Zscaler Integration

Zscaler Integration


This guide will walk you through integrating your Zscaler tenant with Lumia using Proxy Chaining.
This integration allows Zscaler to route traffic from AI applications through Lumia’s engine for real-time inspection and governance.
Before you begin
To complete this integration, ensure you have the following details provided by your Lumia representative:
  • Your unique Lumia CA Certificate (.pem)
  • Your Lumia Proxy URL
Prerequisite: Block HTTP/3 (QUIC)
Lumia requires AI traffic to flow through standard HTTPS for full inspection. Since AI applications often attempt to use the QUIC protocol (which can bypass proxy inspection), QUIC must be blocked in your Zscaler environment.
To get full visibility:
  • Ensure your Zscaler deployment is using Tunnel 2.0 (required to identify and block QUIC traffic).
  • Follow Zscaler’s documentation to disable and block QUIC. If QUIC is not blocked, AI interactions may bypass Lumia, resulting in a loss of visibility.

Installation Steps

đź’ˇ
Note: Zscaler is currently updating its Admin Console UI. If your interface looks different from the steps below, menu locations may vary slightly.

Step 1: Trust Lumia’s CA Certificate

  1. Login to the Zscaler Admin Console (admin.zscaler.net).
  2. Click Administration, then Root Certificates.
A screenshot of a computer AI-generated content may be incorrect.
  1. Click on Add Root Certificate.
A screenshot of a computer AI-generated content may be incorrect.
  1. Fill in the following fields:
    • Name: Enter Lumia Forward CA.
    • Type: Select Proxy Chaining.
Screens screenshot of a computer AI-generated content may be incorrect.
  1. Click Choose File and select the Lumia provided certificate file (.pem), then click on Save.
A screenshot of a computer AI-generated content may be incorrect.

Step 2: Configure a Forwarding Proxy

  1. Open the Administration menu again, and click Proxies & Gateways.
A screenshot of a computer AI-generated content may be incorrect.
  1. Click Add Proxy.
A screenshot of a computer AI-generated content may be incorrect.
  1. Configure the following:
    • Proxy Name: Enter Lumia Forward Proxy.
    • IP Address / FQDN: Enter your unique Lumia Proxy URL.
    • Port: 8080.
    • Proxy’s Root Certificate: Select the Lumia Forward CA you created in Step 1.
A screenshot of a computer AI-generated content may be incorrect.
  1. Enable Insert X-Authenticated-User and Enable Base 64 Encoding for X-Authenticated-User.
  2. Click Save.
Screens screenshot of a computer AI-generated content may be incorrect.
  1. Switch to the Proxy Gateways tab.
A screenshot of a computer AI-generated content may be incorrect.
  1. Click Add Gateway for Proxies.
A screenshot of a computer AI-generated content may be incorrect.
  1. Configure the following:
    • Gateway Name: Enter Lumia Forward Gateway.
    • Fail Close: Disable (This ensures that if the Lumia proxy is unreachable, user internet access will not be interrupted).
    • Primary Proxy: Select the Lumia Forward Proxy you just created.
notion image
  1. Click Save.

Step 3: Create a URL Category

đź’ˇ
Important: In this step, you will create a Lumia URL category. Please pay close attention to entering the domains specifically in the URLs Retaining Parent Category field. Entering them here, rather than in the standard URL field, ensures the domains stay in your existing categories while being added to Lumia. This keeps your current security policies fully active while adding Lumia’s protection.
If you have any concerns, please contact us.
  1. Click Administration in the left main menu.
  2. Select URL Categories.
A screenshot of a computer AI-generated content may be incorrect.
  1. Click Add URL Category.
A screenshot of a computer AI-generated content may be incorrect.
  1. Configure the following settings:
    • Name: Enter Lumia Forward Category.
    • URLs Retaining Parent Category: Enter the following domains:
      • chatgpt.com
      • claude.ai
    đź’ˇ
    Note: To ensure a smooth integration, start with these two domains only. Once the technical setup is verified, Lumia will provide you with the complete list of AI domains to be added.
  2. Click Save.
A screenshot of a computer AI-generated content may be incorrect.

Step 4: Enable SSL Inspection for the Lumia forwarded domains

  1. Navigate to Policy, then click SSL Inspection.
  2. Click Add SSL Inspection Rule.
  3. Configure the following:
    • Forwarding Gateways: Select Lumia Forward Gateway.
    • Enable HTTP/2: Set to Disabled.
  4. Click Save.
đź’ˇ
Note: Zscaler evaluates decryption policies in top-down order. We strongly recommend placing the Lumia decryption rule at the top of the inspect rulebase to ensure no other rules override it for traffic forwarded to Lumia.

Step 5: Create a Lumia Forwarding Policy

  1. In the left menu, Click Policy, then click Forwarding Control.
A screenshot of a computer AI-generated content may be incorrect.
  1. Click Add Forwarding Rule.
A screenshot of a computer AI-generated content may be incorrect.
  1. Enter the Rule Name: Lumia Forwarding Rule.
  2. In the Forwarding Method field, select Proxy Chaining.
notion image
  1. Click the Destination tab, then select URL Category.
A screenshot of a computer AI-generated content may be incorrect.
  1. Select the Lumia Forward Category you previously created.
A screenshot of a computer screen AI-generated content may be incorrect.
  1. In the Forward to Proxy Gateway field, select the Lumia Forward Gateway you previously created.
notion image
  1. Click Save.

Step 6: Exempt Lumia Domains from SSL Inspection (For PAC File Setups Only)

⚠️
Note: This step is required only if your tenant uses both Zscaler forwarding and PAC forwarding together.
If Lumia hasn’t specifically requested this exception, there’s no need to add it.
A. Create a Destination Group:
  1. Go to Administration then click Destination IPv4 Groups.
  2. Click Add Destination IPv4 Group.
notion image
  1. Configure the following settings:
    • Name: Enter Lumia FQDN Wildcard.
    • Type: Select Wildcard FQDN.
    • Wildcard FQDN: Enter *.lumiasecurity.com.
  2. Click Save.
notion image
B. Create the Bypass Rule:
⚠️
Important: We will now create a Bypass rule (”Do Not Inspect”) for the Lumia URLs. Since Zscaler evaluates rules from top to bottom, this new rule must be placed before the inspection rule created in Step 4 to ensure the bypass takes effect.
  1. Go to Policy, then click SSL Inspection.
  2. Click Add SSL Inspection Rule.
  3. Configure the following settings:
    • Rule Name: Enter Bypass Lumia FQDN Wildcard.
    • Rule Order: Set it so that it applies before the inspection rule.
    • Destination Groups: Select Lumia FQDN Wildcard.
notion image
  1. In the Action field, select Do Not Inspect, then select Bypass Other Policies.
  2. Click Save.
notion image

Step 7: Activate and Verify

  1. To apply all configurations, click the Activation icon in the top navigation menu of the Zscaler Admin Console, and select Activate.
  2. (Note: It may take a few minutes for the changes to propagate throughout the Zscaler network).
  3. Once activated, use the Integration Validator at https://check.lumiasecurity.com to confirm that your traffic is correctly routed and SSL inspection is active.

Next Step

If the validator confirms a successful connection, return to our Getting Started guide and proceed to Step 1.2: Verify Integration to confirm that logs are appearing in your Lumia Portal.
Â