Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Disaster Recovery Configuration for Zscaler Internet Access

Zscaler
05/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this series of short videos, we'll be taking a look at recommendations for forwarding your traffic to the Zero Trust Exchange. This is Part 8, Disaster Recovery. Zscaler heavily recommends that you configure Disaster Recovery for Zscaler Internet Access, so that we can continue to provide secure access to the Internet for your users, even in the event of a Zero Trust Exchange outage. Configuring Disaster Recovery for ZIA is a three-step process. First, you should decide how ZIA should behave when in Disaster Recovery mode. You have the choice of three behaviors. One, Fail Open mode. In this mode, users go directly to the Internet, bypassing ZIA entirely with no security restrictions. This is generally not recommended, as users will not be protected for the duration of the outage. Two, Fail Close mode. If selected, users will have no access to the Internet during Disaster Recovery. This is the most secure option, but is generally not recommended, as it will leave your users unable to work during outages. Third, Controlled Fail Open. This allows the client connector to allow access to destinations based on policy you have defined in a custom Disaster Recovery pack file, which is hosted on your own infrastructure. This is the recommended failover action in most cases, and it will allow your users to continue to use any critical business applications you have defined while the outage is resolved, while continuing to block access to potentially risky or malicious domains. Once this choice is made, the second step of the process is to perform a one-time Disaster Recovery configuration. If you've chosen to go with the Controlled Fail Open mode, configure and host your custom Disaster Recovery pack file that will define what destinations users are allowed access to. Then, pre-create your Disaster Recovery activation DNS records inside the ZIA admin portal. You should make sure to create separate records to activate Disaster Recovery for all users to enter Disaster Recovery test mode and to disable Disaster Recovery. Finally, define your processes for triggering Disaster Recovery mode. Note that triggering Disaster Recovery mode for ZIA is a manual process. The final step is to test Disaster Recovery mode to validate that it works as expected. To do this, create or edit an app profile in the ZCC admin portal and enable the Activate Test Mode setting for that app profile, then assign it to your test users. Then, trigger Disaster Recovery test mode by uploading the test mode DNS record you pre-created to the DNS server for the configured Disaster Recovery domain name. This will trigger Disaster Recovery for users who have the test mode app profile. Verify that these users are only able to access the destinations you configured in your custom Disaster Recovery pack file. Once you have validated this, deactivate DR mode by uploading the Disaster Recovery deactivation DNS record. Zscaler recommends that you perform the steps to test Disaster Recovery mode on a regular basis, at least once every 12 months. That's it for this video. Thanks for watching.

TL;DR

  • Zscaler recommends configuring disaster recovery for ZIA to maintain secure internet access during Zero Trust Exchange outages, with three available modes: Fail Open, Fail Close, and Controlled Fail Open.
  • Controlled Fail Open is the recommended approach, allowing policy-based access to critical business applications via a custom DR pack file while blocking risky domains during outages.
  • DR configuration requires creating DNS activation records, hosting a custom pack file, and establishing manual triggering processes, with annual testing recommended to validate functionality.

Summary

This technical tutorial demonstrates how to configure disaster recovery (DR) for Zscaler Internet Access (ZIA), ensuring business continuity during Zero Trust Exchange outages. The video covers three DR modes: Fail Open (unrestricted internet access with no security), Fail Close (complete internet blocking), and Controlled Fail Open (policy-based access to critical applications). Zscaler recommends the Controlled Fail Open approach, which requires hosting a custom DR pack file that defines allowed destinations during outages. The configuration process involves selecting a DR mode, creating DNS activation records in the ZIA portal, and establishing manual triggering procedures. Organizations should test DR mode at least annually using the test mode app profile feature to validate that users can only access pre-approved destinations during simulated outages. This proactive approach balances security requirements with operational continuity, allowing employees to maintain access to essential business applications while blocking potentially risky domains during service disruptions.

Chapters

0:00 - Introduction to Disaster Recovery
0:15 - DR Mode Options
1:37 - Configuration Steps
2:22 - Testing DR Mode

Key Quotes

0:14 "Zscaler heavily recommends that you configure Disaster Recovery for Zscaler Internet Access, so that we can continue to provide secure access to the Internet for your users, even in the event of a Zero Trust Exchange outage."
1:07 "This is the recommended failover action in most cases, and it will allow your users to continue to use any critical business applications you have defined while the outage is resolved, while continuing to block access to potentially risky or malicious domains."
3:08 "Zscaler recommends that you perform the steps to test Disaster Recovery mode on a regular basis, at least once every 12 months."

Categories:
  • » Cybersecurity » Zero Trust
  • » Webinar Library » Zscaler
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • SASE
  • SSE
  • Cloud Security
  • Technical Deep Dive
  • How-To
  • Best Practices
  • Disaster Recovery
  • Business Continuity
  • Zero Trust Exchange
  • ZIA Configuration
  • Failover Modes
  • DNS Management
  • Security Policy
  • Client Connector
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Disaster Recovery Configuration for Zscaler Internet Access

              XStreaminars (watch here)

              • Oct
                28

                EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure

                10/28/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Oct
                  13

                  Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                  10/13/202601:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    • Oct
                      20

                      Harnessing Data Governance for AI with Cyera and Snowflake

                      10/20/202611:00 AM ET
                      • Oct
                        27

                        Maximize Security, Value, and Returns on Your Microsoft Investment

                        10/27/202611:00 AM ET
                        • Oct
                          27

                          The HUMAN Experience: Real-Time Insights into Page Intelligence

                          10/27/202601:00 PM ET
                          More events

                          Upcoming Webinar Calendar

                          • 10/13/2026
                            01:00 PM
                            10/13/2026
                            Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                            https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                          • 10/15/2026
                            11:00 AM
                            10/15/2026
                            Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                            https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                          • 10/20/2026
                            11:00 AM
                            10/20/2026
                            Harnessing Data Governance for AI with Cyera and Snowflake
                            https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                          • 10/27/2026
                            11:00 AM
                            10/27/2026
                            Maximize Security, Value, and Returns on Your Microsoft Investment
                            https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                          • 10/27/2026
                            01:00 PM
                            10/27/2026
                            The HUMAN Experience: Real-Time Insights into Page Intelligence
                            https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                          • 10/28/2026
                            01:00 AM
                            10/28/2026
                            [APAC:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2125/apac-ensuring-comprehensive-security-for-ai-applications/
                          • 10/28/2026
                            06:00 AM
                            10/28/2026
                            [EMEA:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2127/emea-ensuring-ai-security-across-all-platforms/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure
                            https://www.truthinit.com/index.php/channel/2179/envzero-near-zero-time-to-resolution-live-agentic-remediation-for-failed-and-drifted-infrastructure/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                            https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                            https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                            https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                            https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                          • 11/19/2026
                            01:00 PM
                            11/19/2026
                            360View: Govern, Secure & Recover Your Microsoft 365 Environment
                            https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                          Truth in IT
                          • Sponsor
                          • About Us
                          • Terms of Service
                          • Privacy Policy
                          • Contact Us
                          • Preference Management
                          Desktop version
                          Standard version