Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Horizontal Navigation Bar
idQNet Zscaler


Horizontal Navigation Bar Page
titleAbout


Section

Zscaler is a cloud hosted, HIDS supported service that is currently available to end users within HCQIS organizations.  Zscaler was chosen, piloted and deployed due to its ease of use, tight security and cost feasibility.  Zscaler will be the preferred method to access tools and applications residing on the HCQIS network as we retire our legacy VPN connectivity technology.



Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleWho Will Get Zscaler?

The users that require access to the Zscaler solution consist of contractors approved for services connecting to the HCQIS network included but not limited listed below.

  • AWS Environment 
  • Splunk
  • CloudBees Jenkins
  • Ansible Tower
  • Tenable Nessus
  • Nexus RM
  • Nexus IQ
  • CMSNet resources
  • CyberArk
  • CASPER
  • Cloudbees Jenkins Enterprise (CJE)


For requests outside of the initial onboarding process please refer to the Getting Started tab.


Horizontal Navigation Bar Page
idGetting
titleGetting Started


Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleQuick Start Notes
  • Zscaler utilizes a client which must be installed on any Contractor Furnished Equipment (CFE)/Government Furnished Equipment (GFE) computer that will use it.
  • Zscaler must be configured for an organization before it can be used on CFE/GFE computers.
  • End users must be approved by their SO within HARP prior to obtaining access. Follow steps in Requesting the Zscaler User Access Role within HARP below.
  • Contractors installing Zscaler will need administrator rights to successfully install the client. 

The Zscaler Adoption Process

Organizations Seeking Zscaler

If you are a new organization and need access to the HCQIS environment you will require Zscaler.  These organizations will be granted access during the ISG contract onboarding process.  For more information please contact to the Contract Engagement team ISGContractEngagement@hcqis.org.

For new organizations, HIDS-Onboarding can assist you through these processes.

Panel
borderColor#254b78
titleColor#ffffff
titleBGColor#254b78
titleORGANIZATIONS REQUESTING ZSCALER

Listed below are the steps for an organization to request Zscaler.   Expand the steps below to view the process.


Expand
titleStep 1: Obtain a HARP ID.

All Zscaler users will require a valid HARP ID. For instructions on the process, refer to the HARP page.



Expand
titleStep 2: Install Zscaler.

Organizations are required to install the Zscaler client on their corporate machines. Please refer to the Zscaler Installation Instructions page to download copies of installation guides as well as the client installation packages.

Additionally, the the client installation packages can be obtained by contacting the Service Center @ 866-288-8914 (TRS: 711), slack channel help-service-center-sos or via email at ServiceCenterSOS@cms.hhs.gov

If you have issues, please submit a Service Request within ServiceNow requesting support for Zscaler Installation. The ticket will be routed to the HIDS Service Delivery End-User & Access team. 



Expand
titleStep 3: Add Users.

Once your organization is added to the vetted list, your end users can utilize HARP to request Zscaler as a service. The SO will be able to automatically approve requests from end users.



Expand
titleStep 4: Ready to Go.

Once your organization has been added to the vetted list, Zscaler has been installed and the end user has been approved via HARP, you are ready to access and use Zscaler. For information on how to get started, please refer to the Zscaler User Guide.



Section


Note:  Feel free to contact the Service Center-SOS for assistance with instructions if needed.

Service Center @ 866-288-8914 (TRS: 711), slack channel help-service-center-sos or via email at ServiceCenterSOS@cms.hhs.gov




If Your Organization Already Has Zscaler and You Are a New User - How to Request?

Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleREQUESTING THE ZSCALER USER ACCESS ROLE WITHIN HARP

Once you have created your HARP account (For instructions on the process, refer to the HARP page), the next step is to request the Zscaler User Access User role. Expand the steps below to view the process.



Expand
titleStep 1: Go to https://harp.qualitynet.org/ and log in to your HARP account which will take you to your User Profile. From there, select “User Roles”

Go to https://harp.qualitynet.org and log into your HARP account.


Expand
titleStep 2: Request a role


Expand
titleStep 3: Select the QualityNet Zscaler Program.


Expand
titleStep 4: Select your Organization.


Expand
titleStep 5: Select the Zscaler User role.


Expand
titleStep 6: You will be notified via email when your role has been approved.

Once your role has been approved by your SO, you will then have access to Zscaler





Horizontal Navigation Bar Page
idResources
titleResources


Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleUser Resources


Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleSecurity Guidelines


Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleTraining Videos

Administrative Videos

Panel
borderWidth0


Column
width45%

Widget Connector
width100%
urlhttps://www.youtube.com/watch?v=eG3dr2xRrHk&feature=youtu.be
height100%

How to Download Zscaler


Column
width5%



Column
width45%

Widget Connector
width100%
urlhttps://www.youtube.com/watch?v=U0Z9j4WiDXk&feature=youtu.be
height100%

How to Install Zscaler




User Videos

Panel
borderWidth0


Column
width45%

Widget Connector
width100%
urlhttps://www.youtube.com/watch?v=HXkRZ9chUNw&feature=youtu.be
height100%

How to Request a Zscaler Role


Column
width5%



Column
width45%

Widget Connector
width100%
urlhttps://www.youtube.com/watch?v=x4YXY10aGbM&feature=youtu.be
height100%

How to Login and Use Zscaler





Horizontal Navigation Bar Page
titleFAQs


Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleFrequently Asked Questions


Expand
titleWhat is Zscaler?

