Skip to main content

Zscaler Setup

Forward collects Zscaler Private Access (ZPA) through a single SASE setup that pairs your ZPA tenant with the App Connectors it manages. Forward queries the ZPA management API to discover the tenant's App Connectors, then collects each selected connector over SSH. The result is a model of the ZPA cloud tenant together with its App Connectors. The SASE setups section under Network Sources is where you add a setup, run connectivity tests, and view collection state.

note

This flow covers Zscaler Private Access (ZPA) — the ZPA cloud tenant and its App Connectors. It does not collect Zscaler Internet Access (ZIA) or Zscaler Digital Experience (ZDX).

Prerequisites

  • A Forward Collector that can reach your ZPA management API and SCIM endpoint over HTTPS, and reach each App Connector over SSH.
  • The SASE setups section must be available for the network. It appears when the Zscaler ZPA feature is enabled and the collector reports support for it. If you don't see the section, contact your administrator.
  • A role that permits managing collection sources to add, edit, or delete setups (a role with view access can see them). For details on roles, see Role-Based Access Control (RBAC).
  • From your ZPA tenant, gather the following before you start:
    • ZPA management API base URL — for example https://config.zpatwo.net.
    • ZPA API client credentials — a client ID and client secret for the ZPA API. You enter these as the username and password of an HTTP login credential in Forward.
    • SCIM endpoint URL and bearer token — SCIM is the identity server (or servers) ZPA uses to identify users. Forward reads it to associate users with the ZPA configuration. Provide the SCIM endpoint URL — for example https://scim.zpatwo.net — and its API token, which you enter as an HTTP API key credential in Forward. A setup can include more than one SCIM endpoint.
    • SSH credentials for the App Connectors you intend to collect.

You can create the HTTP and SSH credentials ahead of time under Network Sources → Devices → Credentials, or add them inline while filling out the wizard.

Add a Zscaler setup

Open Network Sources → SASE setups and click Add Zscaler setup. (When setups already exist, the button on the list is labeled Add SASE setup; both open the same wizard.) The wizard has three steps: Name setup, Add credential, and Select app connectors.

SASE setups landing with the Add Zscaler setup button

1. Name your Zscaler setup

Enter a Setup name. The name identifies the setup throughout the UI and must be unique among your existing setups. Click Next.

Name your Zscaler setup wizard step

2. Add credential

Provide the credentials Forward uses to reach the ZPA tenant:

FieldNotes
ZPA base URLThe ZPA management API base URL, for example https://config.zpatwo.net.
Select login credentialsThe HTTP login credential for the ZPA API (client ID as the username, client secret as the password). Use Add new login credential to create one inline.
SCIM credentialsOne or more SCIM endpoints. Each row pairs a SCIM URL (for example https://scim.zpatwo.net) with an API key credential that holds the SCIM bearer token.

Use Add another SCIM credential to add more SCIM endpoints, or the remove icon to delete a row. To create an API key credential without leaving the wizard, use Add new API key credential.

Click Test connection. The connection must succeed before the wizard advances. A successful test queries the ZPA API and discovers the tenant's App Connectors, which populate the next step. Changing any credential field clears the test result, so re-run the test after editing.

While the test runs, you can follow its progress: use View all collector jobs while the test is queued, See tail logs while it is running, and See logs once it finishes to review the full output.

Add credential wizard step with the ZPA base URL, login credential, and SCIM fields

3. Select app connectors

Forward lists the App Connectors discovered during the connection test. For each connector you want to collect, turn on the Collect toggle and review its settings:

ColumnNotes
CollectWhether the connector is included in collection.
NameThe connector's name, as reported by ZPA.
Private IPThe connector's private host address.
LocationOptional location assignment. Defaults to Unassigned.
Collect typeSSH to collect over SSH, or Manual to track the connector without active collection.
PortSSH port. Defaults to 22.
CredentialsThe CLI login credential used for SSH. Defaults to Auto-associate.
Jump serverOptional intermediate host for the SSH connection.

Select at least one connector to continue. Use the bulk Edit, Include, and Exclude actions, or the per-row Edit connector action, to set credentials, port, location, or jump server for multiple connectors at once.

Select app connectors wizard step listing discovered App Connectors

Click Add setup to save. Forward starts a connectivity test for each connector marked for SSH collection.

SASE setups section

The SASE setups section lists each setup with these columns:

  • Collect — toggle the whole setup in or out of collection.
  • Setup name and Base URL.
  • Credential — the login credential used for the ZPA API.
  • App connectors — the number of connectors collected out of the total. Click the count to open the App Connectors drawer.
  • Status — a summary of connector connectivity (connected, failed, untested, testing).
  • Newly discovered — connectors found by ZPA that aren't yet configured in the setup.

Each row offers Edit setup and Delete setup actions.

SASE setups section showing a Zscaler setup with its connector and connectivity status

Manage app connectors

Click the App connectors count on a setup row to open the App Connectors drawer. From there you can Test connectivity on an individual connector, Refresh to re-query ZPA, and review each connector's connectivity status. Test connectivity does not apply to connectors set to the Manual collect type.

Edit a setup

Click Edit setup to change the setup. The drawer has a General section for the Setup name and a Credential section with the same ZPA base URL, login credential, and SCIM fields as the wizard. Only changed fields are saved.

As in the wizard, the connection must test successfully before you can save. If the connectivity test fails, the edit can't be saved until the credentials are corrected and the test passes.

Delete a setup

Click Delete setup, then confirm in the deletion dialog. This action can't be undone.

Supported features

See the Feature Matrix for the Zscaler features Forward Enterprise supports.