List view
Integrations
Integrations
Applications
Applications
App-specific Handling
App-specific Handling
test
test
Â
Zscaler Integration
This guide will walk you through integrating your Zscaler tenant with Lumia using Proxy Chaining.
This integration allows Zscaler to route traffic from AI applications through Lumia’s engine for real-time inspection and governance.
This integration allows Zscaler to route traffic from AI applications through Lumia’s engine for real-time inspection and governance.
Before you begin
To complete this integration, ensure you have the following details provided by your Lumia representative:
- Your unique Lumia CA Certificate (
.pem) - Your Lumia Proxy URL
Prerequisite: Block HTTP/3 (QUIC)
Lumia requires AI traffic to flow through standard HTTPS for full inspection. Since AI applications often attempt to use the QUIC protocol (which can bypass proxy inspection), QUIC must be blocked in your Zscaler environment.
To get full visibility:
- Ensure your Zscaler deployment is using Tunnel 2.0 (required to identify and block QUIC traffic).
- Follow Zscaler’s documentation to disable and block QUIC. If QUIC is not blocked, AI interactions may bypass Lumia, resulting in a loss of visibility.
Installation Steps
Note: Zscaler is currently updating its Admin Console UI. If your interface looks different from the steps below, menu locations may vary slightly.
Step 1: Trust Lumia’s CA Certificate
- Login to the Zscaler Admin Console (
admin.zscaler.net). - Click Administration, then Root Certificates.
- Click on Add Root Certificate.
- Fill in the following fields:
- Name: Enter
Lumia Forward CA. - Type: Select Proxy Chaining.
- Click Choose File and select the Lumia provided certificate file (
.pem), then click on Save.
Step 2: Configure a Forwarding Proxy
- Open the Administration menu again, and click Proxies & Gateways.
- Click Add Proxy.
- Configure the following:
- Proxy Name: Enter
Lumia Forward Proxy. - IP Address / FQDN: Enter your unique Lumia Proxy URL.
- Port:
8080. - Proxy’s Root Certificate: Select the
Lumia Forward CAyou created in Step 1.
- Enable Insert X-Authenticated-User and Enable Base 64 Encoding for X-Authenticated-User.
- Click Save.
- Switch to the Proxy Gateways tab.
- Click Add Gateway for Proxies.
- Configure the following:
- Gateway Name: Enter
Lumia Forward Gateway. - Fail Close: Disable (This ensures that if the Lumia proxy is unreachable, user internet access will not be interrupted).
- Primary Proxy: Select the
Lumia Forward Proxyyou just created.
- Click Save.
Step 3: Create a URL Category
Important: In this step, you will create a Lumia URL category. Please pay close attention to entering the domains specifically in the URLs Retaining Parent Category field. Entering them here, rather than in the standard URL field, ensures the domains stay in your existing categories while being added to Lumia. This keeps your current security policies fully active while adding Lumia’s protection.
If you have any concerns, please contact us.
- Click Administration in the left main menu.
- Select URL Categories.
- Click Add URL Category.
- Configure the following settings:
- Name: Enter
Lumia Forward Category. - URLs Retaining Parent Category: Enter the following domains:
chatgpt.comclaude.ai- Click Save.
Note: To ensure a smooth integration, start with these two domains only. Once the technical setup is verified, Lumia will provide you with the complete list of AI domains to be added.
Step 4: Enable SSL Inspection for the Lumia forwarded domains
- Navigate to Policy, then click SSL Inspection.
- Click Add SSL Inspection Rule.
- Configure the following:
- Forwarding Gateways: Select
Lumia Forward Gateway. - Enable HTTP/2: Set to Disabled.
- Click Save.
Note: Zscaler evaluates decryption policies in top-down order. We strongly recommend placing the Lumia decryption rule at the top of the inspect rulebase to ensure no other rules override it for traffic forwarded to Lumia.
Step 5: Create a Lumia Forwarding Policy
- In the left menu, Click Policy, then click Forwarding Control.
- Click Add Forwarding Rule.
- Enter the Rule Name:
Lumia Forwarding Rule. - In the Forwarding Method field, select
Proxy Chaining.
- Click the Destination tab, then select URL Category.
- Select the
Lumia Forward Categoryyou previously created.
- In the Forward to Proxy Gateway field, select the
Lumia Forward Gatewayyou previously created.
- Click Save.
Step 6: Exempt Lumia Domains from SSL Inspection (For PAC File Setups Only)
Note: This step is required only if your tenant uses both Zscaler forwarding and PAC forwarding together.
If Lumia hasn’t specifically requested this exception, there’s no need to add it.
If Lumia hasn’t specifically requested this exception, there’s no need to add it.
A. Create a Destination Group:
- Go to Administration then click Destination IPv4 Groups.
- Click Add Destination IPv4 Group.
- Configure the following settings:
- Name: Enter
Lumia FQDN Wildcard. - Type: Select Wildcard FQDN.
- Wildcard FQDN: Enter
*.lumiasecurity.com. - Click Save.
B. Create the Bypass Rule:
Important: We will now create a Bypass rule (”Do Not Inspect”) for the Lumia URLs. Since Zscaler evaluates rules from top to bottom, this new rule must be placed before the inspection rule created in Step 4 to ensure the bypass takes effect.
- Go to Policy, then click SSL Inspection.
- Click Add SSL Inspection Rule.
- Configure the following settings:
- Rule Name: Enter
Bypass Lumia FQDN Wildcard. - Rule Order: Set it so that it applies before the inspection rule.
- Destination Groups: Select
Lumia FQDN Wildcard.
- In the Action field, select Do Not Inspect, then select Bypass Other Policies.
- Click Save.
Step 7: Activate and Verify
- To apply all configurations, click the Activation icon in the top navigation menu of the Zscaler Admin Console, and select Activate.
- Once activated, use the Integration Validator at https://check.lumiasecurity.com to confirm that your traffic is correctly routed and SSL inspection is active.
(Note: It may take a few minutes for the changes to propagate throughout the Zscaler network).
Next Step
If the validator confirms a successful connection, return to our Getting Started guide and proceed to Step 1.2: Verify Integration to confirm that logs are appearing in your Lumia Portal.
Zscaler IntegrationBefore you beginPrerequisite: Block HTTP/3 (QUIC)Installation StepsStep 1: Trust Lumia’s CA CertificateStep 2: Configure a Forwarding ProxyStep 3: Create a URL CategoryStep 4: Enable SSL Inspection for the Lumia forwarded domainsStep 5: Create a Lumia Forwarding PolicyStep 6: Exempt Lumia Domains from SSL Inspection (For PAC File Setups Only)Step 7: Activate and VerifyNext Step
Â
Â