Zscaler is an alternative to VPN that utilizes a different method of allowing users access to resources within an internal network. It uses tunneling to transmit data between the client and desired resource. This approach eliminates the need to have clients enter into the network directly as is done with VPN.  

The Zscaler solution is made up of two primary modules;  Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA).


Expand
titleWhat is Zscaler Internet Access (ZIA)?

Zscaler Internet Access (ZIA) is a secure Internet and web gateway delivered as a service from the cloud. Before reaching the user, ZIA inspects every byte of traffic inline across multiple security techniques, even within SSL providing full protection from web and Internet threats.


Expand
titleWhat is Zscaler Private Access (ZPA)?

Zscaler Private Access (ZPA) provides secure remote access and works by abstracting a private, internal application from the network on which it resides and provides specific applications access to authorized users via encrypted, per session micro tunnels that are created upon demand.


Expand
titleWhat can I do with Zscaler?

When logged into Zscaler (utilizing both ZIA and ZPA) you will be able to reach tools residing on the HCQIS network such as AWS or HCQIS applications. It will also allow access Internet facing sites that your organization’s firewall and anti-virus policies allow access to.  


Expand
titleWhat can't I do with Zscaler?

When logged into Zscaler (utilizing both ZIA and ZPA), you will not be able to access anything that your organizations Firewall or Anti-virus policies prohibit.  Please reach out to your IT Administrator for information regarding policies for your organizations firewall and anti-virus configurations.  


Expand
titleHow can I get Zscaler?

Please refer to the How to Request Zscaler Confluence Page. This page provides information for New and Existing HCQIS contractors.

Please note at this time (as of 1/28/2020), individual users cannot request Zscaler without approval from their SO. SOs should be submitting requests for Zscaler via a ServiceNow request or inquiry with the QualityNet Service Desk. The "How to Request Zscaler" Confluence page lays out all these details.

Automatic requests for Zscaler are scheduled to be implemented in the April/May 2020 time period. The appropriate Confluence pages will be updated


Expand
titleCan I use Outlook with Zscaler?

Yes. You can use the Outlook Desktop Application or Outlook on the Web or what is formerly known as OWA. The Outlook desktop application is not fully compatible with Zscaler for HCQIS email and it is recommended to go with the web version.


Expand
titleCan I access HCQIS email while on Zscaler?

Yes. You can access your HCQIS email while using Zscaler. Use Outlook on the Web to access your HCQIS email until ADOs and contractors go to corporate email addresses by 3/15/2020.


Expand
titleCan I log out of ZIA and continue with just ZPA?

No.  The reason for this configuration is to enforce protection of the computer while connected to HCQIS using Zscaler.  ZIA provides threat protection for Internet traffic reducing overall risk that the computer will become infected by an external threat while connected to HCQIS.  Only a Zscaler Private Access Administrator (not local IT Admin) can turn off ZIA and still remain active with their ZPA account.


Expand
titleCan I log out of ZPA and continue with just ZIA?

Yes.  However, you will not be able to access information or tools residing upon the HCQIS network such as  AWS or HCQIS applications such as those residing on QualityNet.org.


Expand
titleDoes Zscaler replace VPN, VDI or both?

The intent is for both HCQIS VPN and HCQIS VID to no longer be needed.  Zscaler is intended to be the preferred method of connectivity to HCQIS network tools and applications. With the move to CFE/GFE, and the ability to directly connect to resources within HCQIS, Zscaler will eliminate the need for HCQIS VPN and VDI to be used. 


Expand
titleHow can I do my work with Zscaler if I am currently using HCQIS VPN?

If you were previously a HCQIS VPN user, your experience with using Zscaler will only alter minimally from that of VPN. Instead of logging into VPN, you will now log into Zscaler.  You will not see any differences in how you access sites or tools except that you will be on a CFE or GFE machine in which your organization may have different settings when browsing the Internet. 

If HCQIS VPN remains on your machine and your access remains active, please note that Zscaler and VPN cannot work simultaneously and you would have to log out of one in order to use the other.  

Reference the HCQIS Zscaler Users Guide for any login questions. 


Expand
titleWill Zscaler work with Corporate VPN?

Yes. If your organization is using Split-Tunneling or Full-Tunneling settings within your VPN, please be prepared to share your VPN HostName (or IP) with HIDS End User & Access.  Additional configurations may be required within your settings to properly route traffic, and allow users to access both corporate systems as well as HCQIS systems simultaneously.


