Reader small image

You're reading from  Zscaler Cloud Security Essentials

Product typeBook
Published inJun 2021
PublisherPackt
ISBN-139781800567986
Edition1st Edition
Right arrow
Author (1)
Ravi Devarasetty
Ravi Devarasetty
author image
Ravi Devarasetty

Ravi Devarasetty is originally from India and came to the United States for his higher education. He started his IT career in embedded software development, moved into 24x7 network operations, later transitioned into secure web gateways, and now works in public cloud security. He likes constant learning, both through self-study and via mentoring relationships. He likes to tinker with technology and loves it when he is able to put the things he has learned toward creating a unique solution. He has experience working as a Zscaler solution deployment engineer as part of a Managed Security Service Provider (MSSP) and as a Zscaler consultant. He holds multiple Zscaler certifications, and is also certified in CISSP, CCSK, AlienVault, AWS, and Microsoft Azure.
Read more about Ravi Devarasetty

Right arrow

Chapter 6: Troubleshooting and Optimizing Your ZIA Solution

After learning how to architect a custom Zscaler Internet Access (ZIA) solution, it is time to put that solution into a day-to-day operation. To make the most out of the deployed ZIA solution, the enterprise administrator needs to take care of a few aspects.

Anyone who has been in any type of steady-state operation will almost immediately tell you that it involves working with trouble reports initiated either proactively created by a network monitoring tool or reactive tickets created by end users over the phone or through a web portal.

These trouble tickets are then routed to a generic help desk, where the associates need to know how to identify a potential Zscaler problem and engage the proper points of contact. For this reason, there needs to be a comprehensive and standardized troubleshooting process documented for the help desk. This documentation needs to include the various points of contact within the enterprise...

Technical requirements

Knowledge of operating system commands, such as command prompt, terminal, ping, and traceroute, is helpful to gain an understanding of the content in this chapter.

Setting up proactive ticketing and alerts

We have already mentioned that reactive tickets are usually created when end users call the help desk or via an online ticketing portal. In this section, we will look at the various ticketing and alerting options available with ZIA. First, let's begin with the native alerting mechanism offered by the ZIA Admin Portal.

ZIA alerts

The enterprise administrator can log in to the Admin Portal and then navigate to Administration > Alerts. On the first tab, Define Alerts, click on the + icon to add a new alert definition. The resulting pop-up window has the following options:

  • Status: Alerts can be in an Enabled or a Disabled state. As a best practice, it is good to start with a new alert definition in a disabled state until the administrator has had a chance to fine-tune the settings.
  • Alert Name: The administrator can select the specific event of interest from the drop-down menu list.
  • Alert Class: Based on the previous...

Producing reports for management review

From time to time, the enterprise administrator may be called upon by upper management to generate easy-to-understand reports that show whether the Zscaler ZIA solution is working optimally for the enterprise. ZIA Admin Portal makes it easy to create industry-standard and customized reports. Let's explore the built-in reports.

System-defined reports

ZIA Admin Portal offers several types of default, system-defined reports. The two most common choices are the Executive Report and the Industry Peer Comparison Report. Let's see what is in each type of report.

Executive Report

The executive report contains an overall security view of the enterprise in an HTML format. It shows the value derived from the ZIA service. It contains details such as how many security threats and/or company security policy violations were detected for the enterprise during a certain time frame.

After logging into the ZIA Admin Portal, the administrator...

Generating custom widgets for the ZIA Dashboard

As soon as the enterprise administrator logs into the ZIA Admin Portal, the Web Overview dashboard is displayed by default. This dashboard offers some predefined widgets. These widgets can be edited or deleted, and new custom widgets can be created. Let's take a look at that customization process.

Editing current widgets

The Dashboard page is loaded by default when an enterprise administrator logs into the ZIA Admin Portal so, there is no special navigation required after login. Current widgets on the dashboard can be edited by hovering the mouse near the top-right corner of the individual widget to reveal a pencil icon. Click on the pencil icon, and you will see two options presented there: Edit Widget and Remove. Clicking on Remove will ask for confirmation before proceeding with the deletion of this widget. Clicking on the Edit Widget will open a pop-up menu with the various options. We will discuss those options in the...

Creating a unified ZIA troubleshooting guide

Either through proactive alerting or reactive ticketing, trouble tickets eventually reach the help desk, and they must be worked upon to resolution. When the enterprise adopts a logical and consistent troubleshooting approach, the resolution time for these trouble tickets can be decreased, thus alleviating the pressure on the Zscaler enterprise administrator.

Basic troubleshooting

The basic information that should be gathered by a help desk associate applicable to many common scenarios is as follows.

Access to IP.zscaler.com

If the end user can log into their computer using domain credentials, they should be asked to open a company-approved internet browser and navigate to ip.zscaler.com. This can tell us if the end user is accessing the web using the ZIA service or through an alternate path. If the end user is not going through ZIA, this web page will say "The request received from you did not have an XFF header, so you...

Summary

In this chapter, we looked at the various built-in tools provided by the ZIA Admin Portal, by default, and customizable tools to suit the needs of the enterprise operations staff. They come in various forms such as Insights, Logs, Dashboards, Reports, and more.

We also looked at some of the most frequently seen troubles with the ZIA end users and how a streamlined troubleshooting approach can help the enterprise resolve them effectively.

In the next chapter, we will start addressing the Zero Trust Network Architecture (ZTNA) using Zscaler Private Access (ZPA).

Questions

As we conclude, here is a list of questions for you to test your knowledge regarding this chapter's material. You will find the answers in the Assessments section of the Appendix:

  1. ZIA Admin Portal dashboards cannot be customized by the enterprise administrators.

    a. True

    b. False

  2. Using the Logs option, the enterprise administrator can download the raw logs for the selected transaction criteria.

    a. True

    b. False

  3. User authentication issues occur due to the following reasons:

    a. End user errors

    b. Misconfiguration errors

    c. Provisioning errors

    d. None of the above

    e. All the above

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Zscaler Cloud Security Essentials
Published in: Jun 2021Publisher: PacktISBN-13: 9781800567986
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Ravi Devarasetty

Ravi Devarasetty is originally from India and came to the United States for his higher education. He started his IT career in embedded software development, moved into 24x7 network operations, later transitioned into secure web gateways, and now works in public cloud security. He likes constant learning, both through self-study and via mentoring relationships. He likes to tinker with technology and loves it when he is able to put the things he has learned toward creating a unique solution. He has experience working as a Zscaler solution deployment engineer as part of a Managed Security Service Provider (MSSP) and as a Zscaler consultant. He holds multiple Zscaler certifications, and is also certified in CISSP, CCSK, AlienVault, AWS, and Microsoft Azure.
Read more about Ravi Devarasetty