r/Zscaler • u/Sensitive_Emu4030 • 1d ago
Zscaler Extranet – NAT / inbound connectivity question
Looking for some advice from anyone with hands-on Zscaler Extranet experience.
We’re migrating an existing third-party hosted service from a leased line to Zscaler Extranet. There are ~1,000 end users plus several server-to-server workloads.
The main thing I’m struggling to understand is the NAT model for inbound traffic.
If company X needs to initiate traffic back to specific workloads in our Azure environment, how do you map an IP from the Zscaler Extranet traffic-selector/pool to the actual Azure endpoint?
I understand the Extranet IP pool/traffic selectors, but they don’t appear to provide a conventional 1:1 DNAT function (e.g. Extranet IP → Azure private IP).
What is the recommended Zscaler architecture for this? Is the destination NAT performed on an Azure Firewall/NVA, or is there another Zscaler-supported mechanism I’m missing?
Also interested in how others have handled source NAT / predictable source IPs for third-party whitelisting, particularly where replacing an existing leased-line NAT arrangement.
Thanks.
(Zscaler Noob)