A clearer path to zero trust.
Understand your traffic. Simplify your policies. Plan your next move.
One configuration. Two migration paths.
Convert supported policy rules into ZIA Terraform and ZPA application-import CSVs.
Choose your source
Single-VDOM exports with IPv4 address objects, groups, and explicit TCP/UDP services.
Choose your Zscaler output
Review & download
ZIA firewall policy
Download Terraform configuration for the official Zscaler provider. Supported rules are disabled; source order is retained among exported rules.
.tf.json · Apply through TerraformZPA application inventory
Download the application-import CSV. Add identity access policy and App Connector assignments in your tenant after import.
.csv · Import in the ZPA portalThese are tenant import formats. They do not replace an entire firewall config. NAT, VPN, inspection profiles, schedules, unresolved objects and broad destinations require manual migration.
Your conversion review will show every parsed rule, its destination product, and the reason for any exclusion.
1 data source connected
Grouped by destination & port
11.1K internet-bound records
3,800 private application records
Traffic at a glance
Where your network traffic is going
Your network. More potential.
Of 16,000 analyzed records, 69% are potential ZIA candidates and 24% are potential ZPA candidates. A phased pilot can help simplify internet access and introduce application-level private access. 1,100 records need further investigation before a migration decision.
Recommended next moves 3
A practical starting point for your Zscaler migration.