Cloud Security Services

Cloud Security Service (CSS) is a cloud-hosted security service that protects an Enterprise branch and/or data center. The security services include firewalls, URL filtering, and other such services.

In CSS, define and configure a cloud security service instance and establish a secure tunnel directly from the Edge to the CSS.

Users can configure the branch Edge to establish a direct tunnel to the cloud service pop. This option has the following advantages:
  • Simplifies configuration.
  • Saves link bandwidth costs by offloading non-enterprise traffic to the Internet.
  • Protects branch sites from malicious traffic by redirecting Internet traffic to a cloud security service.

Configure a Cloud Security Service

The Cloud Security Service (CSS) establishes a secure tunnel from an Edge to the cloud security service sites. This ensures secured traffic flow to the cloud security services. To configure a Cloud Security Service, perform the following steps:
  1. In the SD-WAN service of the Enterprise portal, select Configure Network Services.
  2. On the Network Services page, navigate to Non SD-WAN Destinations via Edge > Cloud Security Service , select New.
    Figure 1. Configure New Cloud Security Service
  3. In the New Cloud Security Provider window, select a service type from the menu. Arista SD-WAN supports the following CSS types:
    • Generic Cloud Security Service
    • Symantec / Palo Alto Cloud Security Service
      Note: Starting from the 5.0.0 release, the Orchestrator configures the Palo Alto CSS under the new service type template "Symantec / Palo Alto Cloud Security Service." Customers with an existing Palo Alto CSS configuration under 'Generic Cloud Security Service' must migrate to the new 'Symantec / Palo Alto Cloud Security Service' template.
    • Zscaler Cloud Security Service
    1. For "Generic" or "Symantec / Palo Alto" Cloud Security Service as the Service Type, configure the following details and select Add:
      Table 1. Cloud Security Service Options
      Option Description
      Service Name Enter a descriptive name for the cloud security service.
      Primary Point-of-Presence/Server Enter the IP address or hostname for the Primary server.
      Secondary Point-of-Presence/Server Enter the IP address or hostname for the Secondary server. This field is optional.

       

    2. For Zscaler Cloud Security Service as the Service Type, choose between manual deployment and automated deployment by selecting the Automate Cloud Service Deployment checkbox. Configure additional settings such as Zscaler Cloud and Layer 7 (L7) Health Check details to determine and monitor the health of the Zscaler Server.

Configure Automatic Tunnels from SD-WAN Edge to Zscaler

This section discusses how to automatically create a GRE or IPsec tunnel from SD-WAN Edge to Zscaler service provider.
Figure 2. Configure Automatic Tunnels from SD-WAN Edge to Zscaler
  1. In the New Cloud Security Provider window, enter a service name.
  2. Select the Automate Cloud Service Deployment checkbox.
  3. Select GRE or IPsec protocol for tunnel establishment.
    Note: The customer's Zscaler subscription determines the total number of CSS Zscaler GRE tunnels they can configure. The default value is 100.
  4. Configure additional details such as Domestic Preference, Zscaler Cloud, Partner Admin Username, Password, Partner Key, and Domain, as described in the below table.
    Table 2. Additional Cloud Service Deployment Options
    Option Description
    Domestic Preference Enable this option to prioritize Zscaler data centers from the country of origin of the IP address even if they are farther away from the other Zscaler data centers.
    Note: Previously, the Domestic Preference option was only available for GRE tunnels. Starting with the 6.0.0 release, this option is configurable for establishing IPsec tunnels as well.
    Zscaler Cloud Choose either an existing Zscaler Cloud or use a new Zscaler Cloud. For the existing cloud, select a Zscaler cloud service from the drop-down menu. For new Zscaler cloud, enter the Zscaler cloud service name in the textbox.
    Partner Admin Username Enter the provisioned username of the partner admin.
    Partner Admin Password Enter the provisioned password of the partner admin.
    Note: Starting from the 4.5 release, the use of the special character "<" in the password is no longer supported. In cases where users have already used "<" in their passwords in previous releases, they must remove it to save any changes on the page.
    Partner Key Enter the provisioned partner key.
    Domain Enter the domain name that will host the cloud service.
    Sub Cloud This is an optional parameter that Zscaler Internet Access (ZIA) customers use to have a custom pool of data centers for Geo-location purposes.
    Note: CSS Zscaler automated deployment mode provides this option only after users choose IPsec for establishing tunnels.

