Alkira > Resources > Integrated Security and Network Services > Enhancing Cloud Security using Zscaler Integration with Alkira

Enhancing Cloud Security using Zscaler Integration with Alkira

Enhancing Cloud Security using Zscaler Integration with Alkira

In today’s rapidly evolving digital landscape, ensuring robust security for cloud-based applications and data is paramount. Alkira, a leader in cloud networking as a service, integrated with Zscaler, a renowned cloud security platform, to provide customers with enhanced security capabilities.Figure 1: Alkira Connectivity with Zscaler

Integration steps:

1. Retrieve ZIA Service Edge IPs: Customer can get the IPs for the closest ZIA PoPs to the Alkira CXP using the API (https://pac.zscalertwo.net/getvpnendpoints)

2. Configuration and Establishing Connectivity: Alkira Cloud Exchange Points (CXPs) establish secure tunnels to Zscaler Public Service Edges, facilitating seamless connectivity between Alkira and Zscaler’s security infrastructure.Figure 2: Alkira Portal – Zscaler Integration Configuration

3. Traffic Steering: User traffic is directed to ZIA using Alkira traffic policies based on the required 5-tuple match conditions to, which gives users ability to selectively send desired traffic flows to Zscaler and redirect other traffic flows to other NGFWs if needed.

Figure 3: Diagram showing selective traffic steering exampleFigure 4: Alkira Policy example for Traffic Steering

Validation:

Customers can hit the URL https://ip.zscaler.com from the resource they are trying to access the internet from to validate that the traffic is hitting Zscaler, and they should see an output similar to the one below.

Figure 5: Validating Zscaler connectivity

Alkira Benefits:

The integration of ZIA with Alkira enhances user experience in several key ways:

Simplified Deployment and Enhanced Resilience

By integrating Alkira with Zscaler, customers can enjoy streamlined deployment processes and bolstered network resilience. With this integration Alkira overcomes the tunnel limitation, customers no longer need to configure and add tunnels based on throughput needs manually. They just input the required throughput and Alkira takes care of the rest.Additionally, the health checks ensure seamless failover to Zscaler’s Points of Presence (PoPs) in case of network disruptions or failures, enhancing overall network reliability and minimizing downtime.

Selective Traffic Steering

Based on required match conditions, the customer can choose to send selective traffic to Zscaler, which provides flexibility in terms of what traffic needs to be inspected via Zscaler and what traffic needs to be inspected using other 3rd party NGFWs in the Alkira CXP.

Monitoring and Visibility

Alkira provides monitoring capabilities and visibility into all traffic that is going to traverse Zscaler. Users have rich visibility into the type of traffic is going to the ZIA service and also check BW utilization for that traffic.

Segmentation

Alkira segment represents a unique routing and policy space, maintaining isolation for workloads and traffic flows becomes seamless for customers. Because of this flexibility, the ZIA service is restricted to that unique segment and region within Alkira.

Conclusion

By leveraging Zscaler’s integration with Alkira, organizations can confidently embrace the benefits of cloud computing while ensuring the highest security and compliance standards.

Unlock the power of integrated cloud security with Alkira CSX and Zscaler. Experience enhanced protection, simplified management, and unparalleled peace of mind in your cloud journey.

About the Authors :    & 

You May Also Like

Alkira mobile app screens

Introducing the Alkira Mobile App: Network Visibility Wherever, Whenever

Enterprise networks are expected to run 24/7, and the teams responsible for them need visibility wherever work happens. Cloud environments, partner connections, security services, and provisioning workflows are constantly changing. When something needs attention, network and operations teams need a fast way to understand what happened, assess impact, and take the right next step. That...
Jacob Donovan
Simple diagram showing a network as a platform

The Network Needs To Be Part of Your AI Strategy

Enterprises are moving quickly on AI, but many are still running networking models designed for a slower, more centralized and static era. Today’s network has to connect clouds, data centers, campuses, branches, partner environments, and increasingly private AI infrastructure while enforcing consistent policy across all of it. That creates a new operational reality: every new...
Calvin Nguyen
Blue network shield checkmark illustration

Navigating DORA: Operational Resilience and Security by Design

The Digital Operational Resilience Act (DORA) is reshaping how financial institutions in the European Union manage operational risk related to information and communication technology (ICT). As the regulation takes effect, organizations must ensure that their critical ICT service providers support strong operational resilience, risk management, and oversight capabilities. For technology providers supporting financial institutions, this...
Misbah Rehman