Navigation Area

Secure internet access, from design to operations

Notes on secure internet access, policy design, forwarding models, inspection, DNS, cloud firewall, traffic steering and practical ZIA implementation patterns.

ZIA Cloud Firewall • Policy and DPI

14 September 2026

Ten Rules Is Not a Rulebase: What Advanced Cloud Firewall Actually Buys

What a firewall management plane already solves and what it cannot, where web and non-web traffic actually land, the ten-rule ceiling and the criteria the licence decides, the rule that follows the person instead of the site, what Microsoft 365 One Click writes across four policies and what it exempts in return, and why a network application rule forwards before it decides.

Read article →

ZIA DNS Control • Part Two

31 August 2026

DNS Control Rules: The Policy That Runs First

When the rule belongs on the DNS plane and when it belongs on the web one, and why a DNS block removes every layer underneath it rather than adding one. NAT Control against DNS Control, the build order that keeps troubleshooting honest, rule criteria and actions, the predefined rules already enforcing in your tenant, what blocking DNS tunnels really means, encrypted DNS, and what the blocked user actually sees.

Read article →

ZIA DNS Control • Part One

28 August 2026

The Last Any Rule: Bringing DNS Under Inspection

Port 53 has been open to any destination since before the security programme existed. The business case for closing it, why the AI push makes deferring it easier, recursive against iterative queries, the root hints fallback that turns a forwarder outage into a Zscaler ticket, two roads to the trusted resolver, the tunnel-less guest pattern, and what each forwarding model leaves you able to write policy on.

Read article →

ZIA Authentication • Part One

23 August 2026

The Location Is Not a User: How ZIA Decides Who Sent the Traffic

Why the User field sometimes holds the name of an office instead of a person. Three carriers of identity and how each one fails, what a cookie actually does for a proxy standing in the middle, the five documented conditions read as consequences of one cause, and a measurement across 250,000 unfiltered transactions.

Read article →

ZIA Authentication • Part Two

23 August 2026

Special Users Are Not Users: Governing Traffic ZIA Cannot Attribute

The vocabulary for traffic nobody can name: seven classes rather than seven accounts, the constraint that removes the feature exactly where it is most needed, what Location Type really decides, sublocations and the rule migration nobody plans for, surrogate IP, port 9480, and a triage matrix.

Read article →

ZIA Policy • Enforcement Order

18 August 2026

You Are Not Buying Nine Products. You Are Configuring One Decision.

A protocol primer, then the order policy is actually applied in: two modules and three paths, three different sequences for GET, POST and the response, why the first block stops everything below it, what can be evaluated when only the domain is available, and how to read the logs when a ticket arrives.

Read article →

ZIA • Privacy • Governance

12 August 2026

Somebody Is Going to Ask What You Can See

The privacy conversation an architect cannot delegate: what the logs are really for, why the retention obligation everyone quotes does not apply, what art. 4 of the Statuto dei Lavoratori actually requires, where the logs live when the platform fails, and why the DPO is a source of requirements rather than a blocker.

Read article →

ZIA • TLS Inspection • Governance

11 August 2026

The Padlock Is Not a Promise: TLS Inspection and the Controls That Depend On It

Why encrypted traffic is a blind spot, how inspection works without removing encryption, and how to run the programme around it: policy order, a triage matrix for failures, exception governance with owners and expiry dates, mobile and BYOD boundaries, and what to measure.

Read article →

ZCC • Z-Tunnel 2.0 • Traffic Steering

11 August 2026

Z-Tunnel 2.0: Sending Everything to Zscaler Is the Easy Part

Turning it on takes a minute; deciding what should not go through it is the project. Forwarding profiles and app profiles, the bootstrap dependency nobody plans for, bypass processing priority, DNS exclusions and private endpoints, Teams and Zoom, plus the prerequisites that fail silently.

Read article →