     

  5. Select Validate Credentials. Successful validation activates the Save Changes button.
    Note: It is necessary to validate the credentials to add a new CSS Provider.
  6. Optional: Configure the following L7 Health Check details to monitor the health of the Zscaler Server.
    Note: The L7 Health Check feature tests HTTP reachability to the Zscaler backend server. Upon enabling L7 Health Check, the Edge sends HTTP L7 probes to a Zscaler destination (Example: http://<zscaler cloud>/vpntest) which is Zscaler's backend server for the HTTP health check. This method is an improvement over using network level keep-alive (GRE or IPsec) as that method only tests for network reachability to the frontend of a Zscaler server. It the tunnel does not receive an L7 response after 3 successive retries, or if there is an HTTP error, the system considers the Primary Tunnel as 'Down' and the Edge will attempt to failover Zscaler traffic to the Standby Tunnel (if one is available). If the Edge successfully fails over Zscaler traffic to the Standby Tunnel, the Standby becomes the new Primary Tunnel. In an unlikely event when the L7 Health Check marks both the Primary and Standby tunnels as 'Down', the Edge routes Zscaler traffic using a Conditional Backhaul policy (if such a policy exists). The Edge only sends L7 probes over the Primary Tunnel towards the Primary Server, never over the Standby Tunnel.
    Table 3. L7 Health Check Option Descriptions
    Option Description
    L7 Health Check Select the checkbox to enable L7 Health Check for the Zscaler Cloud Security Service provider, with default probe details (HTTP Probe interval = 5 seconds, Number of Retries = 3, RTT Threshold = 3000 milliseconds). By default, L7 Health Check is not enabled.
    Note: Orchestrator does not support the configuration of health check probe details.
    Note: For a given Edge/Profile, a user cannot override the L7 health check parameters configured in the Network Service.
    HTTP Probe Interval Enter the duration of the interval between individual HTTP probes. The default probe interval is 5 seconds.
    Number of Retries Enter the number of probes retries allowed before marking the cloud service as DOWN. The default value is 3.
    RTT Threshold Displays the round trip time (RTT) threshold, expressed in milliseconds, used to calculate the cloud service status. The system marks the cloud service as DOWN when the measured RTT exceeds the configured threshold.. The default value is 3000 milliseconds.
    Zscaler Login URL Enter the login URL and then select Login to Zscaler. This will redirect users to the Zscaler Admin portal of the selected Zscaler cloud.
    Note: Enter the Zscaler login URL to activate the Login to Zscaler button.

     

  7. To log in to the Zscaler Admin portal from the Orchestrator, enter the Zscaler login URL, and then select Login to Zscaler. This action redirects users to the Zscaler Admin portal of the selected Zscaler cloud.
    Note:

Configure Manual Tunnels from SD-WAN Edge to Zscaler

This section discusses how to manually create a GRE or IPsec tunnel from an SD-WAN Edge to a Zscaler service provider. Unlike automatic tunnels, configuring manual tunnels requires users to specify a tunnel destination to bring up the tunnels.
Figure 3. Configure Manual Tunnels from SD-WAN Edge to Zscaler
  1. In the New Cloud Security Provider window, enter a service name.
  2. Enter the IP address or hostname for the primary server.
  3. Optionally, enter the IP address or hostname for the secondary server.
  4. Select a Zscaler cloud service from the drop-down menu or enter the Zscaler cloud service name in the textbox.
  5. Configure other parameters as desired, and then select Save Changes.
    Note: If users select Zscaler Cloud Security Service and plan to assign a GRE tunnel, they must enter only IP addresses for Primary and Secondary Zscaler servers in GRE deployments. The GRE protocol does not support hostnames.
    The Orchestrator displays the configured cloud security services under the Cloud Security Service area in the Network Services window.
    Figure 4. Configured Cloud Security Services
Associate the cloud security service with a Profile or an Edge:

