Capstone: ZIA + ZPA SASE Build
Zscaler Private Access (ZPA) Zscaler portal — demo tenant (GUI)
مقصدObjectiveObjective
اس capstone میں آپ ZIA (انٹرنیٹ سیکیورٹی) اور ZPA (private access) کو ایک SASE build میں جوڑیں گے اور تصدیق کریں گے کہ دونوں paths ایک ہی صارف کے لیے کام کرتے ہیں۔Is capstone mein aap ZIA (internet security) aur ZPA (private access) ko ek SASE build mein jorenge aur verify karenge ke dono paths ek hi user ke liye kaam karte hain.In this capstone you will combine ZIA (internet security) and ZPA (private access) into one SASE build and verify both paths work for the same user.
آسان مثالSimple AnalogySimple Analogy
یہ capstone نئے برانچ آفس کھولنے جیسا ہے: انٹرنیٹ کا گیٹ (ZIA) اور آفس ایپس کا گیٹ (ZPA) دونوں کھل گئے، لیکن ہر مہمان صرف وہی جائے گا جہاں اس کا pass اجازت دے۔Ye capstone naye branch office kholne jaisa hai: internet ka gate (ZIA) aur office apps ka gate (ZPA) dono khul gaye, lekin har mehman sirf wahi jayega jahan us ka pass ijazat de.This capstone is like opening a new branch office: the gate for the internet (ZIA) and the gate for the office apps (ZPA) both open, but each guest still goes only where their pass allows.
سیٹ اپLab SetupLab Setup
Zscaler پورٹل ڈیمو ٹیننٹ جس میں ZIA اور ZPA دونوں provisioned ہوں۔ ہر test device پر ایک Client Connector، ایک IdP، ایک internal app segment، ZIA میں انٹرنیٹ URL filtering۔Zscaler portal demo tenant jismein ZIA aur ZPA dono provisioned hon. Har test device par ek Client Connector, ek IdP, ek internal app segment, ZIA mein internet URL filtering.Zscaler portal demo tenant with both ZIA and ZPA provisioned. One Client Connector per test device, one IdP, one internal app segment, internet URL filtering in ZIA.
اقداماتStepsSteps
Step 1
Step 1 — Identity۔ Tenant میں IdP ایک بار جوڑیں تاکہ ZIA اور ZPA دونوں وہی users اور groups استعمال کریں۔Step 1 — Identity. Tenant mein IdP ek baar jorein taake ZIA aur ZPA dono wahi users aur groups istemal karein.Step 1 — Identity. Connect the IdP once in the tenant so both ZIA and ZPA use the same users and groups.
Step 2
Step 2 — ZIA path۔ تصدیق کریں کہ انٹرنیٹ ٹریفک ZIA سے گزرتی ہے: test user پر URL filtering اور SSL inspection policy لگتی ہے۔Step 2 — ZIA path. Confirm karein ke internet traffic ZIA se guzarta hai: test user par URL filtering aur SSL inspection policy lagti hai.Step 2 — ZIA path. Confirm internet traffic goes through ZIA: check URL filtering and SSL inspection policy applies to the test user.
Step 3
Step 3 — ZPA path۔ تصدیق کریں کہ App Connector healthy ہے اور Application Segment صحیح FQDN اور ports کے ساتھ published ہے۔Step 3 — ZPA path. Verify karein ke App Connector healthy hai aur Application Segment sahi FQDN aur ports ke saath published hai.Step 3 — ZPA path. Verify the App Connector is healthy and the Application Segment is published with the right FQDN and ports.
🖱️ Administration > App Connectors, Administration > Application SegmentsAdministration > App Connectors, Administration > Application SegmentsAdministration > App Connectors, Administration > Application Segments
Step 4
Step 4 — Unified policy۔ Access Policy rules لکھیں جو private app کے لیے IdP group، MFA اور compliant posture مانگیں۔Step 4 — Unified policy. Access Policy rules likhein jo private app ke liye IdP group, MFA aur compliant posture maangein.Step 4 — Unified policy. Write Access Policy rules that require the IdP group, MFA, and compliant posture for the private app.
