Cloud Security Services
Cloud Security Service (CSS) is a cloud-hosted security service that protects an Enterprise branch and/or data center. The security services include firewalls, URL filtering, and other such services.
In CSS, define and configure a cloud security service instance and establish a secure tunnel directly from the Edge to the CSS.
- Simplifies configuration.
- Saves link bandwidth costs by offloading non-enterprise traffic to the Internet.
- Protects branch sites from malicious traffic by redirecting Internet traffic to a cloud security service.
Configure a Cloud Security Service
Configure Automatic Tunnels from SD-WAN Edge to Zscaler

Configure Manual Tunnels from SD-WAN Edge to Zscaler

Configure Cloud Security Services for Profiles
- Users must have access permission to configure Network Services.
- The Orchestrator version must be 3.3.x or above.
- Users must configure CSS Gateway endpoint IPs and FQDN credentials in the third party CSS.
- Redirect only web traffic to the cloud security service.
- Redirect all Internet-bound traffic to the cloud security service.
- Redirect traffic based on business policy settings. This option is available only from release 3.3.1. If users choose this option, then the other two options are no longer available.
For new Profiles (release 3.3.1 or later), the Business Policy settings redirect the traffic by default. See Configure Business Policies with Cloud Security Services.
Configure Cloud Security Services for Edges
To override the CSS configuration for a specific Edge, perform the following steps:
Manual Zscaler CSS Provider Configuration for Edges
When configuring an IPsec tunnel manually, users must provide a Fully Qualified Domain Name (FQDN) and Pre-Shared Key (PSK) in addition to the inherited attributes.

Manual GRE tunnel configuration requires manually setting the GRE tunnel parameters for the WAN interface designated as the GRE tunnel source. Follow the steps below to complete the configuration.
Automated Zscaler CSS Provider Configuration for Edges
- IPsec/GRE Tunnel Automation
- Zscaler Location/Sub-Location Configuration
IPsec/GRE Tunnel Automation
Zscaler Location and Sub-Location Configuration
- Verify that the Edge has established the tunnel and has automatically created the location. The Orchestrator enables Sub-location creation only after users configure the VPN credentials or GRE options for the Edge. Review the sub-location features and limitations before beginning the configuration. See https://help.zscaler.com/zia/understanding-sublocations.
- Match the Cloud Subscription to the one used during the Automatic CSS set up.
To update the Location or create Sub-locations for the selected Edge, perform the following steps:
Configure Zscaler Gateway Options and Bandwidth Control