Configure Cloud Security Services for Profiles

  • Users must have access permission to configure Network Services.
  • The Orchestrator version must be 3.3.x or above.
  • Users must configure CSS Gateway endpoint IPs and FQDN credentials in the third party CSS.
Enable Cloud Security Service (CSS) to establish a secure tunnel from an Edge to the cloud security service sites. This feature redirects secured traffic to third-party cloud security sites. At the Profile level, Arista SD-WAN and Zscaler integration supports automation of IPsec and GRE tunnels.
Note: Only one CSS with GRE is allowed per Profile.
  1. In the Enterprise portal, select Configure > Profiles .
  2. Select the Device icon next to a Profile, or select the link to the Profile, and then select the Device tab.
  3. In the Cloud Security area, switch the dial from the Off position to the On position.
  4. Configure the following settings:
    Figure 5. Cloud Security Service Settings

     

    Table 4. Cloud Security Service Option Descriptions
    Option Description
    Cloud Security Service Select a cloud security service from the drop-down menu to associate with the profile. Users can also select New Cloud Security Service from the drop-down to create a new service type. For additional information about how to create a new CSS, see Configure a Cloud Security Service.
    Note: Configure the Zscaler login URL to enable the Login to Zscaler button in the CSS area. Selecting the Login to Zscaler button will redirect users to the Zscaler Admin portal of the selected Zscaler cloud.
    Tunneling Protocol This option is available only for the Zscaler cloud security service provider. For a manual Zscaler service provider, choose either IPsec or GRE as the tunneling protocol. By default, IPsec is selected. For an automated Zscaler service provider, users cannot configure the Tunneling Protocol field. It displays the protocol name used by the service provider.
    Hash Select the hash function as SHA 1 or SHA 256 from the drop-down. The default value is SHA 1.
    Encryption Select the encryption algorithm as AES 128 or AES 256 from the drop-down. The default value is None.
    Key Exchange Protocol Select the key exchange method as IKEv1 or IKEv2. The default value is IKEv2. This option is not available for Symantec cloud security service.
    Login to Zscaler Select Login to Zscaler to log in to the Zscaler Admin portal of the selected Zscaler cloud.

     

  5. Select Save Changes.
When users enable Cloud Security Service and configure the settings in a Profile, the setting is automatically applied to the Edges in the Profile. If required, override the configuration for a specific Edge. See Configure Cloud Security Services for Edges.
For the Profiles created before the 3.3.1 release, and with an active cloud security service, follow the steps below:
  • Redirect only web traffic to the cloud security service.
  • Redirect all Internet-bound traffic to the cloud security service.
  • Redirect traffic based on business policy settings. This option is available only from release 3.3.1. If users choose this option, then the other two options are no longer available.

For new Profiles (release 3.3.1 or later), the Business Policy settings redirect the traffic by default. See Configure Business Policies with Cloud Security Services.

Configure Cloud Security Services for Edges

When users assign a Profile to an Edge, the Edge automatically inherits the Cloud Security Service (CSS) and attributes configured in the Profile. Users can override the settings to select a different cloud security provider or modify the attributes for each Edge.

To override the CSS configuration for a specific Edge, perform the following steps:

  1. In the SD-WAN service of the Enterprise portal, select Configure > Edges .
    The Edges page displays the existing Profiles.
  2. Select the link to an Edge or select the View link in the Device column of the Edge.
    The Device tab displays the configuration options for the selected Edge.
  3. Under the VPN Services category, the Cloud Security Service area displays the CSS parameters of the associated Profile.
  4. In the Cloud Security Service area, select the Override checkbox to select a different CSS or to modify the attributes that the Edge inherits from its associated Profile.
    For additional information on the attributes, see Configure Cloud Security Services for Profiles.
  5. Select Save Changes in the Edges window to save the modified settings.
    Note: For CSS of type Zscaler and Generic, users must create VPN credentials. The Symantec CSS type does not require VPN credentials.

Manual Zscaler CSS Provider Configuration for Edges

At the Edge level, for a selected manual Zscaler CSS provider, users can override the settings inherited from the Profile and can configure additional parameters manually based on the tunneling protocol selected for tunnel establishment.

When configuring an IPsec tunnel manually, users must provide a Fully Qualified Domain Name (FQDN) and Pre-Shared Key (PSK) in addition to the inherited attributes.

Note: As a prerequisite, configure the Cloud Security Service Gateway endpoint IPs and FQDN credentials in the third-party security provider's portal.
Figure 6. Configure Cloud Security Service
Note: Configure the Zscaler login URL to display the Login to Zscaler button in the Cloud Security Service area. Use this button to access the Zscaler Admin portal directly.

