What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of interdependent policies, objects, and connectors where missed mappings cause silent security gaps. This Skill provides a structured workflow for inventorying source configurations, mapping them to Cloudflare One resources, and staging a safe rollout. ## Core Features & Use Cases - Source Stack Assessment: Guides collection of structured exports from ZIA, ZPA, Palo Alto/Prisma, and legacy VPN environments, including rules, objects, hit counts, and identity data. - Policy Mapping Plans: Maps source rules to Cloudflare Gateway policies, Access applications, Cloudflare Tunnel routes, DLP profiles, and device posture checks with confidence levels and partial-mapping flags. - Staged Rollout & Validation: Enforces disabled/audit-mode rule creation, pilot groups, object-count validation gates, rollback paths, and a full source-rule accounting table. - Use Case: A network engineer migrating from Zscaler ZPA uses the Skill to map connector groups to Cloudflare Tunnels, convert app segments into CIDR and hostname routes, and translate access policies into reusable Cloudflare Access policies. ## Quick Start Ask the assistant to assess a migration from Zscaler ZIA to Cloudflare One using your exported URL filtering, firewall, and DLP policy files.