---
title: "Configure a Zscaler cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/1611245/Configure%20a%20Zscaler%20cloud%20connector"
format: markdown
---
Zscaler is a global cloud-based information security company that provides Internet security. Zscaler infrastructure comprises three key components: ZIA Public Service Edges (formerly Zscaler Enforcement Nodes or ZENs) Central Authority (CA) Nanolog Servers Zscaler customers forward all of their web traffic to the nearest Public Service Edge, where security, management, and compliance policies served by the Central Authority are enforced.  This topic describes Zscaler-specific configuration settings for connecting your Aryaka ANAP device to the Zscaler cloud security platform. The ANAP can connect using a GRE or IPSec VTI-based tunnel, which can either be IKEv1 or IKEv2. The first section of this document outlines the necessary steps on Zscaler portal and the second section outlines the steps to be performed on Aryaka’s SmartServices platform. This information is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors  topic. This integration is supported for all three Aryaka ANAP topologies: Simple routed mode Inline routed mode Edge routed mode The following tables describe the configuration settings required for each of these modes. Simple routed mode Field Description Tunnel Destination Public IP of the Zscaler cloud on which the tunnel terminates. ICMP Keep Alive Settings Ping Source CIDR Internal Router IP and mask in CIDR format that is assigned by Zscaler. Ping Destination IP Internal ZEN IP that is assigned by Zscaler. Enable IP SLA  (if enabled) HTTP Get URL (Optional) When enabled, performs an HTTP GET to the Zscaler instance. Typically the URL uses the following syntax: gateway. <zscaler_cloud> .net/vpntest. Visit  https://help.zscaler.com/zia/what-mycloud-name  to obtain the actual  <zscaler_cloud>  name. Optionally, you can enable a secondary tunnel. The configuration is similar to that of the primary tunnel. Inline and edge routed modes Field Description Tunnel Destination Public IP of the Zscaler cloud on which the tunnel terminates. Tunnel Source Interface The interface that is used for the tunnel. Use Interface IP for Tunnel Source  (edge routed mode only) If you select Yes, the tunnel source is the selected interface IP. If you select No, you must provide an IP from the same ISP that is associated with the interface selected in the Tunnel Source Interface field. ICMP Keep Alive Settings Ping Source CIDR Internal router IP and mask in CIDR format that is assigned by Zscaler. Ping Destination IP Internal ZEN IP that is assigned by Zscaler. Enable IP SLA  (if enabled) HTTP Get URL (Optional) When enabled, performs an HTTP GET to the Zscaler instance. Typically the URL is:  gateway. <zscaler_cloud> .net/vpntest. Visit  https://help.zscaler.com/zia/what-mycloud-name  to obtain the actual  <zscaler_cloud>  name. Traffic Forwarding Select Traffic that you want to forward to Zscaler All internet traffic—Creates a default route in the  Route controller  that routes all Internet traffic through the cloud connector tunnel. Specific traffic—You must manually create routes using the  Route controller  to route specific traffic through the tunnel. If the ANAP supports segmentation, you must match the traffic by selecting the existing match rules on this page. If not, create a new one and reference it here. Drop Traffic to private subnet Allows or blocks private destination IPs that are routed over the tunnel. Operation on both tunnel failure Determines the behavior of the ANAP If both tunnels are down. Prerequisites Aryaka SmartServices service subscription. Zscaler Security as a Service platform subscription. You must also contact Zscaler support to have them provision GRE or VTI-based tunnels (whichever you prefer) and create a gateway location as described in the next section. You must provide your Zscaler account representative or their customer support with the public IP address of your Aryaka ANAP and the physical location of your branch office where the ANAP resides. You must have the Zscaler-assigned virtual IP addresses (VIPs) for the source and destination addresses inside the tunnel. You need this information to configure Zscaler in the MyAryaka portal as described in the MyAryaka Configuration section. Zscaler configuration This procedure must be performed with the help of Zscaler Technical Support—only Zscaler Support can provision these tunnels. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. To configure a tunnel and location in Zscaler Ensure your Zscaler account representative or their customer support have created GRE or VTI tunnels  with a static IP address  for your account.  Log in to the Zscaler Service Portal at  https://admin.zscloud.net/ , add your gateway location as shown, and then click  Save . The Location is added: Click  Activate  to enable the new tunnels and Location on the Zscaler network as shown in the following graphic: MyAryaka configuration Aryaka allows you to connect to a cloud security service using a cloud connector. Connector configuration can be done using MyAryaka service portal at  https://my.aryaka.com/  or with the help of Aryaka’s technical support team. When configuring the connector in MyAryaka, you can also configure traffic forwarding. If and how traffic forwarding is performed depends on the routing mode of your ANAP device: If your ANAP is in simple routed mode, all traffic that is not destined for the Aryaka POP is routed to the Zscaler tunnel. If you want to forward only select traffic, you must create some form of policy-based routing in your upstream firewall or router. If your ANAP is in edge routed mode or inline routed mode, you can control what traffic gets forwarded to Zscaler by performing the following procedure. To configure the Zscaler connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right), then click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations (Add) tab page