- 15 Oct 2023
- 2 Minutes to read
- Print
- DarkLight
- PDF
Zscaler Web Security
- Updated on 15 Oct 2023
- 2 Minutes to read
- Print
- DarkLight
- PDF
Zscaler Web Security is a secure Internet and web gateway service that stops malware, advanced threats, phishing, browser exploits, malicious URLs, botnets, and more.
This adapter is compatible with Zscaler Internet Access (ZIA).
Types of Assets Fetched
This adapter fetches the following types of assets:
- Devices
- Users
- SaaS Data
Parameters
Zscaler Domain (required, default: admin.zscalerthree.net) - Specify the Zscaler cloud name was provisioned for your organization. For example:
- admin.zscalerbeta.net
- admin.zscalerone.net
- admin.zscalertwo.net
- admin.zscaler.net
- admin.zscloud.net
For more details, see 'Retrieve your base URI and API key' section under Zscaler API - Getting Started.
Note:Your organization may use a Zscaler domain for Single Sign On (SSO) that is different from the Base URL. This domain may need to be accounted for in firewall rule configurations to allow for a successful connection.
User Name and Password (required) - The user name and password used to connect to Zscaler Web Security.
API Key (required) – Your organization's API key. The API key is mandatory to fetch user data from Zscaler.
For more details about adding a new API key, see Zscaler documentation - About API Key Management.Company ID (optional) - Enter the Company ID. This parameter is only required if the Fetch Zscaler Client Connector enrolled devices parameter is selected.
Verify SSL - Select to verify the SSL certificate offered by the value supplied in Zscaler Domain. For more details, see SSL Trust & CA Settings.
HTTPS Proxy (optional) - A proxy to use when connecting to the value supplied in Zscaler Domain.
For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
Advanced settings can either apply for all connections for this adapter, or you can set different advanced settings and/or different scheduling for a specific connection, refer to Advanced Configuration for Adapters.
- Ignore duplicated MAC addresses
- If enabled, all connections for this adapter will ignore MAC addresses that are associated with more than one device fetched from Zscaler.
- If disabled, all connections for this adapter will fetch all MAC addresses from Zscaler.
- Fetch users (required, default: true) - Select whether to fetch users' data from Zscaler.
- If enabled, all connection for this adapter will fetch users data. Each user will be added as a user asset in Axonius.
- If disabled, all connection for this adapter will not fetch users data.
- Avoid hostnames duplications - Select this option to avoid returning duplicate hostname fetches.
- Fetch Zscaler Client Connector enrolled devices - Select to fetch enrolled devices from the Zscaler Client Connector.
When Fetch Zscaler Client Connector enrolled devices is selected, you must enter a value in the Company ID parameter.
- Enrich devices service status - Select this option to enrich device information with Service Status data.
- Add last used users information for duplicated devices - Select this option to add the last used users information for duplicated devices. This is only applicable only when “Avoid hostnames duplications” is used.
- Add Device Manufacturer Serial for Zscaler devices - Select this option to extract the device manufacturer serial number from the UDID and add it to the device?
For details on general advanced settings under the Adapter Configuration tab, see Adapter Advanced Settings.
Permissions
The following permissions are required for this adapter:
Functional Scope:
Under the 'Edit Administrator Role' setting:
- Access Control
- Policy and resource management
- Zscaler Client Connector Portal
- Traffic Forwarding
- Zscaler Client Connector Devices
- Authentication Configuration
- User Management
- Administrator's Access
- View Only
- Dashboard Access
- View Only
- Policy Access
- View Only
- Reporting Access
- View Only
You need to enable firewall access to mobile.zscaler.net