Manual GRE tunnel configuration requires manually setting the GRE tunnel parameters for the WAN interface designated as the GRE tunnel source. Follow the steps below to complete the configuration.

  1. Under GRE Tunnels, select +Add.
    Figure 7. Add a GRE Tunnel
  2. In the Configure Tunnel window, configure the following GRE tunnel parameters, and select Update.
    Figure 8. Configure a GRE Tunnel

     

    Table 5. GRE Tunnel Configuration Options
    Option Description
    WAN Links Select the WAN interface that will serve as the source for the GRE tunnel.
    Tunnel Source Public IP Choose the IP address that will serve as the public IP for the tunnel. Select either the WAN Link IP or a Custom WAN IP. For Custom WAN IP, enter the specific IP address. It is necessary to use a different source public IP for each segment when configuring a Cloud Security Service (CSS) on multiple segments.
    Primary Point-of-Presence Enter the primary Public IP address of the Zscaler Data center.
    Secondary Point-of-Presence Enter the secondary Public IP address of the Zscaler Data center.
    Primary Router IP/Mask Enter the primary IP address of Router.
    Secondary Router IP/Mask Enter the secondary IP address of Router.
    Primary Internal ZEN IP/Mask Enter the primary IP address of Internal Zscaler Public Service Edge.
    Secondary Internal ZEN IP/Mask Enter the secondary IP address of Internal Zscaler Public Service Edge.
    Note:
    • Zscaler provides the Router IP/Mask and ZEN IP/Mask.
    • Each Enterprise supports only one Zscaler cloud and domain.
    • The Orchestrator allows only one CSS with GRE per Edge. An Edge can support only one segment with Zscaler GRE automation enabled.

    Scale Limitations

    • GRE-WAN: Edge supports a maximum of 4 public WAN links for a Non SD-WAN Destination (NSD), and on each link, it can have up to 2 tunnels (primary/secondary) per NSD. Therefore, for each NSD, users can have a maximum of 8 tunnels and 8 BGP connections from a single Edge.
    • GRE-LAN: Edge supports 1 link to Transit Gateway (TGW), and it can have up to 2 tunnels (primary/secondary) per TGW. Therefore, for each TGW, users can have a maximum of two tunnels and four BGP connections from one Edge (two BGP sessions per tunnel).

Automated Zscaler CSS Provider Configuration for Edges

At the Edge level, Arista SD-WAN and Zscaler integration supports:
  • IPsec/GRE Tunnel Automation
  • Zscaler Location/Sub-Location Configuration

IPsec/GRE Tunnel Automation

Users can configure IPsec/GRE tunnel automation for each Edge segment. Perform the following steps to establish automatic tunnels from an Edge.
  1. In the SD-WAN service of the Enterprise portal, select Configure > Edges .
  2. Select the Edge that users want to establish automatic tunnels on.
  3. Select the link to an Edge or select the View link in the Device column of the Edge.
    The Device tab displays the configuration options for the selected Edge.
  4. Under the VPN Services category, the Cloud Security Service area displays the CSS parameters of the associated Profile.
  5. In the Cloud Security Service area, select the Override checkbox to select a different CSS or to modify the attributes that the Edge inherits from its associated Profile.
    For additional information on the attributes, see Configure Cloud Security Services for Profiles.
  6. From the Cloud Security Service drop-down menu, select an automated CSS provider, and then select Save Changes.
    Figure 9. Automate IPsec and GRE Tunnel

    The automation creates a tunnel in the segment for each Edge public WAN link with a valid IPv4 address. Only one WAN link carries user data packets in a multi-WAN deployment. The Edge selects the WAN link with the best Quality of Service (QoS) score using bandwidth, jitter, loss, and latency as criteria. The Edge automatically creates the location after establishing a tunnel. The details of tunnel establishment and WAN links appear in the Cloud Security Service section.

    Note: The system does not allow users to change providers on a segment once it establishes an automated Zscaler tunnel. To switch to a new provider from an automated Zscaler service, users must explicitly deactivate the Cloud Security Service for that Edge and segment before reactivating it with the new provider.

