Skip to main content
The Zscaler Internet Access integration uses two enforcement paths. Content-aware AI traffic is decrypted by ZIA and forwarded to the Forge rerouter. The broader Forge AI catalog is governed by URL and firewall policies that execute directly in ZIA without redirecting traffic.

Enforcement modes

Native catalog enforcement avoids an additional network hop and does not require content decryption by Forge. Use content-aware routing only where prompt, response, or MCP policy is required.

Content routing

Forge provisions the inspection CA and bounded ZIA SSL-inspection and forwarding configuration for the supported destination set. Managed clients must trust the inspection CA through the organization’s existing certificate-distribution process. The Forge rerouter recognizes the application and protocol, preserves the intended upstream, and directs the connection to the organization’s LLM Gateway or MCP Gateway. The gateway then authenticates the identity, applies policies, forwards allowed traffic, and records the session. Forge previews changes to SSL inspection, destination scope, forwarding, exclusions, and rollback before applying them. TLS bypass, certificate pinning, QUIC, ECH, location exclusions, and metadata-only paths remain visible as coverage states.

Native policies

Forge generates a provider diff and rollback plan and requires explicit confirmation before apply. Rule creation, activation, and provider readback are tracked separately. The native policy remains in ZIA’s request path. Forge ingests the resulting Web NSS events after the fact rather than proxying that traffic.

Sources

Web NSS imports are authenticated, bounded, idempotent, and support gzip delivery. Forge records accepted, rejected, parsed, skipped, attached, and unresolved counts.

Connection

Setup

  1. Connect the ZIA tenant and test policy, SSL-inspection, forwarding, identity, location, and NSS capabilities independently.
  2. Configure Web NSS delivery to the Forge receiver and verify the shared secret and feed identity.
  3. Enable content-aware routing for the supported AI destinations in scope.
  4. Review and confirm the CA, inspection rules, forwarding target, exclusions, provider readback, and rollback plan.
  5. Compile broad Access policies into ZIA URL or firewall rules.
  6. Verify a routed test session and a separate native-policy event in Forge.
NSS evidence does not prove content visibility. Prompt, response, and tool inspection require a verified route through a Forge gateway.