List view
Integrations
Integrations
Applications
Applications
App-specific Handling
App-specific Handling
test
test
Zscaler Integration
Configuring your Zscaler to work with Lumia is easy!
To connect your Zscaler tenant, Lumia will share your unique certificate file (
.pem) and proxy URL with you.Before starting, make sure your SASE can handle HTTP/3 (QUIC) traffic. Since Zscaler cannot process QUIC yet, this usually means blocking QUIC.
Step 1: Trusting Lumia’s CA Certificate
- Login to the Zscaler admin dashboard (
admin.zscaler.net) - Click on Administration, then on Root Certificates
- Click on Add Root Certificate
- In the Name field, enter Lumia Forward CA;
In the Type field, select Proxy Chaining.
- Click Choose File and select the Lumia provided certificate file (
.pem), then click on Save
Step 2: Configuring a Forwarding Proxy
- Open the Administration menu again, and click on Proxies & Gateways
- Click on Add Proxy
- In the Proxy name field, enter Lumia Forward Proxy
In the IP Address / FQDN field, enter the Lumia provided Proxy URL
In the Port field, enter 8080
In the Proxy’s Root Certificate field, select the Lumia Forward CA you defined ealrier
- Enable Insert X-Authenticated-User and Enable Base 64 Encoding for X-Authenticated-User, then click on Save
- Click on the Proxy Gateways tab
- Click on Add Gateway for Proxies
- In the Gateway Name field, enter Lumia Forward Proxy
Disable Fail Close
In the Primary Proxy field, select the Lumia Forward Proxy you defined earlier
Then click on Save
Step 3: Creating a URL Category
Warning: The scope of any Zscaler URL Category applies to the entire tenant. If your current Zscaler policies depend on URL categories, make sure that creating the Lumia category does not invalidate any existing rules. We address this by using the “URLs Retaining Parent Category” option (see below). If you’re unsure, please contact us.
- Click on Administration in the left main menu, then select URL Categories
- Click on Add URL Category
- In the Name field, enter Lumia Forward Category
- In the URLs Retaining Parent Category, enter:
chatgpt.com claude.ai
(We will add the full list after the technical sanity check is complete.)
Then click on Save.
Step 4: Creating a Lumia Forwarding Policy
- In the left menu, select Policy, then click on Forwarding Control
- Click Add Forwarding Rule
- Enter a name for the Rule
In the Forwarding Method field, select Proxy Chaining
- Click on Destination, then on URL Category
- Select the Lumia Forward Category you previously created
- In the Forward to Proxy Gateway, select the Lumia Forward Proxy you previously created
- Click on Save
Finally, don’t forget to Activate the changes 🙂
That’s it, you can now enjoy using Lumia!
Step 5: Create SSL Inspection policy for the Lumia forwarded domains
- Navigate to Policy → SSL Inspection
- Click Add SSL Inspection Rule:
- Forwarding Gateways: Lumia Forward Proxy
- Enable HTTP/2: Disabled
- Click Save
Important:
Decryption policies are evaluated top-down. We strongly recommend placing the Lumia decryption rule at the top of the inspect rulebase and ensuring no other inspect rule overrides it for traffic forwarded to Lumia.
Decryption policies are evaluated top-down. We strongly recommend placing the Lumia decryption rule at the top of the inspect rulebase and ensuring no other inspect rule overrides it for traffic forwarded to Lumia.
[Optional] Exempting Lumia Domains from SSL Inspection
This step is required only if your tenant uses both Zscaler forwarding and PAC forwarding together.
If Lumia hasn’t specifically requested this exception, there’s no need to add it.
If Lumia hasn’t specifically requested this exception, there’s no need to add it.
- Go to Administration → Destination IPv4 Groups, then click on Add Destination IPv4 Group
- In the Name field, enter Lumia FQDN.
In the Type field, select Wildcard FQDN.
In the Wildcard FQDN field, enter*.lumiasecurity.com.
Click Save.
- Go to Policy → SSL Inspection
We will now create a Do Not Inspect rule for the Lumia URLs.
Since rules are evaluated from top to bottom, it’s important to place the new rule before the relevant Inspect rule.
Click Add SSL Inspection Rule.
Set the Rule Order so that it applies before the inspection rule.
In the Destination Groups field, select Lumia FQDN.
- In the Action field, select Do Not Inspect, then select Bypass Other Policies.