A company requires stricter control of non-web traffic when users are outside the corporate network.
Which adjustment best reduces unintended exposure for off-network users?
A.
Configure Zscaler Client Connector to use Z-Tunnel 2.0 when off-network, and enable the appropriate Cloud Firewall rules
B.
Increase inspection depth for on-network users to compensate for off-network access risks, assuming that stricter internal analysis provides an aggregate deterrent
C.
Configure Zscaler Client Connector to use Z-Tunnel 1.0 when off-network, and enable the appropriate Cloud Firewall rules
D.
Duplicate the off-network block rule and place both copies below the global allow rule to provide redundant coverage and increased monitoring
Option A forwards the traffic that the organization actually needs to control. Z-Tunnel 2.0 can send all ports and protocols from Zscaler Client Connector to the Zscaler Service Edge, enabling Cloud Firewall to inspect and enforce policy on non-web sessions from roaming users. Zscaler’s Z-Tunnel 1.0 and 2.0 documentation confirms that Z-Tunnel 2.0 supports all ports and protocols. Its firewall end-user notification guidance also describes Cloud Firewall handling of non-web traffic over Z-Tunnel 2.0. Tightening on-network inspection does not protect users who are off-network. Z-Tunnel 1.0 primarily handles web proxy traffic and therefore leaves the stated non-web gap. Duplicate rules placed below a global allow will not be reached when the earlier allow rule already matches the session.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit