Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler B2B Extranet Configuration & IPSec Tunnels

Zscaler
08/17/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


So first of all, under infrastructure, private access, we have B2B exchange, extranet. So these are all your business partners. So one of my business partner amongst all of this is LexCorp. So for LexCorp, I'm saying that when I'm trying to access LexCorp applications, my business partner applications, these are the proxies that I can use. So I can use any of these proxies that is called as a traffic selector. And then we can leverage the partners DNS server. And these are all the placeholders for the partner DNS server. So these are again, all the placeholders that I can use for this business partners, we are not using it yet. Then we start defining the IPSec location. So we'll get to the IPSec location option here. And then we have this partner defined IPSec location, wherein I'm saying that the location type is extranet. And this happens to be for my business partner LexCorp. And this is the proxy that I'm using. And this is the DNS server that I'm using. And this is the VPN pre shared key that I'm using at the moment. So now I have provisioned an IPSec tunnel. Now the partner can use this VPN credential and create an IPSec tunnel to any of the Zscaler data center. Then we come to the policies. So on the ZPA side, we have defined a server group. So we have introduced a new connector type known as extranet. So if you look at this server group, this is the connector type, and the same location that we defined on the ZIA side is available on the ZPA side. So you create a server group using that. And then you define an application segment. So if you look at this application segment, this is jira.lex.corp, which is one of my partner application. And instead of mapping it to an app connector, I've directly mapped it to an IPSec tunnel. So that's an indication to ZPA that in order to access this application, go through this extranet tunnel. And then at last, what we have is an access policy. So here I'm defining a very specific access policy saying that only specific user can access this partner application. And finally, let's look at the experience. So if we look at the application here, this is the ZCC client connector logged in. And if I resolve the partner application, it still resolves to 164 IP, which obviously is not the real IP. However, if I try to access the application, the access will work just fine. So let's look at that. All right, so here you go. So this is how the application is accessed. Let's look at the logging capabilities. So if we go to ZPA Logging, Diagnostic, if you look at the log here, I'm able to access partner application. And this was allowed through this access policy. And the traffic, instead of going through the app connector, it just went through an IPSec tunnel. And this happens to be the real IP address of the partner application. Then we'll just flip the switch. So what if somebody from the partner side, through this IPSec tunnel, wants to access our application? So in that case, it's the same policy. So what we can do is we can go to private access, if we look at one of an existing application. So for example, PortQuiz.net, this is like any other normal application, and it is mapped to an app connector group. And then under policy, under access policy, I'm writing yet another policy. But instead of saying, I've introduced a new client type known as client connector. And then I'm saying that, you know, the partners can access this application. So I can get even more granular and add one more criteria called as externet location. And then call out that LexCorp, amongst all these IPSec locations, is allowed to access my application. So this is the IPSec location that I created, and I can create a policy like this. So let's look at the experience. So I have this VM here, and let me bring it up. All right, so I have this VM. First of all, what I'm going to do is I'm going to do a curl to PortQuiz, dig to PortQuiz.net. So if I do a dig to PortQuiz.net, you will see that it does not resolve to a real IP, even though PortQuiz.net is a public hosted website. However, if I do a curl to it, the access works just fine, right? And I'll show you the logs. So if you look at the logs, so if you go to logs, if you look at diagnostic, I can filter by a new client type that we have introduced, the client type known as externet, because this is a partner-initiated traffic. So if you look at this logs, the traffic came through the CES tunnel, the IPSec location that we just defined, and they were accessing PortQuiz.net, and this is the real IP address of the PortQuiz.net. What we also have is capability to use these same location in the firewall policies. So if we look at the firewall policies here, the same applications will be available. So if we can define the same location, so for example, the same extranet location that I just defined here, it's also available here. So I can specifically call out through my firewall policies that these are the applications that I'm allowed to access, right? So this helps you do a layer seven inspection of the application. You can also do a web SSL inspection provided your business partner can install a Zscaler SSL certificate. So the same applications, the same locations will also be available, for example, under URL filtering policy. So you have this full suite capability of inspecting all the applications and doing the SSL inspection provided if your partner can install Zscaler SSL certificate. Then again, because we do have these capabilities to inspect the application and the traffic goes through the ZIE inspection engine when the partner initiates the traffic, this also means that these logs will be available on the firewall insights or the web insights or the DNS insights. Thank you.