🖱️ Policy > Access PolicyPolicy > Access PolicyPolicy > Access Policy
Step 5
Step 5 — End-to-end test۔ ایک ہی client سے انٹرنیٹ سائٹ (ZIA path) اور internal app (ZPA path) کھولیں۔ دونوں ایک ہی Client Connector سے کام کرنے چاہئیں۔Step 5 — End-to-end test. Ek hi client se internet site (ZIA path) aur internal app (ZPA path) kholein. Dono ek hi Client Connector se kaam karne chahiye.Step 5 — End-to-end test. From one client, open an internet site (ZIA path) and the internal app (ZPA path). Both must work from the same Client Connector.
Step 6
Step 6 — Negative tests۔ Unapproved انٹرنیٹ category try کریں (ZIA کو block کرنا چاہیے) اور segment پر unauthorized user (ZPA کو deny کرنا چاہیے)۔ دونوں Analytics > Logs میں چیک کریں۔Step 6 — Negative tests. Unapproved internet category try karein (ZIA ko block karna chahiye) aur segment par unauthorized user (ZPA ko deny karna chahiye). Dono Analytics > Logs mein check karein.Step 6 — Negative tests. Try an unapproved internet category (ZIA must block) and an unauthorized user on the segment (ZPA must deny). Check Analytics > Logs for both.
تصدیقVerifyVerify
وہی user، وہی device: انٹرنیٹ blocked category ZIA سے deny، private app ZPA سے allow — سب Analytics > Logs میں نظر آئے۔Wahi user, wahi device: internet blocked category ZIA se deny, private app ZPA se allow — sab Analytics > Logs mein nazar aaye.Same user, same device: internet blocked category denied by ZIA, private app allowed by ZPA — all visible in Analytics > Logs.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ انٹرنیٹ ZIA سے چل رہا ہے لیکن private app کبھی نہیں کھلتی۔Internet ZIA se chal raha hai lekin private app kabhi nahi khulti.Internet works through ZIA but the private app never opens.
✅ Client Connector کا ZPA module off ہو سکتا ہے، یا Access Policy اس user کو deny کر رہی ہے۔ ترتیب follow کریں: client module → policy → segment → connector۔Client Connector ka ZPA module off ho sakta hai, ya Access Policy is user ko deny kar rahi hai. Tarteeb follow karein: client module → policy → segment → connector.The ZPA module of the Client Connector may be off, or the Access Policy denies this user. Follow the order: client module → policy → segment → connector.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ اس capstone سے کیا deliver ہونا چاہیے؟Is capstone se kya deliver hona chahiye?What should this capstone deliver?
ڈیمو ٹیننٹ میں ZIA اور ZPA کی combined working deployment، دونوں paths کے verified user traffic کے ساتھ۔Demo tenant mein ZIA aur ZPA ki combined working deployment, dono paths ke verified user traffic ke saath.A combined, working deployment of ZIA and ZPA in the demo tenant with verified user traffic for both paths.
❓ SASE build میں ZIA اور ZPA ٹریفک کیسے تقسیم کرتے ہیں؟SASE build mein ZIA aur ZPA traffic kaise taqseem karte hain?How do ZIA and ZPA split traffic in a SASE build?
ZIA انٹرنیٹ اور SaaS ٹریفک سنبھالتا ہے؛ ZPA private apps سنبھالتا ہے۔ ایک Client Connector دونوں لے کر چلتا ہے، policy کے حساب سے الگ کر کے۔ZIA internet aur SaaS traffic sambhalta hai; ZPA private apps sambhalta hai. Ek Client Connector dono le kar chalta hai, policy ke hisaab se alag kar ke.ZIA handles internet and SaaS traffic; ZPA handles private apps. One Client Connector carries both, split by policy.