Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Disaster Recovery Configuration for Zscaler Internet Access

Zscaler
05/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this series of short videos, we'll be taking a look at recommendations for forwarding your traffic to the Zero Trust Exchange. This is Part 8, Disaster Recovery. Zscaler heavily recommends that you configure Disaster Recovery for Zscaler Internet Access, so that we can continue to provide secure access to the Internet for your users, even in the event of a Zero Trust Exchange outage. Configuring Disaster Recovery for ZIA is a three-step process. First, you should decide how ZIA should behave when in Disaster Recovery mode. You have the choice of three behaviors. One, Fail Open mode. In this mode, users go directly to the Internet, bypassing ZIA entirely with no security restrictions. This is generally not recommended, as users will not be protected for the duration of the outage. Two, Fail Close mode. If selected, users will have no access to the Internet during Disaster Recovery. This is the most secure option, but is generally not recommended, as it will leave your users unable to work during outages. Third, Controlled Fail Open. This allows the client connector to allow access to destinations based on policy you have defined in a custom Disaster Recovery pack file, which is hosted on your own infrastructure. This is the recommended failover action in most cases, and it will allow your users to continue to use any critical business applications you have defined while the outage is resolved, while continuing to block access to potentially risky or malicious domains. Once this choice is made, the second step of the process is to perform a one-time Disaster Recovery configuration. If you've chosen to go with the Controlled Fail Open mode, configure and host your custom Disaster Recovery pack file that will define what destinations users are allowed access to. Then, pre-create your Disaster Recovery activation DNS records inside the ZIA admin portal. You should make sure to create separate records to activate Disaster Recovery for all users to enter Disaster Recovery test mode and to disable Disaster Recovery. Finally, define your processes for triggering Disaster Recovery mode. Note that triggering Disaster Recovery mode for ZIA is a manual process. The final step is to test Disaster Recovery mode to validate that it works as expected. To do this, create or edit an app profile in the ZCC admin portal and enable the Activate Test Mode setting for that app profile, then assign it to your test users. Then, trigger Disaster Recovery test mode by uploading the test mode DNS record you pre-created to the DNS server for the configured Disaster Recovery domain name. This will trigger Disaster Recovery for users who have the test mode app profile. Verify that these users are only able to access the destinations you configured in your custom Disaster Recovery pack file. Once you have validated this, deactivate DR mode by uploading the Disaster Recovery deactivation DNS record. Zscaler recommends that you perform the steps to test Disaster Recovery mode on a regular basis, at least once every 12 months. That's it for this video. Thanks for watching.

TL;DR

  • Zscaler recommends configuring disaster recovery for ZIA to maintain secure internet access during Zero Trust Exchange outages, with three available modes: Fail Open, Fail Close, and Controlled Fail Open.
  • Controlled Fail Open is the recommended approach, allowing policy-based access to critical business applications via a custom DR pack file while blocking risky domains during outages.
  • DR configuration requires creating DNS activation records, hosting a custom pack file, and establishing manual triggering processes, with annual testing recommended to validate functionality.

Summary

This technical tutorial demonstrates how to configure disaster recovery (DR) for Zscaler Internet Access (ZIA), ensuring business continuity during Zero Trust Exchange outages. The video covers three DR modes: Fail Open (unrestricted internet access with no security), Fail Close (complete internet blocking), and Controlled Fail Open (policy-based access to critical applications). Zscaler recommends the Controlled Fail Open approach, which requires hosting a custom DR pack file that defines allowed destinations during outages. The configuration process involves selecting a DR mode, creating DNS activation records in the ZIA portal, and establishing manual triggering procedures. Organizations should test DR mode at least annually using the test mode app profile feature to validate that users can only access pre-approved destinations during simulated outages. This proactive approach balances security requirements with operational continuity, allowing employees to maintain access to essential business applications while blocking potentially risky domains during service disruptions.

Chapters

0:00 - Introduction to Disaster Recovery
0:15 - DR Mode Options
1:37 - Configuration Steps
2:22 - Testing DR Mode

Key Quotes

0:14 "Zscaler heavily recommends that you configure Disaster Recovery for Zscaler Internet Access, so that we can continue to provide secure access to the Internet for your users, even in the event of a Zero Trust Exchange outage."
1:07 "This is the recommended failover action in most cases, and it will allow your users to continue to use any critical business applications you have defined while the outage is resolved, while continuing to block access to potentially risky or malicious domains."
3:08 "Zscaler recommends that you perform the steps to test Disaster Recovery mode on a regular basis, at least once every 12 months."

Categories:
  • » Cybersecurity » Zero Trust
  • » Webinar Library » Zscaler
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • SASE
  • SSE
  • Cloud Security
  • Technical Deep Dive
  • How-To
  • Best Practices
  • Disaster Recovery
  • Business Continuity
  • Zero Trust Exchange
  • ZIA Configuration
  • Failover Modes
  • DNS Management
  • Security Policy
  • Client Connector
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Disaster Recovery Configuration for Zscaler Internet Access

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version