Zscaler Location and Sub-Location Configuration

After users have established automatic IPsec/GRE tunnel for an Edge segment, the Orchestrator automatically creates a Location and displays under the Zscaler section of the Edge Device Settings page.
Note: In releases before 4.5.0, the Orchestrator displays the Sub-location configuration in the Cloud Security Service section for each segment. Currently, the Orchestrator allows configuring Zscaler settings for Location and Sub-location across the entire Edge from the Zscaler section of the Device Settings page. For existing users of CSS Sub-location automation, the Orchestrator upgrade automatically migrates the data.
In the Zscaler section, to update the Location or create Sub-locations for the selected Edge, make sure to:
  • Verify that the Edge has established the tunnel and has automatically created the location. The Orchestrator enables Sub-location creation only after users configure the VPN credentials or GRE options for the Edge. Review the sub-location features and limitations before beginning the configuration. See https://help.zscaler.com/zia/understanding-sublocations.
  • Match the Cloud Subscription to the one used during the Automatic CSS set up.

To update the Location or create Sub-locations for the selected Edge, perform the following steps:

  1. In the SD-WAN service of the Enterprise portal, select Configure > Edges .
  2. Select an Edge and select the icon under the Device column.
    The Device settings page for the selected Edge appears.
  3. Go to the Zscaler section, and then turn on the toggle button.
    Figure 10. Update a Zscaler Configuration
  4. From the Cloud Subscription drop-down menu, select the Cloud Subscription used to set up the Automatic CSS. The Cloud Name associated to the selected Cloud Subscription automatically appears.
    Note:
    • Cloud Subscription must have same Cloud name and Domain name as CSS.
    • To change "Cloud Subscription" provider, first deactivate CSS and Zscaler to remove the "Location", and then follow the creation steps for the new provider.

    In the Location table, selecting the View under the Action Details column displays the actual values for the configuration returned from Zscaler, if present. To configure the Gateway options and Bandwidth Controls for the Location, select the Edit button under Gateway Options.

  5. To create a Sub-location, in the Sub-Locations table, select the + icon under the Action column.
    1. In the Sub-Location Name text box, enter a unique name for the Sub-location. The Sub-location name should be unique across all segments for the Edge. The name can contain alphanumeric with a maximum word length of 32 characters.
    2. From the LAN Networks drop-down menu, select a VLAN configured for the Edge. The Subnet for the selected LAN network populates automatically.
      Note: For a selected Edge, Sub-locations should not have overlapping Subnet IPs.
  6. Select Save Changes.
    Figure 11. Save the CSS Changes
    Note: After creating at least one sub-location in the Orchestrator, Zscaler automatically generates an 'Other' sub-location, which the Orchestrator UI then displays. Users can also configure the “Other” Sub-location’s Gateway options by selecting the Edit button under Gateway Options in the Sub-Locations table.
  7. After creating a Sub-location, update the Sub-location configurations from the same Orchestrator page. Selecting the Save Changes button automatically updates the Sub-location configurations on the Zscaler side.
  8. To delete a Sub-location, select the '-' icon under the Action column.
    Note: Deleting the last sub-location from the table also automatically removes the 'Other' sub-location.

Configure Zscaler Gateway Options and Bandwidth Control

To configure Gateway options and Bandwidth controls for the Location and Sub-location, select the Edit button under Gateway Options, in the respective table.
The Zscaler Gateway Options and Bandwidth Control window appears.
Figure 12. Edit Location Gateway Options

Configure the Gateway options and Bandwidth controls for the Location and Sub-location, as needed, and select Save Changes.