Configure the Gateway options and Bandwidth controls for the Location and Sub-location, as needed, and select Save Changes.
| Option | Description |
|---|---|
| Gateway Options for Location/Sub-Location | |
| Use XFF from Client Request | Enable this option when the location uses proxy chaining to forward traffic; this allows the service to discover the client IP address from the X-Forwarded-For (XFF) headers inserted by the on-premises proxy server. The XFF header identifies the client IP address, which the service uses to determine the client’s sub-location. Using the XFF headers, the service can apply the appropriate sub-location policy to the transaction. When users turn on the Enable IP Surrogate option for the location or sub-location, the system applies the appropriate user policy to the transaction. When the service forwards the traffic to its destination, it removes the original XFF header. It replaces it with an XFF header that contains the IP address of the client gateway (the organization’s public IP address), ensuring that the organization's internal IP addresses are never exposed externally.
Note: The Orchestrator restricts this Gateway option to the parent Location level.
|
| Enable Caution | If Authentication remains inactive, enable this feature to display a caution notification for unauthenticated traffic. |
| Enable AUP | If Authentication remains inactive, enable this feature to display an Acceptable Use Policy (AUP) for unauthenticated traffic and require acceptance. Activating this feature triggers the following:
|
| Enforce Firewall Control | Select this option to enable the service's firewall control.
Note: Before enabling this option, users must ensure that their Zscaler accounts have "Firewall Basic" subscriptions.
|
| Enable IPS Control | When Enforce Firewall Control is active, select this option to enable the service's IPS controls.
Note: Before enabling this option, users must ensure that their Zscaler accounts have "Firewall Basic" and "Firewall Cloud IPS" subscriptions.
|
| Authentication | Activating this option enforces service authentication for the Location or Sub-location. |
| IP Surrogate | When Authentication is active, select this option if users want to map users to device IP addresses. |
| Idle Time for Dissociation | When IP Surrogate is active, specify how long after a completed transaction, the service retains the IP address-to-user mapping. Users can specify the Idle Time for Dissociation in Mins (default), or Hours, or Days.
|
| Surrogate IP for Known Browsers | Enable this option to use the existing IP address-to-user mapping (acquired from the surrogate IP) to authenticate users sending traffic from known browsers. |
| Refresh Time for re-validation of Surrogacy | When Surrogate IP for Known Browsers is active, specify the length of time that the Zscaler service can use IP address-to-user mapping for authenticating users sending traffic from known browsers. After the defined period of time elapses, the service will refresh and revalidate the existing IP-to-user mapping so that it can continue to use the mapping for authenticating users on browsers. Users can specify the Refresh Time for re validation of Surrogacy in minutes (default), or hours, or days.
|
| Bandwidth Control Options for Location | |
| Bandwidth Control | Enable this option to enforce bandwidth controls for the location., and then specify the maximum bandwidth limits for Download (Mbps) and Upload (Mbps). All sub-locations will share the bandwidth limits assigned to this location. |
| Download | When Bandwidth Control is active, specify the maximum bandwidth limits for Download in Mbps. The allowable range is from 0.1 through 99999. |
| Upload | When Bandwidth Control is active, specify the maximum bandwidth limits for Upload in Mbps. The allowable range is from 0.1 through 99999. |
Bandwidth Control Options for Sub-Location (if Bandwidth Control is enabled on Parent Location)
![]() Note: The Orchestrator enables specific bandwidth control options for Sub-locations only when the parent Location has bandwidth control active. If the parent Location lacks active bandwidth control, the Sub-location provides the same standard options as a Location (Bandwidth Control, Download, and Upload).
|
|
| Use Location Bandwidth | Enabling bandwidth control on the parent Location allows the selection of this option, which applies the parent's download and upload maximum bandwidth limits to the Sub-location. |
| Override | Select this option to enable bandwidth control on the sub-location and then specify the maximum bandwidth limits for Download (Mbps) and Upload (Mbps). The Sub-location uses this dedicated bandwidth exclusively and does not share it with other Sub-locations. |
| Disabled | Select this option to exempt the traffic from any Bandwidth Management policies. Sub-location with this option can only use up to a maximum of available shared bandwidth at any given time. |
Limitations
- In release 4.5.0, the Orchestrator automatically saves an 'Other' Sub-location upon the creation of any new Sub-location. Earlier Orchestrator versions did not save the Zscaler 'Other' Sub-location. After upgrading the Orchestrator to release 4.5.0, the system automatically imports the 'Other' sub-location only after the user creates a new normal (non-'Other') sub-location using automation.
- Zscaler Sub-locations cannot have overlapping IP addresses (subnet IP ranges). Attempting to edit (add, update, or delete) multiple Sub-locations with conflicting IP addresses may cause the automation to fail.
- Users cannot update the bandwidth of Location and Sub-location at the same time.
- Sub-locations support the Use Location Bandwidth option only when users enable bandwidth control on the parent location. When the user turns off the Location bandwidth control on a Parent Location, the Orchestrator does not proactively check or update the Sub-location bandwidth control option.
Configure Business Policies with Cloud Security Services
Users can create business policies to redirect the traffic to a Cloud Security Service.
Monitor Cloud Security Services
To monitor the cloud security service sites:
Monitor Cloud Security Service Events
Users can view the events related to cloud security services from the screen.
In the SD-WAN service of the Enterprise portal, select .
To view the events related to cloud security service sites, use the Search and Filter options. Select Filter and to filter either by the Event or by the Message column.

The below table includes the Enterprise events which help track various Edge actions related to CSS deployment, Location and Sub-location automation.
| Events | Description |
|---|---|
| Call made to external API | The Edge made an API call to some external service. |
| CLOUD_SECURITY_PROVIDER_ADDED | The Edge added a new CSS provider. |
| CLOUD_SECURITY_PROVIDER_UPDATED | The Edge updated a new CSS provider. |
| CLOUD_SECURITY_PROVIDER_REMOVED | The Edge removed a CSS provide. |
| Cloud Security Service site creation enqueued | The Edge enqueued a CSS site creation task. |
| Cloud Security Service site update enqueued | The Edge enqueued a CSS site update task. |
| Cloud Security Service site deletion enqueued | The Edge enqueued a CSS site deletion task. |
| Network Service created | The Edge created a CSS site. |
| Network Service updated | The Edge updated a CSS site. |
| Network Service deleted | The Edge deleted a CSS site. |
| CSS tunnels are up | The CSS paths are UP. The traffic routes through CSS based on the configured Business policy rules. |
| All CSS tunnels are down | The CSS paths are DOWN. |
| Edge Non SD-WAN Destination tunnel up | The tunnel is UP for the Edge. |
| Edge Non SD-WAN Destination tunnel down | The tunnel is DOWN for the Edge. |
| Zscaler Location creation enqueued | The Edge enqueued an action to create a location. |
| Zscaler Location update enqueued | The Edge enqueued an action to update a location. |
| Zscaler Location deletion enqueued | The Edge enqueued an action to delete a location. |
| Zscaler Location object created | The Edge created a Zscaler location object. |
| Zscaler Location object updated | The Edge enqueued an action to update a sub-location. |
| Zscaler Location object deleted | The Edge enqueued an action to delete a sub-location. |
| Zscaler Sub Location creation enqueued | The Edge enqueued an action to create a sub-location. |
| Zscaler Sub Location update enqueued | The Edge enqueued an action to update a sub-location. |
| Zscaler Sub Location deletion enqueued | The Edge enqueued an action to delete a sub-location. |
| Zscaler Sub Location object created | The Edge created a Zscaler Sub-location object. |
| Zscaler Sub Location object updated | The Edge updated a Zscaler Sub-location object. |
| Zscaler Sub Location object deleted | The Edge deleted a Zscaler Sub-location object. |








