cloudflare-one-migrations
This skill guides you through migrating from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE environments to Cloudflare One. It covers migration assessments, policy mapping, dependency sequencing, and safe rollout staging with source-specific guidance for each platform.
Cloudflare One Migrations helps you plan and execute complete transitions from Zscaler, Palo Alto, legacy VPN, or other security stacks to Cloudflare One.
AI-generated summary based on this skill's SKILL.md
Decision gist · record as of 2026-07-24
Cloudflare One Migrations helps you plan and execute complete transitions from Zscaler, Palo Alto, legacy VPN, or other security stacks to Cloudflare One. This skill guides you through migrating from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE environments to Cloudflare One. It covers migration assessments, policy mapping, dependency sequencing, and safe rollout staging with source-specific guidance for each platform.
Use it when
- cloudflare-one-migrations covers migrating from Palo Alto NGFW and Prisma Access.
- cloudflare-one-migrations helps you retire legacy VPN by assessing current usage.
Verify before relying
Read SKILL.md below before installing (1 file). Open directory: indexed for reading, not audited.
Install
cloudflare/skills/cloudflare-one-migrations · repository language: Shell
Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.
Frequently asked questions
AI-generated answers based on this skill's SKILL.md and metadata
How do I migrate from Zscaler to Cloudflare One?
cloudflare-one-migrations guides you through a structured transition from Zscaler ZIA/ZPA to Cloudflare One. Start with a readiness assessment to map your ZIA policies, ZPA app segments, and connector groups to Cloudflare equivalents. The skill helps identify gaps, sequence dependencies, and stage rollout in phases—typically moving web filtering and DLP rules first, then access policies, then tunnel traffic. Plan for identity sync, TLS inspection settings, and connector placement differences.
What's involved in a Palo Alto to Cloudflare One migration?
cloudflare-one-migrations covers migrating from Palo Alto NGFW and Prisma Access. Map your firewall rules, app segments, and identity policies to Cloudflare Gateway rules, Access policies, and Tunnel configurations. The skill highlights vendor-specific gotchas: Palo Alto's app-based routing differs from Cloudflare's DNS/IP-based approach, and Prisma Access connector groups require rethinking for Cloudflare's architecture. Validate DLP and TLS inspection settings during transition.
How can I replace legacy VPN with Cloudflare One?
cloudflare-one-migrations helps you retire legacy VPN by assessing current usage, mapping VPN access rules to Cloudflare Tunnel and Access policies, and staging a safe cutover. Identify all dependent applications, users, and compliance requirements. The skill guides connector placement, split-tunnel configuration, and fallback strategies. Plan identity provider integration and test failover before full rollout to avoid service disruption.
What does a SASE to Cloudflare One transition assessment cover?
cloudflare-one-migrations provides readiness assessment for SASE platform transitions, evaluating your current SWG, firewall, VPN, and DLP posture. It maps policies and objects across vendors, identifies coverage gaps, and sequences implementation to maintain security. The skill flags partial mappings—some advanced threat prevention or custom routing may require workarounds—and recommends phased rollout with validation gates to ensure no security loss.
How do I map security policies and validate migrated rules?
cloudflare-one-migrations includes gap analysis tools to map source policies to Cloudflare One equivalents and validate coverage. Document each legacy rule's intent, then create corresponding Gateway DNS/HTTP rules, Access policies, and Tunnel routes. The skill helps you test migrated rules in shadow mode, compare allow/block decisions, and confirm DLP and TLS inspection behavior matches your baseline before switching traffic.
What vendor-specific gotchas should I know about?
cloudflare-one-migrations highlights key differences: Zscaler's connector groups and app-based routing differ from Cloudflare's DNS-centric model; Palo Alto's granular app control requires Gateway rule creativity; legacy VPN split-tunnel logic may not map directly. The skill documents partial mappings—some advanced threat feeds or custom routing may need alternative approaches—and recommends testing each vendor's migration path separately before full deployment.
SKILL.md
Rendered from the published skill. Quoted content, verbatim.
Cloudflare One Migrations
Retrieve current Cloudflare docs, Cloudflare API schemas, and source-vendor export docs before generating exact configuration.
Workflow
- Identify the source stack: Zscaler ZIA, Zscaler ZPA, Palo Alto NGFW/Prisma/GlobalProtect, legacy VPN/SWG/SD-WAN, or other.
- Request exports and logs before mapping. Prefer structured exports over screenshots or prose summaries.
- Build an inventory: identities, groups, apps, destinations, connectors/tunnels, DNS/URL/firewall/DLP/TLS policies, objects/lists, locations/sites, exceptions, hit counts, and compliance logging.
- Produce a mapping plan: source object, Cloudflare One target resource, confidence, prerequisites, unsupported/partial mappings, and manual decisions.
- Create dependencies first: identity/SCIM, connectors/on-ramps, routes/DNS, lists/objects, TLS bypasses, Access
(truncated - see the full file via the links below)
File tree — 1 file
skills/cloudflare-one-migrations/SKILL.md
Let your AI agent find skills like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.
wish › “Plan and execute a complete migration from legacy security stacks to Cloudflare One”
Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →
Related skills
Cloudflare One helps you architect and operate zero trust deployments spanning identity, traffic control, private networking, and data protection. It covers Access for app authorization, Gateway for traffic filtering, WARP for device connectivity, Tunnel for private network on-ramps, plus DLP, CASB, device posture, and identity federation. Use it to design topology, configure policies, troubleshoot connectivity, and review security posture across your infrastructure.
Replace VPN access to internal services using Cloudflare's Zero Trust platform, which combines identity verification, device compliance checks, and encrypted tunnels to protect dashboards, admin panels, and on-premises apps. Enforce DNS-level threat filtering and support remote teams without opening inbound ports.
Analyze HTTP traffic patterns in Cloudflare to spot suspicious IPs, bots, and scraping activity, then manage Custom Rules and Rate Limit Rules across zones. Export rules from one zone and port them to another with filtering and compatibility transforms for different plan tiers.
Expose any local HTTP service to the internet using your own domain through Cloudflare Tunnel, with zero inbound firewall configuration or certificate hassle. The skill handles tunnel creation, DNS setup, and cloudflared installation automatically while you manage the Cloudflare account and API token. Supports multiple sites on a single tunnel for efficient resource use.
Systematically identifies and resolves Cloudflare Tunnel connectivity failures that block remote access. Checks container status, validates tunnel tokens, analyzes logs for Error 1033 and QUIC issues, and provides targeted recovery commands.
Master firewall configuration across UFW, nftables, iptables, and cloud platforms like AWS, GCP, and Azure. This skill covers stateful and stateless rule patterns, defense-in-depth strategies, and safety practices to prevent lockouts while hardening servers and implementing network segmentation.
More skills cloudflare-zero-trust-access (MIT) · cloudflare-vpc-services (MIT) · Cloudflare (unlicensed) · cloudflare (Apache-2.0) · cloudflare-deploy (Apache-2.0)