ZIA Setup: Locations, GRE/IPsec Tunnels
Zscaler Internet Access (ZIA) Zscaler portal — demo tenant (GUI)
مقصدObjectiveObjective
اس سبق کے بعد آپ لوکیشنز بنانا اور GRE یا IPsec ٹنل اپ کرنا جان سکیں گے تاکہ برانچ کا انٹرنیٹ ٹریفک Zscaler کلاؤڈ پر جائے۔Is lesson ke baad aap Locations banana aur GRE ya IPsec tunnel up karna jaan sakenge taake branch ka internet traffic Zscaler cloud par jaye.After this lesson you will know how to define Locations and bring up GRE or IPsec tunnels so a branch's internet traffic goes to the Zscaler cloud.
آسان مثالSimple AnalogySimple Analogy
لوکیشن کو اپنے برانچ آفس کا شناختی کارڈ سمجھیں۔ GRE/IPsec ٹنل وہ بند مہر پرائیویٹ راستے ہیں جو اس کا ٹریفک Zscaler کلاؤڈ تک لے جاتے ہیں۔Location ko apne branch office ka shanakhti card samjhein. GRE/IPsec tunnel wo band muhr private rastay hain jo is ka traffic Zscaler cloud tak le jate hain.Think of a Location as your branch office's identity card. GRE/IPsec tunnels are the sealed, private roads that carry its traffic to the Zscaler cloud.
سیٹ اپLab SetupLab Setup
Zscaler ڈیمو ٹیننٹ پورٹل۔ لوکیشن اور ٹنل بنانے کے لیے ایڈمن رسائی چاہیے (Administration > Location Management)۔Zscaler demo tenant portal. Location aur tunnel banane ke liye admin access chahiye (Administration > Location Management).Zscaler demo tenant portal. You need admin access (Administration > Location Management) to create a location and tunnels.
اقداماتStepsSteps
Step 1
لوکیشن ٹریفک کا ماخذ متعین کرتی ہے — مثلاً ایک برانچ آفس۔ یہ IP ایڈریس یا VPN گیٹ وے سے ٹریفک پہچانتی ہے، اور اسی پر پالیسیاں لگتی ہیں۔Location traffic ka source define karti hai — masalan ek branch office. Yeh IP address ya VPN gateway se traffic pehchanti hai, aur isi par policies lagti hain.A Location defines a source of traffic — e.g. a branch office. It identifies traffic by IP address or VPN gateway, and policies are applied to it.
🖱️ Administration > Location Management > Add Location پر جا کر Add LocationAdministration > Location Management > Add Location par ja kar Add LocationAdministration > Location Management > Add Location
Step 2
ایک لوکیشن بنائیں: نام دیں (مثلاً Branch-Office-LHR)، ملک اور ٹائم زون چنیں، اور دفتر کا پبلک اسٹیٹک IP شامل کریں۔ ZIA اسی IP سے اس کا ٹریفک پہچانتا ہے۔Ek location banayein: naam dein (masalan Branch-Office-LHR), country aur timezone chunein, aur office ka public static IP add karein. ZIA isi IP se is ka traffic pehchanta hai.Create a location: give it a name (e.g. Branch-Office-LHR), pick the country and timezone, and add the office's public static IP(s). ZIA uses this IP to identify its traffic.
🖱️ لوکیشن شامل کرتے وقت نام، ملک/ٹائم زون اور اسٹیٹک IP لکھیںLocation add karte waqt name, country/timezone aur static IP(s) likheinAdd Location: name it, select country/timezone, add static IP(s)
Step 3
ٹنل کے لیے ایک VPN کریڈینشل (صارف نام/پاس ورڈ یا پری شیئرڈ کی) بنائیں۔ یہ کریڈینشل آپ کے فائر وال/روٹر سے Zscaler تک ٹنل کی تصدیق کرتی ہے۔Tunnel ke liye ek VPN credential (username/password ya pre-shared key) banayein. Yeh credential aap ke firewall/router se Zscaler tak tunnel ko authenticate karti hai.Create a VPN credential (username/password or pre-shared key) for the tunnel. This credential authenticates the tunnel from your firewall/router to Zscaler.
