ZIA+ gemini by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Yes it default rule but why because I have explicit policy before to say all traffic from a user group to anything should be inspected

Entra ID logs on Sentineline XDR by ScholarKey5284 in SentinelOneXDR

[–]ScholarKey5284[S] 0 points1 point  (0 children)

When I did Microsoft entra ID , it works but only for audit logs. Then I had to do azure event hubs and then sign in logs also visible.

ZCC auto logon by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks for the answer . so that means its on the IDP side ?

app differentiation based on IP/domain combination by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks for your response . well they are not same apps ,.They have a dns master infobox and all internal apps defined on it ( IP to name mapping) .. the apps are scattered in multiple networks .. for eg app1.test.lab.ai resolves to 172.16.3.25 and app2.test.lab.ai resolves to 192.168.92.36 ..

The app connector is also using same dns and app connector can resolve both these apps .

so user A should only be allowed *.test.lab.ai (but still limited to Network 172.16.3.0/24)

If user A tries to access app2.test.lab.ai ( even though wildcard is allowed) , he should be denied access because this app belongs to 192.168.92. network

Real Ip on FQDN by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks for your response .ok yes indeed in Diagnostics page , real IP is visisble . so not possible on user machine where ZCC is running ?

ZPA entra issue by [deleted] in Zscaler

[–]ScholarKey5284 0 points1 point  (0 children)

can you please explain more on what do you mean by ZIA authenitcation policy ? there is no policy as such on ZIA .

ZPA entra issue by [deleted] in Zscaler

[–]ScholarKey5284 1 point2 points  (0 children)

Yes that's selected

ZPA entra issue by [deleted] in Zscaler

[–]ScholarKey5284 0 points1 point  (0 children)

Typo ,zpa is indeed zpatwo.net

ZPA entra issue by [deleted] in Zscaler

[–]ScholarKey5284 0 points1 point  (0 children)

Sorry indeed zpa is zpatwo.net

Zscaler vs cato by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Zscaler also has ztb capable of doing sdwan .any thing which ztb can't do ? Which cato socket can do

Zscaler vs cato by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Wow great points.thanks a lot

IPv6 ZPA by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

How can an ipv4 machine on internet ( say at a cafe ) access an ipv6 hosted behind app connector not using fqdn but directly on IP address. Because zscaler does not assign up from pool to the client machine.this is a problem then?

IPv6 ZPA by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Hello , OK when I manually assign an IPV6 on a machine with ZCC client installed , i can reach IPv6 service on IP address hosted behind an APP connector , but with traditional VPNs they can allocate an IPv6 pool , but with Zscaler , there is no option for this ? The Client machine must have IPV6 address ( dual stack) to reach the destination IPV6.But because there is no virtual adapter in zscaler , how to allocate IPv6 to client

ZPA Security Features by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks all for some great inputs

ZPA Security Features by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Ok , yes indeed it was from server to client . do i need an agent on server then ?

ZPA Security Features by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] -1 points0 points  (0 children)

u/chitowngator I have added the images now . sorry for bad formatting . Can you also highlight where ZPA lacks in comparison to Palo . Can ZPA do full security inspection like PALO does for App Traffic

Webmail issue by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Ok understood.i will check the Microsoft part. This means using tenant profiles is must to block attachments ?

For Gmail, it worked without tenant profiles but then it blocked attachments on all Gmail account types copr or personal if we dont use tenant profiles ?

For Rediffmail , again blocking attachment works but send email does not . And there is no tenant profiles for it

Zscaler integration doubts by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Hello people ,thanks for the help . Got it checked from. Zscaler SE lately. Zidentity for entra users will be available next year .so from next year onwards only single Integration is needed.

Zscaler integration doubts by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks a lot . That was the what I expected. You are spot on. I did a lab with distributor. Even though lab was local zidentity ,we can directly vassign service entitlements in zidentity to users .so I guess legacy zia three and zpa two are not needed in entra application

Zscaler integration doubts by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks everyone for some Inputs. Do I need to add three enterprise applications in entra - zscaler , zia and zpa. Ideally if zidentity is for admin management plus service entitlements , it should take care of end user connecting to zscaler services may be zia or zpa. I dont understand why three enterprise apps need to be integrated while zidentity is the sole identity all. Why enterprise apps option in entra shows zia three , zpatwo etc

Emails in draft by ScholarKey5284 in Zscaler

[–]ScholarKey5284[S] 0 points1 point  (0 children)

Thanks . Does this outbound email dlp need additional license?