What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of interdependent policies, objects, and connectors where missed mappings cause silent security gaps. This Skill provides a structured workflow for inventorying source configurations, mapping them to Cloudflare One resources, and staging a safe rollout. ## Core Features & Use Cases - Source Stack Assessment: Guided export checklists for ZIA, ZPA, and Palo Alto/Prisma covering policies, objects, tunnels, identity, and hit counts. - Mapping Heuristics: Concrete rules for translating source constructs to Gateway policies, Access apps, Cloudflare Tunnels, DLP profiles, and split tunnels, with explicit partial-mapping flags. - Source-Specific Traps: Documented pitfalls such as ZPA connector-group-to-tunnel topology, Access app hostname limits, ZIA caution/warn behavior, and Gateway Network rules blocking private app traffic. - Use Case: Given ZPA app segment and connector group exports, produce a mapping plan with one Cloudflare Tunnel per connector group, CIDR/hostname routes, reusable Access policies, and a validation gate comparing object counts before enablement. ## Quick Start Ask the assistant to plan a migration from your Zscaler ZIA and ZPA exports to Cloudflare One, including a policy mapping table and pilot rollout plan.