Tooling

The public Zscaler tools: what each one answers, and what it does not

Zscaler publishes a number of free check pages that save real time in day-to-day support. Most people only know the ones they happened to stumble across. This overview states, for each tool, which question it answers and where it stops.

Eight tools

Each one answers exactly one question.

The order follows the support workflow: first establish whether the traffic runs through Zscaler at all, then assess the address, then the file, then the cloud.

Is my traffic going through Zscaler right now?

ip.zscaler.com

Shows the gateway IP and the full HTTP headers of your own request. The first tool to reach for when someone asks whether the traffic passes the proxy at all.

How risky is this address before anyone clicks it?

Zulu URL Risk Analyzer

Combines content, page and host scoring into a single risk rating. Useful for the suspicious link in a ticket. The page takes noticeably long to answer, at times more than twenty seconds.

Which URL category does Zscaler assign to an address?

Site Review

The place to answer "why is this site blocked?", and the place to file an objection against a categorisation.

What does the sandbox say about this file?

Cloud Sandbox File Check

Submit files up to 50 MB against your own organisation’s sandbox policies. Requires that your traffic runs through Zscaler.

Is it us, or is it the cloud?

Zscaler Trust

Operational status and incident notices per Zscaler cloud. The authoritative source when an outage is in question.

Which IP ranges, hostnames and ports does the firewall need to know?

Zscaler Config

The configuration data per cloud. The basis for firewall allowances and for PAC files.

What is known about this campaign?

ThreatLabz

Zscaler’s threat research: analyses, campaign reports and background on current attack patterns.

Where is it written how to do this in the Zscaler views?

Zscaler Help

The product documentation. For every step inside the ZIA and ZPA views, the authoritative source.

Where these tools stop

Eight separate findings are not yet a case.

Each of these tools answers its own question well. The ticket, however, asks a different one: what happened for this user, on this device, at this moment? Answering that means bringing the findings together, and that is where CentaurNexus starts. The optimal complement to your Zscaler security stack: easier, faster and more convenient to run.

  • Read a ZCC log instead of ten thousand lines: the ZCC Log Analyzer sorts findings by severity and names the next step for each. Free, no sign-up, in the browser.
  • Check a PAC file without reading JavaScript: the PAC Tester shows which rule applies to a test URL and whether the result is DIRECT or PROXY.
  • See the whole case: how user, device and connectivity context come together without broad admin rights is described on Zscaler help desk support, no admin access.
Related

A German glossary covers the terms these tools use.

Explanations for ZPA, ZIA, ZDX and ZTNA are available in German.