Expand
titleHow can I do my work with Zscaler if I am currently using VDI?

If you were previously a HCQIS VDI user, your experience will be altered while using Zscaler in a positive way.  When using VDI, you are on a virtual desktop that has programs loaded onto it based on your role and organization.  When using Zscaler, you will be logged only onto your laptop to access programs and tools that are installed or available via the Internet.   

Reference the HCQIS Zscaler Users Guide for any login questions.


Expand
titleI am getting an Endpoint FW/AV error, what should I do?

If you or an end user within your organization is receiving the following error when logging into Zscaler “Endpoint FW/AV Error”, then your organizations Firewall (FW) or Antivirus (AV) is blocking Zscaler, causing it to be non-operational. To remedy this, your organization's IT Administrator will have to white-list a specific subnet within your FW or AV.

If you run into this issue during configuration or thereafter, please submit a ticket within ServiceNow referencing the error you received. HIDS will provide the proper subnet to white-list.


Expand
titleI cannot access a tool, drive, host or server that I normally could?

If you cannot access a tool, drive, host or server that you normally could prior to Zscaler, first bring this up with your organization's IT Administrator or colleagues to ensure that naming conventions are using Fully Qualified Domain Names (FQDN). A FQDN is the complete domain name for a specific computer, or host, on the internet. The FQDN consists of two parts: the hostname and the domain name.

If FQDN names are being used or were added and access is still not available, then submit a ServiceNow ticket and assign to HIDS End User and Access Team. Please include detailed information such as the tool, host and server name. The HIDS-End User and Access Team may have to add this tool, drive, host or server to your network segment group to ensure all at your organization with access can get to it in the future.


Expand
titleCan I use the Zscaler App on my Android, or iOS device?

No, not at this time. The mobile (Android and iOS) policies have been disabled at this time. If the use of Zscaler via mobile becomes a necessity for a number of users, this feature could be addressed at a later time.


Expand
titleWhat should I do if I need Zscaler support?

If you are experiencing any issues with Zscaler such as installation, errors, loss of service or any other problems, please contact the Service Center @ 866-288-8914 (TRS: 711) or via email at qnetsupport@hcqis.org. Business hours are 7 am- 7 pm CDT Monday through Friday.  

Please provide as much information, error codes or screenshots if possible to allow for quick troubleshooting.


Expand
titleWhat should I do if I am receiving a 403 App Not Assigned Error?

If you are experiencing this error when attempting to log into Zscaler, your Security Point of Contact needs to open a Service Now Request for your HARP ID to be configured for Zscaler. The ticket should be assigned to HIDS Security IAM.


Expand
titleWhat should I do if I am receiving an Invalid Token Error?

If you are experiencing this error when attempting to log into Zscaler, first you should verify you are able to log in and that your token method set up for your HARP ID is working by going to https://harp.qualitynet.org/login/login. I you are able to log in there and the problem with logging into Zscaler continues, then try rebooting your workstation.


Expand
titleIs BitLocker the only Windows Disk Encryption supported by Zscaler?

According to Zscaler support, the only Windows Disk Encryption supported by Zscaler is BitLocker. All 3rd party encryption is not recognized. An Enhancement Request has been submitted "To provide 3rd party support for encryption products". However, there is no planned/expected release date at this time.


Expand
titleKnown Zscaler RHEL Connection Issue - Resolution - 4/6/2020

Issue: All RHEL and CENTOS AMIs have routing settings that force the Zscaler networks over the Management interface on the host.  Due to this static routing configuration, Zscaler connections will not be allowed to the Functional interface on the host. This will prevent users being able to reach application web pages while logged into Zscaler. Currently VPN and VDI do not use this type of network configuration, so users can connect to both management and application interfaces on the same host.

To resolve this issue please go to the following page that provides detailed information: Linux FAQ


Expand
titleRemoving Users from ZScaler

1) The ADO or Customer Success Manager will submit a ServiceNow Ticket assigned to the HIDS-End User and Access Team to remove users from the subject organization from Zscaler

2) The End User and Access Team will submit a task to the IAM team to provide HARP IDs associated with the organization and to also remove the organization as an option for the Zscaler role in HARP.










Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleSystem Status


Excerpt

Status
Operational
colourGreenYellow
titleISSUE REPORTED

Zscaler Connection Timeout issues have been reported.



Panel
borderColor#009CDA
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleZscaler Updates

1/25/2021 - Please ensure that you are using the most up to date version on Zscaler 3.1.0.88. All other versions will be denied access as of 2/1/2021. 



Panel
borderColor#254b78
titleColor#ffffff
borderWidth1
titleBGColor#254b78
borderStylesolid
titleNeed Help ?

Feel free to contact the QualityNet Service Center at:

Phone: (866) 288-8914 (TRS:711)

Slack: #help-service-center-sos

Email: ServiceCenterSOS@cms.hhs.gov

Hours of Operation: 24/7