Enforcement modes
Native catalog enforcement avoids an additional network hop and does not
require content decryption by Forge. Use content-aware routing only where
prompt, response, or MCP policy is required.
Content routing
Forge provisions the inspection CA and bounded ZIA SSL-inspection and forwarding configuration for the supported destination set. Managed clients must trust the inspection CA through the organization’s existing certificate-distribution process. The Forge rerouter recognizes the application and protocol, preserves the intended upstream, and directs the connection to the organization’s LLM Gateway or MCP Gateway. The gateway then authenticates the identity, applies policies, forwards allowed traffic, and records the session. Forge previews changes to SSL inspection, destination scope, forwarding, exclusions, and rollback before applying them. TLS bypass, certificate pinning, QUIC, ECH, location exclusions, and metadata-only paths remain visible as coverage states.Native policies
Forge generates a provider diff and rollback plan and requires explicit
confirmation before apply. Rule creation, activation, and provider readback are
tracked separately.
The native policy remains in ZIA’s request path. Forge ingests the resulting
Web NSS events after the fact rather than proxying that traffic.
Sources
Web NSS imports are authenticated, bounded, idempotent, and support gzip
delivery. Forge records accepted, rejected, parsed, skipped, attached, and
unresolved counts.
Connection
Setup
- Connect the ZIA tenant and test policy, SSL-inspection, forwarding, identity, location, and NSS capabilities independently.
- Configure Web NSS delivery to the Forge receiver and verify the shared secret and feed identity.
- Enable content-aware routing for the supported AI destinations in scope.
- Review and confirm the CA, inspection rules, forwarding target, exclusions, provider readback, and rollback plan.
- Compile broad Access policies into ZIA URL or firewall rules.
- Verify a routed test session and a separate native-policy event in Forge.