Zscaler Integration[old]

Zscaler Integration


Configuring your Zscaler to work with Lumia is easy!
To connect your Zscaler tenant, Lumia will share your unique certificate file (.pem) and proxy URL with you.
 
Before starting, make sure your SASE can handle HTTP/3 (QUIC) traffic. Since Zscaler cannot process QUIC yet, this usually means blocking QUIC.

Step 1: Trusting Lumia’s CA Certificate

  • Login to the Zscaler admin dashboard (admin.zscaler.net)
  • Click on Administration, then on Root Certificates
A screenshot of a computer AI-generated content may be incorrect.
  • Click on Add Root Certificate
A screenshot of a computer AI-generated content may be incorrect.
  • In the Name field, enter Lumia Forward CA;
    In the Type field, select Proxy Chaining.
Screens screenshot of a computer AI-generated content may be incorrect.
  • Click Choose File and select the Lumia provided certificate file (.pem), then click on Save
A screenshot of a computer AI-generated content may be incorrect.

Step 2: Configuring a Forwarding Proxy

  • Open the Administration menu again, and click on Proxies & Gateways
A screenshot of a computer AI-generated content may be incorrect.
  • Click on Add Proxy
A screenshot of a computer AI-generated content may be incorrect.
  • In the Proxy name field, enter Lumia Forward Proxy
    In the IP Address / FQDN field, enter the Lumia provided Proxy URL
    In the Port field, enter 8080
    In the Proxy’s Root Certificate field, select the Lumia Forward CA you defined ealrier
A screenshot of a computer AI-generated content may be incorrect.
  • Enable Insert X-Authenticated-User and Enable Base 64 Encoding for X-Authenticated-User, then click on Save
Screens screenshot of a computer AI-generated content may be incorrect.
  • Click on the Proxy Gateways tab
A screenshot of a computer AI-generated content may be incorrect.
  • Click on Add Gateway for Proxies
A screenshot of a computer AI-generated content may be incorrect.
  • In the Gateway Name field, enter Lumia Forward Proxy
    Disable Fail Close
    I
    n the Primary Proxy field, select the Lumia Forward Proxy you defined earlier
    Then click on Save
A screenshot of a computer AI-generated content may be incorrect.

Step 3: Creating a URL Category

Warning: The scope of any Zscaler URL Category applies to the entire tenant. If your current Zscaler policies depend on URL categories, make sure that creating the Lumia category does not invalidate any existing rules. We address this by using the “URLs Retaining Parent Category” option (see below). If you’re unsure, please contact us.
  • Click on Administration in the left main menu, then select URL Categories
A screenshot of a computer AI-generated content may be incorrect.
  • Click on Add URL Category
A screenshot of a computer AI-generated content may be incorrect.
  • In the Name field, enter Lumia Forward Category
  • In the URLs Retaining Parent Category, enter:
  • chatgpt.com claude.ai
    (We will add the full list after the technical sanity check is complete.)

    Then click on Save.
A screenshot of a computer AI-generated content may be incorrect.

Step 4: Creating a Lumia Forwarding Policy

  • In the left menu, select Policy, then click on Forwarding Control
A screenshot of a computer AI-generated content may be incorrect.
  • Click Add Forwarding Rule
A screenshot of a computer AI-generated content may be incorrect.
 
  • Enter a name for the Rule
    In the Forwarding Method field, select Proxy Chaining
A screenshot of a computer AI-generated content may be incorrect.
  • Click on Destination, then on URL Category
A screenshot of a computer AI-generated content may be incorrect.
  • Select the Lumia Forward Category you previously created
A screenshot of a computer screen AI-generated content may be incorrect.
  • In the Forward to Proxy Gateway, select the Lumia Forward Proxy you previously created
A screenshot of a computer AI-generated content may be incorrect.
  • Click on Save
A screenshot of a computer AI-generated content may be incorrect.
 
Finally, don’t forget to Activate the changes 🙂
That’s it, you can now enjoy using Lumia!

Step 5: Create SSL Inspection policy for the Lumia forwarded domains

  1. Navigate to PolicySSL Inspection
  2. Click Add SSL Inspection Rule:
    1. Forwarding Gateways: Lumia Forward Proxy
    2. Enable HTTP/2: Disabled
  3. Click Save
 
Important:
Decryption policies are evaluated top-down. We strongly recommend placing the Lumia decryption rule at the top of the inspect rulebase and ensuring no other inspect rule overrides it for traffic forwarded to Lumia.

[Optional] Exempting Lumia Domains from SSL Inspection

This step is required only if your tenant uses both Zscaler forwarding and PAC forwarding together.
If Lumia hasn’t specifically requested this exception, there’s no need to add it.
  • Go to Administration → Destination IPv4 Groups, then click on Add Destination IPv4 Group
notion image
  • In the Name field, enter Lumia FQDN.
    In the Type field, select Wildcard FQDN.
    In the Wildcard FQDN field, enter *.lumiasecurity.com.
    Click Save.
notion image
  • Go to Policy → SSL Inspection
    We will now create a Do Not Inspect rule for the Lumia URLs.
    Since rules are evaluated from top to bottom, it’s important to place the new rule before the relevant Inspect rule.
    Click Add SSL Inspection Rule.
    Set the Rule Order so that it applies before the inspection rule.
    In the Destination Groups field, select Lumia FQDN.
notion image
  • In the Action field, select Do Not Inspect, then select Bypass Other Policies.
notion image