What problem does it solve? Migrating from existing VPN, SWG, or SASE platforms like Zscaler ZIA/ZPA or Palo Alto to Cloudflare One is error-prone: policies, objects, tunnels, and identity rules rarely map 1:1, and missed rules create silent security gaps. This Skill provides a structured assessment and mapping workflow so every source rule is accounted for. ## Core Features & Use Cases - Source Stack Assessment: Inventory identities, apps, connectors, DNS/URL/firewall/DLP/TLS policies, and hit counts from ZIA, ZPA, Palo Alto/Prisma, and legacy VPN exports. - Mapping Plans with Confidence Levels: Map each source object to Cloudflare Gateway policies, Access apps, Cloudflare Tunnel routes, DLP profiles, and split tunnels, flagging partial or unsupported mappings. - Source-Specific Trap Guidance: Covers ZPA connector-group-to-tunnel topology, ZIA caution/warn behavior, Palo Alto zone handling, and Gateway Network allow rules for private apps. - Use Case: Given ZPA app segment and connector group exports, produce a tunnel-per-connector-group plan with CIDR/hostname routes, reusable Access policies, and a staged pilot rollout with rollback criteria. ## Quick Start Assess these Zscaler ZIA and ZPA exports and produce a Cloudflare One migration plan with policy mappings, gaps, and a pilot rollout.