Note: The Orchestrator offers slightly different Zscaler Gateway Options and Bandwidth Control parameters for locations versus sub-locations; however, these parameters align with the options available in the Zscaler portal. For additional information about Zscaler Gateway Options and Bandwidth Control parameters, see https://help.zscaler.com/zia/configuring-locations.
Table 6. Zscaler Gateway Options and Bandwidth Control Parameters Options
Option Description
Gateway Options for Location/Sub-Location
Use XFF from Client Request Enable this option when the location uses proxy chaining to forward traffic; this allows the service to discover the client IP address from the X-Forwarded-For (XFF) headers inserted by the on-premises proxy server. The XFF header identifies the client IP address, which the service uses to determine the client’s sub-location. Using the XFF headers, the service can apply the appropriate sub-location policy to the transaction. When users turn on the Enable IP Surrogate option for the location or sub-location, the system applies the appropriate user policy to the transaction. When the service forwards the traffic to its destination, it removes the original XFF header. It replaces it with an XFF header that contains the IP address of the client gateway (the organization’s public IP address), ensuring that the organization's internal IP addresses are never exposed externally.
Note: The Orchestrator restricts this Gateway option to the parent Location level.
Enable Caution If Authentication remains inactive, enable this feature to display a caution notification for unauthenticated traffic.
Enable AUP If Authentication remains inactive, enable this feature to display an Acceptable Use Policy (AUP) for unauthenticated traffic and require acceptance. Activating this feature triggers the following:
  • In the Custom AUP Frequency (Days) section, specify in days how frequently the Orchestrator displays the AUP.
  • A First Time AUP Behavior section appears, with the following settings:
    • Block Internet Access - Enable this feature to deactivate all access to the Internet, including non-HTTP traffic, until the user accepts the displayed AUP.
    • Force SSL Inspection - Enable this feature to make SSL Inspection enforce an AUP for HTTPS traffic.
Enforce Firewall Control Select this option to enable the service's firewall control.
Note: Before enabling this option, users must ensure that their Zscaler accounts have "Firewall Basic" subscriptions.
Enable IPS Control When Enforce Firewall Control is active, select this option to enable the service's IPS controls.
Note: Before enabling this option, users must ensure that their Zscaler accounts have "Firewall Basic" and "Firewall Cloud IPS" subscriptions.
Authentication Activating this option enforces service authentication for the Location or Sub-location.
IP Surrogate When Authentication is active, select this option if users want to map users to device IP addresses.
Idle Time for Dissociation When IP Surrogate is active, specify how long after a completed transaction, the service retains the IP address-to-user mapping. Users can specify the Idle Time for Dissociation in Mins (default), or Hours, or Days.
  • If the user selects the unit as Mins, the allowable range is from 1 through 43200.
  • If the user selects the unit as Hours, the allowable range is from 1 through 720.
  • If the user selects the unit as Days, the allowable range is from 1 through 30.
Surrogate IP for Known Browsers Enable this option to use the existing IP address-to-user mapping (acquired from the surrogate IP) to authenticate users sending traffic from known browsers.
Refresh Time for re-validation of Surrogacy When Surrogate IP for Known Browsers is active, specify the length of time that the Zscaler service can use IP address-to-user mapping for authenticating users sending traffic from known browsers. After the defined period of time elapses, the service will refresh and revalidate the existing IP-to-user mapping so that it can continue to use the mapping for authenticating users on browsers. Users can specify the Refresh Time for re validation of Surrogacy in minutes (default), or hours, or days.
  • If the user selects the unit as Mins, the allowable range is from 1 through 43200.
  • If the user selects the unit as Hours, the allowable range is from 1 through 720.
  • If the user selects the unit as Days, the allowable range is from 1 through 30.
Bandwidth Control Options for Location
Bandwidth Control Enable this option to enforce bandwidth controls for the location., and then specify the maximum bandwidth limits for Download (Mbps) and Upload (Mbps). All sub-locations will share the bandwidth limits assigned to this location.
Download When Bandwidth Control is active, specify the maximum bandwidth limits for Download in Mbps. The allowable range is from 0.1 through 99999.
Upload When Bandwidth Control is active, specify the maximum bandwidth limits for Upload in Mbps. The allowable range is from 0.1 through 99999.
Bandwidth Control Options for Sub-Location (if Bandwidth Control is enabled on Parent Location)
Figure 13. Edit Bandwidth Control Options for Sub-location
Note: The Orchestrator enables specific bandwidth control options for Sub-locations only when the parent Location has bandwidth control active. If the parent Location lacks active bandwidth control, the Sub-location provides the same standard options as a Location (Bandwidth Control, Download, and Upload).
Use Location Bandwidth Enabling bandwidth control on the parent Location allows the selection of this option, which applies the parent's download and upload maximum bandwidth limits to the Sub-location.
Override Select this option to enable bandwidth control on the sub-location and then specify the maximum bandwidth limits for Download (Mbps) and Upload (Mbps). The Sub-location uses this dedicated bandwidth exclusively and does not share it with other Sub-locations.
Disabled Select this option to exempt the traffic from any Bandwidth Management policies. Sub-location with this option can only use up to a maximum of available shared bandwidth at any given time.

