Zscaler & Zero Trust operations glossary ยท Access & traffic

What is Source IP Anchoring (SIPA)?

Definition

Source IP Anchoring, or SIPA for short, is a Zscaler feature that sends users' outbound internet traffic out through fixed IP address ranges assigned to the organisation. Instead of the exit point varying with the nearest Zscaler data centre, destination systems consistently see the same company-assigned IP origin for that traffic. This matters most when external services restrict access by fixed IP address, for example partner portals or applications with IP whitelisting.

Source IP Anchoring in detail

Without SIPA, the visible exit point of Zscaler traffic can change with the user's location and the Zscaler data centre in use, which is unproblematic for most internet destinations. For destination systems that restrict access through an IP whitelist, though, a changing source IP is an obstacle. Technically, SIPA relies on ZIA forwarding policies that route selected traffic through a ZPA App Connector; the visible source IP is then that of the App Connector. Internal destinations are reached over the intranet, external ones over the internet. Using it does not require a separate Private Access licence, but it does require its own Source IP Anchoring subscription; the Real Time Streaming Protocol (RTSP) is not supported.

Setup is usually targeted at the user groups or destinations that need a fixed source IP, not applied blanket-style across all company traffic.

Why Source IP Anchoring matters in Zscaler operations

When SIPA is missing for a user segment that actually needs a fixed source IP, access to IP-restricted destination systems fails, even though the underlying Zscaler policy allows it. To users, this looks like a fault in the destination application, when the cause actually sits in the network part of the configuration.

Without knowledge of SIPA, support finds cases like this hard to spot, because neither the application nor the Zscaler policy looks faulty at first glance.

Common sources of error

Source IP Anchoring in practice: what CentaurNexus contributes

In Connectivity Triage Map, CentaurNexus brings together the ZDX chain and policy status, and classifies a reported access fault in plain language, whether the cause sits more with the device, the network or the Zscaler side, instead of leaving support to guess. For network-side causes such as a missing or misapplied SIPA configuration, that helps hand the case to administration in a more targeted way, even though the configuration itself is still reviewed there. What root cause diagnosis for access faults looks like in practice is shown in the guide Is it Zscaler or the Wi-Fi? Root cause analysis in minutes.

See in the live demo how Connectivity Triage Map classifies network-side access causes.Watch the live demo

Related terms

Frequently asked questions about Source IP Anchoring

What is Source IP Anchoring?

Source IP Anchoring, or SIPA for short, is a Zscaler feature that sends users' outbound internet traffic out through fixed IP address ranges assigned to the organisation. As a result, destination systems always see the same company-assigned IP origin, regardless of which location a user is actually connecting from.

What is Source IP Anchoring needed for?

Many external services, such as partner systems, banking portals or SaaS applications with IP whitelisting, only allow access from known IP addresses. Source IP Anchoring makes sure Zscaler traffic comes from a defined, predictable IP range that such destination systems can allow.

Why Source IP Anchoring matters in Zscaler operations

If SIPA is misconfigured or not active for the right user groups, access to IP-restricted destination systems fails even though the Zscaler policy itself is correct. Cases like this look like an application fault to users, but the cause sits in the network part of the configuration.

Does Source IP Anchoring apply to all of an organisation's traffic?

The scope depends on the specific configuration in the tenant and is typically set up for particular user groups or destination systems with IP requirements, not applied blanket-style to all internet traffic.

How does Source IP Anchoring differ from a regular Zscaler internet exit?

Without SIPA, the exit point of traffic can vary with the nearest Zscaler data centre. With SIPA, the visible source IP stays constant for particular destinations, even when the user connects from different locations.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.