What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of policies, objects, and tunnels that rarely map 1:1, and mistakes cause silent traffic drops or security gaps. This Skill provides a structured workflow for assessment, policy mapping, staged rollout, and validation so no source rule is lost or misconfigured. ## Core Features & Use Cases - Source Stack Assessment: Builds a full inventory of identities, apps, policies, connectors, and hit counts from ZIA, ZPA, Palo Alto, or legacy VPN exports before any mapping begins. - Policy Mapping & Gap Analysis: Maps source rules to Cloudflare Gateway, Access, Tunnel, DLP, and device posture resources, flagging partial, unsupported, or manual-decision items explicitly. - Staged Rollout & Validation: Creates disabled/audit-mode rules with migration prefixes, pilots with small groups, compares object counts and logs, and produces a source-rule accounting table with rollback paths. - Use Case: A network engineer migrating from Zscaler ZPA exports app segments and connector groups, then uses this Skill to generate one Cloudflare Tunnel per connector group, map CIDR and hostname routes, and build reusable Access policies with the required Gateway Network allow rule. ## Quick Start Ask the AI to plan a migration from Zscaler ZIA and ZPA to Cloudflare One using your exported policy and app segment files.