zia-onboard-location

Coordinate static IP, VPN credentials, and location records to onboard a ZIA location.

44|24|Updated May 29, 2025
One-click install
npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zia-onboard-location
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: zia-onboard-location
Source: https://github.com/zscaler/zscaler-mcp-server/tree/main/skills/zia/onboard-location
Command: npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zia-onboard-location

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Onboard a new ZIA location end-to-end by coordinating static IPs, VPN credentials, and location records, ensuring consistent configuration and minimal manual steps.

Core Features & Use Cases

  • Dependency chain orchestration: Static IP (IP-based VPN), VPN credentials (UFQDN or IP), Location creation, and optional sub-location.
  • Supports both UFQDN-based VPN and IP-based VPN flows.
  • Guides administrators through required fields for common scenarios such as new offices, branches, or data centers, with validation and best practices.

Quick Start

Onboard a new ZIA location by creating VPN credentials (UFQDN or IP), optionally creating a static IP for IP-based VPN, then creating the location and an optional sub-location.

Frequently Asked Questions about zia-onboard-location

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I onboard a new ZIA location end-to-end with VPN credentials and static IPs?

ZIA location onboarding coordinates static IPs, VPN credentials, and location records into a single repeatable workflow. It validates resource presence and order, ensuring correct configuration for new offices, branches, or data centers with minimal manual steps.

What is the difference between UFQDN-based and IP-based VPN flows for ZIA traffic forwarding?

UFQDN-based VPN uses fully qualified domain names for credentials, while IP-based VPN requires a static IP resource. The onboarding workflow supports both flows, automatically coordinating the required resources based on your chosen authentication method.

Can I configure sub-locations when creating a new ZIA location?

Yes, the ZIA location onboarding workflow supports optional sub-location creation alongside the primary location record. This allows hierarchical traffic forwarding configurations while maintaining consistent deployment parameters.

What prerequisites are needed before onboarding a ZIA location for IP-based VPN?

IP-based VPN onboarding requires a static IP resource to be allocated before creating the location record. The workflow validates the presence and order of dependencies, ensuring the static IP exists prior to VPN credential generation.

How does the ZIA location onboarding workflow validate VPN credential usage and deployment order?

The workflow validates the presence and sequence of required resources including static IPs, VPN credentials, and location records. It ensures correct VPN credential usage and guides deployment through final activation and verification steps.

When should I use a repeatable ZIA location onboarding workflow instead of manual configuration?

Use the repeatable onboarding workflow when deploying multiple new offices, branches, or data centers requiring consistent ZIA configuration. It minimizes manual steps and ensures standardized IPsec VPN credential and location record management.