> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Zscaler

> Route supported AI traffic through Forge and enforce broad AI access directly in ZIA.

The Zscaler Internet Access integration uses two enforcement paths.
Content-aware AI traffic is decrypted by ZIA and forwarded to the Forge
rerouter. The broader Forge AI catalog is governed by URL and firewall policies
that execute directly in ZIA without redirecting traffic.

## Enforcement modes

| Mode                       | Coverage                                                            | Traffic path                                                                        | Forge visibility                                                                 |
| -------------------------- | ------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| Content-aware routing      | Supported desktop AI, developer APIs, browser AI, and MCP protocols | ZIA SSL inspection and forwarding route the request to the Forge LLM or MCP Gateway | Supported content, identity, sessions, tool activity, and inline policy outcomes |
| Native catalog enforcement | Thousands of classified AI applications and destinations            | ZIA evaluates the generated URL or firewall rule locally                            | Destination, user, device, provider action, inventory, and analytics from NSS    |

Native catalog enforcement avoids an additional network hop and does not
require content decryption by Forge. Use content-aware routing only where
prompt, response, or MCP policy is required.

## Content routing

Forge provisions the inspection CA and bounded ZIA SSL-inspection and forwarding
configuration for the supported destination set. Managed clients must trust the
inspection CA through the organization's existing certificate-distribution
process.

The Forge rerouter recognizes the application and protocol, preserves the
intended upstream, and directs the connection to the organization's LLM Gateway
or MCP Gateway. The gateway then authenticates the identity, applies policies,
forwards allowed traffic, and records the session.

Forge previews changes to SSL inspection, destination scope, forwarding,
exclusions, and rollback before applying them. TLS bypass, certificate pinning,
QUIC, ECH, location exclusions, and metadata-only paths remain visible as
coverage states.

## Native policies

| Rule               | Compiled fields                                                         |
| ------------------ | ----------------------------------------------------------------------- |
| URL filtering      | Forge AI categories, request methods, action, state, logging, and order |
| Firewall filtering | Destination addresses, action, state, logging, and rank                 |

Forge generates a provider diff and rollback plan and requires explicit
confirmation before apply. Rule creation, activation, and provider readback are
tracked separately.

The native policy remains in ZIA's request path. Forge ingests the resulting
Web NSS events after the fact rather than proxying that traffic.

## Sources

| Source     | Coverage                                                                                    |
| ---------- | ------------------------------------------------------------------------------------------- |
| ZIA OneAPI | URL categories, URL and firewall rules, SSL inspection, forwarding, identity, and locations |
| Identity   | Users, groups, departments, locations, and location groups                                  |
| NSS setup  | Feeds, servers, delivery state, and receiver configuration                                  |
| Web NSS    | Host, application, category, action, identity, inspection, routing, and lag                 |

Web NSS imports are authenticated, bounded, idempotent, and support gzip
delivery. Forge records accepted, rejected, parsed, skipped, attached, and
unresolved counts.

## Connection

| Field                | Description                                          |
| -------------------- | ---------------------------------------------------- |
| Vanity domain        | Customer ZIA tenant                                  |
| Cloud                | Zscaler cloud hosting the tenant                     |
| Client ID and secret | OneAPI OAuth credentials                             |
| NSS feed secret      | Shared secret for authenticated Web NSS delivery     |
| NSS feed name        | Stable provider feed identifier attached to evidence |
| Poll interval        | OneAPI configuration-readback interval               |

## Setup

1. Connect the ZIA tenant and test policy, SSL-inspection, forwarding, identity,
   location, and NSS capabilities independently.
2. Configure Web NSS delivery to the Forge receiver and verify the shared secret
   and feed identity.
3. Enable content-aware routing for the supported AI destinations in scope.
4. Review and confirm the CA, inspection rules, forwarding target, exclusions,
   provider readback, and rollback plan.
5. Compile broad Access policies into ZIA URL or firewall rules.
6. Verify a routed test session and a separate native-policy event in Forge.

NSS evidence does not prove content visibility. Prompt, response, and tool
inspection require a verified route through a Forge gateway.