appears. Configure the tunnel in the Tunnel Details pane as follows: Click the  Tunnel Source Interface  drop-down list and select the tunnel source interface that matches your ANAP's deployment mode: Select  LAN  if this site's ANAP is deployed in simple routed mode. Select  M1  or  M2  (or  F1  or  F2  if the ANAP uses a fiber connection) if this site's ANAP is deployed in edge routed mode or inline routed mode. Click the  Tunnel Source Type  drop-down list and select one of the following tunnel types: Use Interface IP—Select this option if you want to source the tunnel from the IP on the interface you chose in the previous step (that is, M1, M2, F1, or F2). Use Interface Aux IP—Select this option if you want to choose a different IP address that belongs to the ISP terminating on the interface. When selected, you must specify the source IP address in the Tunnel Source IP Address field that appears. Enter the primary public destination IP that was assigned by the Zscaler team in the Tunnel Destination IP field. Configure the ICMP source and destination in the ICMP Keepalive pane as follows: In the Ping Source Address field, enter the internal router IP in CIDR format that was assigned by Zscaler. In the Ping Source Mask field, enter the internal router mask in CIDR format that was assigned by Zscaler. In the Ping Destination Address field, enter the Internal ZIA IP that was assigned by Zscaler. By default, Aryaka uses ICMP probing to decide the health of the tunnel. (Optional) If you are using a GRE tunnel type, click the  HTTP IP SLA  toggle to configure an HTTP-based service level keepalive mechanism for this connector. This monitor sends probes to Zscaler that traverse its full application stack and can be used in addition to the GRE keepalive and the ping mechanism if they are enabled). In the HTTP Get URL field, enter gateway. <zscaler_cloud> .net/vpntest. This is the URL where the connector performs the HTTP query to Zscaler. To obtain the  <zscaler_cloud>  name, go to:  https://help.zscaler.com/zia/what-my-cloud-name . In the Proxy IP field, enter the IP address where HTTP-based keepalives are started on the corresponding tunnels. In the Proxy Source IP field, enter the source IP from which to connect to HTTP. In the Proxy Port field, enter the source's port number to connect to HTTP. Click  OK . The tunnel configuration is saved, and you are returned to the Tunnel Configurations (Add) tab page. Do one of the following: Click the  Save  icon to save your settings, then configure traffic forwarding as described in the next section. Click the  Submit  icon to create a change request and send it to Aryaka support for processing. To configure traffic forwarding in MyAryaka Open the Cloud Security Connector (Add) page. It includes a Forward Traffic toggle that is disabled by default: After adding the required tunnels (as described in the previous section), click the  Forward Traffic  toggle to configure traffic match criteria that, when matched, forwards traffic to the Zscaler connector. The following fields appear:  Forward Using—Drop-down list that includes the following options: Internet Policies—Select this if you want the ANAP to route the traffic to Zscaler that reaches the public interfaces  after  all other routing decisions have been made on the traffic. Local Policies—Select this if you want the ANAP to override all other routing decisions that could possibly make on that traffic. For example, traffic may be heading to ASN but you want to override that decision and send it to Zscaler. If Forward Fails—Drop-down list that includes the following options: Blackhole—Select this if you want the ANAP to silently discard the traffic and send no response back to the sender. Prohibit—Select this if you want to send a code 13 ICMP administratively prohibited message back to the sender. Policy Name table with Add New button—Click  Add New  to define a local or internet policy (depending on your selection in the Forward Using field), then provide the following details in the Policy (Add) page that appears: Name—Enter a descriptive policy name. Zone—Select the zone where the traffic originates. Match Rules—Set the toggle to  Explicit , click  Choose  in the Match Rules Details table that appears, and then select a preconfigured mach rule from the  Name  drop-down list that matches the traffic you want to forward to Zscaler. Restrictive Mode—(Optional) Click  Advanced  (top right) and select  Yes  from the Restrictive Mode drop-down list to allow traffic to flow to a private subnet. By default, this traffic is dropped. Click the  Submit  icon to create a change request and send it to Aryaka support for processing. MyAryaka Visibility You can log in to the MyAryaka portal to get complete visibility for all your traffic routed to Zscaler. You can monitor traffic and health of all of your sites connected to Zscaler by the ANAP. The status of tunnels can be determined using the Status page. Availability of the Zscaler tunnels (that is, whether they are up or down) is determined using ICMP probing. To determine Zscaler status Click  SD-WAN  >  Status  in the left navigation pane, then click the site name where you created a Zscaler connector. The site's details page appears with the Edge tab page displayed by default. Click  ANAP . The ANAP details tab page appears. It contains the Services pane, which includes a Cloud Security Connector property for each connector configured at the selected site: Do one of the following: If the Value column displays OK, no action is required. If the Value column displays Error, click the plus  +  icon in the row. The tunnels for that connector appear and they each display their status (Up or Down). Click the plus  +  icon for a tunnel to display the corresponding IP addresses for the tunnel (one for each end: Aryaka and Zscaler). Alternatively, you can visit  http://ip.zscaler.com  to verify that traffic is coming through Zscaler. In this topic Related topics Configure cloud connectors Route controller