Create a new application segment. Define the address and port ranges (you can use the default ports in the screenshot below), enable status and SIPA. Leave all other settings as their defaults unless advised otherwise.
Add a new segment group if you hadn’t already created one beforehand:
Add a new server group if you hadn’t already created one beforehand. Select appropriate app connector groups depending on the application:
Review and Save settings.
Create a new access policy for the application if there isn’t one set up:
Create 2 client forwarding policies. One for ‘Bypass’ one for ‘Allow’
For domain-based applications, configure the following rules:
- Rule 1: Select the Bypass ZPA rule action for Source IP Anchoring Segment Groups and add all client types, except ZIA Service Edge client type:
- Rule 2: Select the Forward to ZPA rule action for Source IP Anchoring Segment Groups and add only the ZIA Service Edge client type:
From here, load the website. It should load normally; if not, review your settings.
For full article, see official Zscaler documentation:
https://help.zscaler.com/zia/configuring-source-ip-anchoring
https://help.zscaler.com/zia/understanding-source-ip-anchoring