Limitations

  • In release 4.5.0, the Orchestrator automatically saves an 'Other' Sub-location upon the creation of any new Sub-location. Earlier Orchestrator versions did not save the Zscaler 'Other' Sub-location. After upgrading the Orchestrator to release 4.5.0, the system automatically imports the 'Other' sub-location only after the user creates a new normal (non-'Other') sub-location using automation.
  • Zscaler Sub-locations cannot have overlapping IP addresses (subnet IP ranges). Attempting to edit (add, update, or delete) multiple Sub-locations with conflicting IP addresses may cause the automation to fail.
  • Users cannot update the bandwidth of Location and Sub-location at the same time.
  • Sub-locations support the Use Location Bandwidth option only when users enable bandwidth control on the parent location. When the user turns off the Location bandwidth control on a Parent Location, the Orchestrator does not proactively check or update the Sub-location bandwidth control option.

Configure Business Policies with Cloud Security Services

Users can create business policies to redirect the traffic to a Cloud Security Service.

For additional information on business policies, see Create Business Policy Rule.
  1. In the SD-WAN service of the Enterprise portal, select Configure > Profiles .
  2. Select a profile from the list and select Business Policy.
  3. Under Configure Business Policy > Business Policy Rules , select +ADD to display Add Rule.
  4. Enter a name for the business rule and select the IP version.
  5. Select Match, and then select the Match options to match the traffic.
  6. Select Action and from the Network Service menu, select Internet Backhaul and select a Cloud Security Service. It is necessary to associate the cloud security service to the Profile before selecting it.
    Figure 14. Add a Business Policy Rule
  7. Select other actions as required, and then click OK.

    The business policies for a Profile automatically apply to all the Edges associated with the Profile. If required, users can create additional business policies specific to the Edges.

    1. Navigate to Configure > Edges , and then select an Edge. Select Business Policy.
    2. Under Configure Business Policy > Business Policy Rules , select +ADD to display Add Rule.
    3. Define the rule with cloud security service associated with the Edge.

    The Business Policy tab of the Edge displays the policies from the associated profile along with the policies specific to the Edge.

Monitor Cloud Security Services

Users can view the details of Cloud Security Services (CSS) configured for the Enterprise from the Monitor > Network Services screen.

To monitor the cloud security service sites:

  1. In the SD-WAN service of the Enterprise portal, select Monitor > Network Services to display Network Services.
  2. Select the Cloud Security Service Sites to view all the CSS configured for the Enterprise along with the following configuration details.
    Figure 15. Monitor Cloud Security Service Site

     

    Table 7. Cloud Security Service - Options and Descriptions
    Option Description
    Name The name of the CSS provider.
    Type The type of the CSS provider.
    Public IP The Public IP address of the CSS provider.
    Status The overall status of the CSS provider:
    • White- Specifies two possible states:
      • ALL_STANDBY- A CSS provider enters this state once all its associated tunnels transition to STANDBY mode.
      • UNKNOWN- The CSS provider enters this state if the system fails to determine its overall status.
    • Green- The CSS provider is in ALL_UP state if all the tunnels associated with the CSS provider are UP.
    • Red- The CSS provider is in ALL_DOWN state if all the tunnels associated with the CSS provider are DOWN.
    • Amber- The CSS provider is in PARTIAL state if the tunnels associated with the CSS provider are partially UP, DOWN, or in STANDBY mode.
    Tunnel Status The status of tunnels created from the CSS provider from different Edges:
    • White- Specifies two possible states:
      • UNKNOWN- The tunnel enters this state when the tunnel remains unestablished.
      • NOT ENABLED- The tunnel enters this state when the configuration disables it.
    • Gray- The tunnel associated with the CSS provider is in STANDBY mode.
    • Green- Specifies two possible states:
      • ALL_UP- All the tunnels associated with the CSS provider are UP.
      • UP- A specific tunnel associated with the CSS provider is UP.
    • Red- Specifies two possible states:
      • ALL_DOWN- All the tunnels associated with the CSS provider are DOWN.
      • DOWN- A specific tunnel associated with the CSS provider is DOWN.
      The numbers that appear on the Tunnel Status and Service Status icons signify the number of Edges associated with that state for the respective CSS provider.
    Service Status The status of the external service as recorded by each Edge:
    • Green- The Layer 7 (L7) Health status of external service is UP.
    • Red- The L7 Health status of external service is DOWN.
    • Red- The L7 Health status of external service is DOWN due to one of the following reasons:
      • The Zen service does not respond to 'N' (Default = 3) consecutive HTTP probe messages.
      • The HTTP response (200 OK) time exceeds the set time (Default = 300 milliseconds).
      • The Zen server responds with 4xx HTTP error code.
    • Amber- The L7 Health status of external service is DEGRADED if the HTTP load time exceeds 'N' seconds (Default = 3 seconds).
    • Gray- The L7 Health status of external service is UNKNOWN.
    State Changed Time The date and time when the state changes.
    Deployment Status Deployment status of the CSS provider.