🖱️ VPN Credentials میں Add VPN Credential پر جا کر کریڈینشل بنائیںVPN Credentials mein Add VPN Credential par ja kar credential banayeinAdministration > Location Management > VPN Credentials > Add VPN Credential
Step 4
لوکیشن کے اندر ایک GRE ٹنل شامل کریں۔ GRE لوکیشن سے ٹریفک Zscaler کی طرف بھیجتا ہے؛ روٹر/فائر وال کی طرف Zscaler کے دیے گئے IPs پر میچنگ ٹنل بنائیں۔Location ke andar ek GRE tunnel add karein. GRE location se traffic Zscaler ki taraf bhejta hai; router/firewall ki taraf Zscaler ke diye gaye IPs par matching tunnel banayein.Add a GRE tunnel inside the location. GRE forwards traffic from the location to Zscaler; on the router/firewall side, create a matching tunnel with Zscaler's IPs.
🖱️ Add Location کے اندر VPN Tunnel (GRE) ٹیب میں Zscaler جو ٹنل IPs دکھائے وہ نوٹ کریںAdd Location ke andar VPN Tunnel (GRE) tab mein Zscaler jo tunnel IPs dikhaye woh note kareinAdd Location > VPN Tunnel (GRE) — Zscaler shows source/dest IPs and tunnel IPs
Step 5
لچک کے لیے دوسرا (بیک اپ) ٹنل کسی الگ Zscaler ڈیٹا سینٹر سے بنائیں۔ اگر پرائمری ڈاؤن ہو تو ٹریفک خودکار طور پر فیل اوور ہو جاتا ہے۔Resilience ke liye dosra (backup) tunnel kisi alag Zscaler data center se banayein. Agar primary down ho to traffic automatically failover ho jata hai.For resilience, add a second (backup) tunnel to a different Zscaler data center. If the primary fails, traffic fails over automatically.
🖱️ ریڈنڈنسی کے لیے دوسرا ٹنل بنائیںRedundancy ke liye second tunnel banayeinAdministration > Location Management > Backup tunnel + enable for failover
Step 6
محفوظ کر کے Location Management میں ٹنل اسٹیٹس چیک کریں۔ صحت مند ٹنل Up نظر آتا ہے۔ اب اس لوکیشن کا ٹریفک آپ کی پالیسیوں کے مطابق Zscaler سے گزر کر نکلتا ہے۔Save karke Location Management mein tunnel status check karein. Sehatmand tunnel Up nazar aata hai. Ab is location ka traffic aap ki policies ke mutabiq Zscaler se guzar kar nikalta hai.Save and check tunnel status in Location Management. A healthy tunnel shows Up. The location's traffic now exits through Zscaler per your policies.
🖱️ Location Management میں ٹنل اسٹیٹس چیک کریںLocation Management mein tunnel status check kareinAdministration > Location Management — Tunnel status column
تصدیقVerifyVerify
Location Management میں لوکیشن ٹنل اسٹیٹس Up کے ساتھ نظر آتی ہے، اور ٹیسٹ صارف کا ویب ٹریفک Analytics > Web Insights میں دکھتا ہے۔Location Management mein location tunnel status Up ke saath nazar aati hai, aur test user ka web traffic Analytics > Web Insights mein dikhta hai.Location Management shows the location with tunnel status Up, and a test user's web traffic appears in Analytics > Web Insights.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Location Management میں ٹنل Down نظر آ رہا ہے۔Location Management mein tunnel Down nazar aa raha hai.Tunnel shows Down in Location Management.
✅ VPN کریڈینشل (صارف نام/PSK)، روٹر کا سورس IP، اور Zscaler گیٹ وے تک UDP 4500/500 کی رسائی چیک کریں۔VPN credential (username/PSK), router ka source IP, aur Zscaler gateway tak UDP 4500/500 ki reachability check karein.Check the VPN credential (username/PSK), source IP of your router, and UDP 4500/500 reachability to Zscaler gateways.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ GRE/IPsec ٹنل اور Zscaler Client Connector (ZCC) میں کیا فرق ہے؟GRE/IPsec tunnel aur Zscaler Client Connector (ZCC) mein kya farq hai?What is the difference between GRE/IPsec tunnels and Zscaler Client Connector (ZCC)?
GRE ایک سادہ ٹنل ہے (تیز، لیکن انکرپشن نہیں) — IPsec انکرپشن جوڑتا ہے۔ ZCC (Zscaler Client Connector) صارفین کے لیے ایجنٹ ہے، جبکہ GRE/IPsec دفتر کے نیٹ ورکس اور ہیڈ لیس ٹریفک کے لیے ہے۔GRE ek simple tunnel hai (tez, lekin encryption nahi) — IPsec encryption jorta hai. ZCC (Zscaler Client Connector) users ke liye agent hai, jabke GRE/IPsec office networks aur headless traffic ke liye hai.GRE is a plain tunnel (fast, no encryption) — IPsec adds encryption. ZCC (Zscaler Client Connector) is an agent for users, while GRE/IPsec is for office networks and headless traffic.