zia-audit-ssl-inspection-bypass

Audit ZIA SSL inspection rules to identify decryption and bypass risks.

44|24|Updated May 29, 2025
One-click install
npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zia-audit-ssl-inspection-bypass
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: zia-audit-ssl-inspection-bypass
Source: https://github.com/zscaler/zscaler-mcp-server/tree/main/skills/zia/audit-ssl-inspection-bypass
Command: npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zia-audit-ssl-inspection-bypass

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audit SSL inspection configurations to identify rules that decrypt or bypass traffic within ZIA, enabling security teams to close gaps and reduce risk.

Core Features & Use Cases

  • Identify rules by action (INSPECT, DO_NOT_INSPECT, DO_NOT_DECRYPT, BLOCK) and summarize their impact.
  • Resolve IDs to human-friendly names for users, groups, departments, and locations to produce clear reports.
  • Perform a risk assessment of bypass rules and generate a prioritized remediation plan.

Quick Start

Run a comprehensive SSL inspection audit to identify decrypting and bypassing rules and report their scope.

Frequently Asked Questions about zia-audit-ssl-inspection-bypass

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit SSL inspection bypass rules in ZIA?

To audit SSL inspection bypass rules in ZIA, run a comprehensive audit to identify rules by action (INSPECT, DO_NOT_INSPECT, DO_NOT_DECRYPT, BLOCK) and summarize their scope across apps, users, groups, and locations.

What is an SSL inspection bypass risk assessment?

An SSL inspection bypass risk assessment identifies decryption gaps by analyzing bypass rules within ZIA, resolving rule IDs to human-friendly names, and generating a prioritized remediation plan to close security gaps.

How do I find decryption gaps in Zscaler Internet Access?

Find decryption gaps in Zscaler Internet Access by auditing SSL policies to locate traffic matching DO_NOT_DECRYPT or DO_NOT_INSPECT actions, then review the resolved names for users, groups, and locations to understand the exposure.

Can I generate a structured report of ZIA SSL rules by action?

Yes, you can generate a structured audit report detailing ZIA SSL rules by action, resolving IDs to human-friendly names for users, groups, departments, and locations, and summarizing the impact of decrypting and bypassing rules.

Does the SSL inspection audit resolve user and group IDs to names?

Yes, the SSL inspection audit resolves IDs to human-friendly names for users, groups, departments, and locations, ensuring the generated audit report clearly identifies the scope and impact of bypass and decryption rules.

What are the limitations of auditing SSL inspection configurations?

Auditing SSL inspection configurations is limited to analyzing existing rules within ZIA to identify bypass risks and decryption gaps; it reports on current policy scope but does not automatically enforce changes without administrator remediation.