What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of interdependent policies, objects, and connectors where missed mappings cause silent security gaps or broken connectivity. This Skill provides a structured workflow to inventory source configurations, map them to Cloudflare One resources, and stage a safe rollout. ## Core Features & Use Cases - Source Stack Inventory: Defines exactly which exports to request from ZIA, ZPA, and Palo Alto/Prisma, including policies, objects, connectors, hit counts, and identity data. - Mapping Heuristics: Maps source constructs to Cloudflare One targets such as Gateway traffic policies, Access applications, Cloudflare Tunnels, Split Tunnels, and DLP profiles, with explicit partial/unsupported flags. - Source-Specific Traps: Documents known pitfalls like ZPA connector-group-to-tunnel topology, Access app hostname limits, ZIA caution/warn behavior, and Gateway Network rules blocking private app traffic. - Use Case: A network engineer receives ZPA exports with 40 app segments and 12 connector groups. The Skill guides creating one Cloudflare Tunnel per connector group, converting app segment IPs to CIDR routes, building reusable Access policies, and adding the Gateway Network allow rule before enabling L4 blocks. ## Quick Start Ask the agent to assess a migration from Zscaler ZPA to Cloudflare One using your exported app segments, connector groups, and access policies.