     

  3. Select a CSS provider name to view the related state change events.
    Figure 16. Review Related State Change Events
  4. Select View in the Deployment Status column to view the deployment status of the CSS provider.
    Figure 17. Cloud Security Service Automated Deployment Status
    The following are the seven different states for an Edge action:
    • Pending Location - The Edge action remains in this state until the system creates the Zscaler location. This state is only applicable for Sub-location Edge actions.
    • Pending - The Edge action is in this state while it waits for a backend worker process to pick it up and begin processing.
    • In Progress - The Edge action is in this state after a backend worker process picks up the Edge action and begins working on it.
    • Completed - The Edge action is in this state if the Edge completes the task.
    • Failed - The Edge action is in this state if the system encounters an error.
    • Timed Out - The Edge action is in this state if it takes more than the expected amount of time to complete the Edge action task.
    • Pending Delete - The Edge action is in this state if it is pending deletion.
      Note: Currently, the Pending Location and Pending Delete states are non-functional.
  5. Select Details to view the Event details.
    Users can also view the Layer 7 (L7) health check statistics for Cloud Security Service from the Monitor > Edges screen.

Monitor Cloud Security Service Events

Users can view the events related to cloud security services from the Monitor > Events screen.

In the SD-WAN service of the Enterprise portal, select Monitor > Events .

To view the events related to cloud security service sites, use the Search and Filter options. Select Filter and to filter either by the Event or by the Message column.

Figure 18. Monitor Cloud Security Service Events

The below table includes the Enterprise events which help track various Edge actions related to CSS deployment, Location and Sub-location automation.

Table 8. Enterprise Events
Events Description
Call made to external API The Edge made an API call to some external service.
CLOUD_SECURITY_PROVIDER_ADDED The Edge added a new CSS provider.
CLOUD_SECURITY_PROVIDER_UPDATED The Edge updated a new CSS provider.
CLOUD_SECURITY_PROVIDER_REMOVED The Edge removed a CSS provide.
Cloud Security Service site creation enqueued The Edge enqueued a CSS site creation task.
Cloud Security Service site update enqueued The Edge enqueued a CSS site update task.
Cloud Security Service site deletion enqueued The Edge enqueued a CSS site deletion task.
Network Service created The Edge created a CSS site.
Network Service updated The Edge updated a CSS site.
Network Service deleted The Edge deleted a CSS site.
CSS tunnels are up The CSS paths are UP. The traffic routes through CSS based on the configured Business policy rules.
All CSS tunnels are down The CSS paths are DOWN.
Edge Non SD-WAN Destination tunnel up The tunnel is UP for the Edge.
Edge Non SD-WAN Destination tunnel down The tunnel is DOWN for the Edge.
Zscaler Location creation enqueued The Edge enqueued an action to create a location.
Zscaler Location update enqueued The Edge enqueued an action to update a location.
Zscaler Location deletion enqueued The Edge enqueued an action to delete a location.
Zscaler Location object created The Edge created a Zscaler location object.
Zscaler Location object updated The Edge enqueued an action to update a sub-location.
Zscaler Location object deleted The Edge enqueued an action to delete a sub-location.
Zscaler Sub Location creation enqueued The Edge enqueued an action to create a sub-location.
Zscaler Sub Location update enqueued The Edge enqueued an action to update a sub-location.
Zscaler Sub Location deletion enqueued The Edge enqueued an action to delete a sub-location.
Zscaler Sub Location object created The Edge created a Zscaler Sub-location object.
Zscaler Sub Location object updated The Edge updated a Zscaler Sub-location object.
Zscaler Sub Location object deleted The Edge deleted a Zscaler Sub-location object.