Navigation Area
Secure internet access, from design to operations
Notes on secure internet access, policy design, forwarding models, inspection, DNS, cloud firewall, traffic steering and practical ZIA implementation patterns.
ZIA Cloud Firewall • Policy and DPI
14 September 2026
Ten Rules Is Not a Rulebase: What Advanced Cloud Firewall Actually Buys
What a firewall management plane already solves and what it cannot, where web and non-web traffic actually land, the ten-rule ceiling and the criteria the licence decides, the rule that follows the person instead of the site, what Microsoft 365 One Click writes across four policies and what it exempts in return, and why a network application rule forwards before it decides.
Read article →ZIA DNS Control • Part Two
31 August 2026
DNS Control Rules: The Policy That Runs First
When the rule belongs on the DNS plane and when it belongs on the web one, and why a DNS block removes every layer underneath it rather than adding one. NAT Control against DNS Control, the build order that keeps troubleshooting honest, rule criteria and actions, the predefined rules already enforcing in your tenant, what blocking DNS tunnels really means, encrypted DNS, and what the blocked user actually sees.
Read article →ZIA DNS Control • Part One
28 August 2026
The Last Any Rule: Bringing DNS Under Inspection
Port 53 has been open to any destination since before the security programme existed. The business case for closing it, why the AI push makes deferring it easier, recursive against iterative queries, the root hints fallback that turns a forwarder outage into a Zscaler ticket, two roads to the trusted resolver, the tunnel-less guest pattern, and what each forwarding model leaves you able to write policy on.
Read article →ZIA Authentication • Part One
23 August 2026
The Location Is Not a User: How ZIA Decides Who Sent the Traffic
Why the User field sometimes holds the name of an office instead of a person. Three carriers of identity and how each one fails, what a cookie actually does for a proxy standing in the middle, the five documented conditions read as consequences of one cause, and a measurement across 250,000 unfiltered transactions.
Read article →ZIA Authentication • Part Two
23 August 2026
Special Users Are Not Users: Governing Traffic ZIA Cannot Attribute
The vocabulary for traffic nobody can name: seven classes rather than seven accounts, the constraint that removes the feature exactly where it is most needed, what Location Type really decides, sublocations and the rule migration nobody plans for, surrogate IP, port 9480, and a triage matrix.
Read article →ZIA Policy • Enforcement Order
18 August 2026
You Are Not Buying Nine Products. You Are Configuring One Decision.
A protocol primer, then the order policy is actually applied in: two modules and three paths, three different sequences for GET, POST and the response, why the first block stops everything below it, what can be evaluated when only the domain is available, and how to read the logs when a ticket arrives.
Read article →ZIA • Privacy • Governance
12 August 2026
Somebody Is Going to Ask What You Can See
The privacy conversation an architect cannot delegate: what the logs are really for, why the retention obligation everyone quotes does not apply, what art. 4 of the Statuto dei Lavoratori actually requires, where the logs live when the platform fails, and why the DPO is a source of requirements rather than a blocker.
Read article →ZIA • TLS Inspection • Governance
11 August 2026
The Padlock Is Not a Promise: TLS Inspection and the Controls That Depend On It
Why encrypted traffic is a blind spot, how inspection works without removing encryption, and how to run the programme around it: policy order, a triage matrix for failures, exception governance with owners and expiry dates, mobile and BYOD boundaries, and what to measure.
Read article →ZCC • Z-Tunnel 2.0 • Traffic Steering
11 August 2026
Z-Tunnel 2.0: Sending Everything to Zscaler Is the Easy Part
Turning it on takes a minute; deciding what should not go through it is the project. Forwarding profiles and app profiles, the bootstrap dependency nobody plans for, bypass processing priority, DNS exclusions and private endpoints, Teams and Zoom, plus the prerequisites that fail silently.
Read article →