TL;DR

  • Zscaler's B2B extranet uses IPSec tunnels to connect business partners, with traffic selectors and DNS configurations defined per partner relationship
  • Application segments can be mapped directly to IPSec tunnels using a new extranet connector type, eliminating the need for traditional app connectors for partner applications
  • Bidirectional access is supported through granular access policies that control both outbound access to partner apps and inbound partner access to internal resources
  • Full security inspection applies to partner traffic including Layer 7 filtering, SSL inspection (with certificate installation), and comprehensive logging across all Zscaler insights platforms

Extranet Configuration and IPSec Tunnel Setup

This technical demonstration walks through Zscaler's B2B extranet configuration, showing how organizations can securely connect with business partners using IPSec tunnels. The setup begins with defining business partners under the B2B exchange extranet section, where traffic selectors (proxies) and DNS server placeholders are configured. An IPSec location is then provisioned with VPN credentials that partners use to establish tunnels to any Zscaler data center. On the ZPA side, a new extranet connector type is introduced, allowing application segments to be mapped directly to IPSec tunnels rather than traditional app connectors. The demonstration shows how a partner application (jira.lex.corp) resolves to a 164 IP address but remains accessible through the extranet tunnel, with granular access policies controlling which users can reach partner resources.

Bidirectional Access and Security Controls

The configuration supports bidirectional access, enabling partners to reach internal applications through the same IPSec tunnel infrastructure. By introducing a new client type called 'client connector' in access policies, administrators can define which partner locations can access specific internal applications. The platform provides comprehensive logging capabilities, tracking all partner-initiated traffic with detailed diagnostic information including real IP addresses and IPSec location identifiers. Zscaler's full security stack applies to partner traffic, including Layer 7 application inspection, firewall policies, URL filtering, and optional SSL inspection if partners install Zscaler's SSL certificate. All partner traffic flows through the ZIA inspection engine, making logs available across firewall insights, web insights, and DNS insights for complete visibility into B2B communications.

Chapters

0:00 - Extranet Configuration Overview
0:48 - IPSec Location Setup
1:27 - ZPA Server Groups and Application Segments
2:34 - Partner Application Access Demo
3:34 - Bidirectional Access Configuration
4:45 - Partner-Initiated Traffic Demo
5:54 - Security Inspection Capabilities

Key Quotes

0:29 "So I can use any of these proxies that is called as a traffic selector."
1:37 "So we have introduced a new connector type known as extranet."
2:07 "So that's an indication to ZPA that in order to access this application, go through this extranet tunnel."
4:14 "I've introduced a new client type known as client connector."
6:34 "You can also do a web SSL inspection provided your business partner can install a Zscaler SSL certificate."

FAQ

How do business partners establish connectivity to Zscaler for extranet access?

Partners use VPN credentials (pre-shared keys) defined in the IPSec location configuration to create IPSec tunnels to any Zscaler data center. The organization defines traffic selectors (proxies) and DNS server configurations for each partner relationship.

Can partners access internal applications through the same extranet tunnel?

Yes, bidirectional access is supported. Organizations create access policies using the 'client connector' client type and specify which extranet locations (partners) can access specific internal applications. Traffic is logged with the extranet client type identifier for visibility.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Zero Trust
  • Network Security
  • Technical Deep Dive
  • Demo
  • Identity & Access
  • B2B Extranet
  • IPSec Tunnels
  • Zero Trust Network Access
  • Partner Connectivity
  • Zscaler Private Access
  • Application Segmentation
  • Bidirectional Access Control
  • SSL Inspection
  • Traffic Logging
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler B2B Extranet Configuration & IPSec Tunnels

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Oct
                        08

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        10/08/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 10/08/2026
                          12:00 PM
                          10/08/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version