What problem does it solve? Migrating from existing VPN, SWG, or SASE platforms like Zscaler ZIA/ZPA or Palo Alto NGFW to Cloudflare One involves complex policy mapping, hidden parity gaps, and risky cutovers. This Skill structures the assessment and planning process so no source rule is silently dropped. ## Core Features & Use Cases - Source Stack Inventory: Catalogs identities, apps, tunnels, DNS/URL/firewall/DLP/TLS policies, objects, and hit counts from ZIA, ZPA, Palo Alto, and legacy VPN exports. - Policy Mapping Plan: Maps each source rule to Cloudflare One targets (Gateway traffic policies, Access apps, Cloudflare Tunnel, DLP profiles) with confidence levels, partial mappings, and explicit Not Migrated rows. - Safe Staged Rollout: Creates disabled/audit-mode rules with migration prefixes, pilot groups, log comparison, validation gates, and rollback paths. - Use Case: Given ZPA app segment and connector group exports, produce a tunnel-per-connector-group topology with CIDR/hostname routes, reusable Access policies, and the Gateway Network allow rule needed to avoid blocking private app traffic. ## Quick Start Assess my exported Zscaler ZIA and ZPA configuration files and produce a Cloudflare One migration plan with policy mappings and a pilot rollout.