What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of interdependent policies, objects, and connectors where missed mappings cause silent security gaps. This Skill provides a structured workflow to inventory source configurations, map them to Cloudflare One resources, and stage a safe rollout. ## Core Features & Use Cases - Source Stack Inventory: Catalogs identities, apps, tunnels, DNS/URL/firewall/DLP policies, objects, and hit counts from ZIA, ZPA, and Palo Alto exports. - Mapping Plans: Produces source-to-target mappings with confidence levels, partial/unsupported flags, and explicit Not Migrated decisions with security impact. - Staged Rollout & Validation: Creates disabled/audit-mode rules with migration prefixes, pilot groups, log comparison, rollback paths, and per-rule accounting tables. - Use Case: Given ZPA app segment and connector group exports, generate one Cloudflare Tunnel per connector group, map app segment CIDRs to tunnel routes, and create reusable Access policies before attaching them to applications. ## Quick Start Use the cloudflare-one-migrations skill to assess these Zscaler ZIA and ZPA exports and produce a Cloudflare One migration plan with a mapping table and pilot rollout.