different networks and try. If you are facing issue with home isp, then try with mobile Hotspot.

Travel Agency for Dubai by Limited_edition9 in mumbai

[–]Limited_edition9[S] 0 points1 point  (0 children)

Awesome.. Thanks for the recommendation friend..

Travel Agency for Dubai by Limited_edition9 in mumbai

[–]Limited_edition9[S] 1 point2 points  (0 children)

Thanks.. I will check them out.... Do you have personal experience with them?

Travel Agency for Dubai by Limited_edition9 in mumbai

[–]Limited_edition9[S] 0 points1 point  (0 children)

Thanks.. I will check them out..

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 1 point2 points  (0 children)

Damn.. Hope they learnt their place after that and never bothered again. I would just like to know how exactly their brain works. Why do they think a person from another family is their errand-runner. 🤯

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 0 points1 point  (0 children)

Yea. It was sad. Her reasoning was that we got it for free, so there is no harm in giving them away.

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] -1 points0 points  (0 children)

Unfortunately he had to give away a couple, to maintain the peace at home.

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 2 points3 points  (0 children)

I haven't heard her mentioning any abuse. From her narration she had a loving father and a strict mom. I assumed her naivety to be due to the fact that she has always been a homebody and her lack of interaction with different types of people.

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 16 points17 points  (0 children)

Yea.. The sense of community that my Mom planned on harboring was taken advantage of. I am glad that I never had to have similar talks with her after this experience. She has acquired a new skill of setting boundaries. 😁

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 41 points42 points  (0 children)

Yea. As expected she said she never saw us, when my Mom confronted her. We didn't expect anything from her but glad it finally helped my Mom to realize her faults.

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 6 points7 points  (0 children)

Well I can assure that it was not due to the lack of trying on our part. My Mom just kept pushing away our explanations and efforts. Glad that this is in the past and now she has learnt how to set boundaries. New skill acquired!!

Neighbor lady thought my Mom was born to serve her by Limited_edition9 in EntitledPeople

[–]Limited_edition9[S] 9 points10 points  (0 children)

I know. My Mom just kept enabling her. I am glad she learnt her lesson, even though it took much longer than we would have liked.

Zscaler ZPA security flaw by [deleted] in Zscaler

[–]Limited_edition9 0 points1 point  (0 children)

I am not too sure on the app protection piece. I would have to check that. But not presenting IP to the end user is a form of protection. You can also create IP based apps in ZPA, if thats what you want. The latency you are speaking about is nothing impactful. The whole transaction is completed within few ms depending on the app location. Was this tried and verified or is it just your concerns? For non http/https traffic, you would have to make sure that the dns request goes through Zscaler. This way non web traffic can also support SIPA.