skillfed

cloudflare-one-migrations

This skill guides you through migrating from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE environments to Cloudflare One. It covers migration assessments, policy mapping, dependency sequencing, and safe rollout staging with source-specific guidance for each platform.

Cloudflare One Migrations helps you plan and execute complete transitions from Zscaler, Palo Alto, legacy VPN, or other security stacks to Cloudflare One.

AI-generated summary based on this skill's SKILL.md

2,499 235 Apache-2.0 updated by cloudflare

Install

cloudflare/skills/cloudflare-one-migrations · repository language: Shell

git clone https://github.com/cloudflare/skills
cp -r skills/skills/cloudflare-one-migrations ~/.claude/skills/cloudflare-one-migrations
npx skillfed install cloudflare/skills/cloudflare-one-migrations

Frequently asked questions

AI-generated answers based on this skill's SKILL.md and metadata

How do I migrate from Zscaler to Cloudflare One?

cloudflare-one-migrations guides you through a structured transition from Zscaler ZIA/ZPA to Cloudflare One. Start with a readiness assessment to map your ZIA policies, ZPA app segments, and connector groups to Cloudflare equivalents. The skill helps identify gaps, sequence dependencies, and stage rollout in phases—typically moving web filtering and DLP rules first, then access policies, then tunnel traffic. Plan for identity sync, TLS inspection settings, and connector placement differences.

What's involved in a Palo Alto to Cloudflare One migration?

cloudflare-one-migrations covers migrating from Palo Alto NGFW and Prisma Access. Map your firewall rules, app segments, and identity policies to Cloudflare Gateway rules, Access policies, and Tunnel configurations. The skill highlights vendor-specific gotchas: Palo Alto's app-based routing differs from Cloudflare's DNS/IP-based approach, and Prisma Access connector groups require rethinking for Cloudflare's architecture. Validate DLP and TLS inspection settings during transition.

How can I replace legacy VPN with Cloudflare One?

cloudflare-one-migrations helps you retire legacy VPN by assessing current usage, mapping VPN access rules to Cloudflare Tunnel and Access policies, and staging a safe cutover. Identify all dependent applications, users, and compliance requirements. The skill guides connector placement, split-tunnel configuration, and fallback strategies. Plan identity provider integration and test failover before full rollout to avoid service disruption.

What does a SASE to Cloudflare One transition assessment cover?

cloudflare-one-migrations provides readiness assessment for SASE platform transitions, evaluating your current SWG, firewall, VPN, and DLP posture. It maps policies and objects across vendors, identifies coverage gaps, and sequences implementation to maintain security. The skill flags partial mappings—some advanced threat prevention or custom routing may require workarounds—and recommends phased rollout with validation gates to ensure no security loss.

How do I map security policies and validate migrated rules?

cloudflare-one-migrations includes gap analysis tools to map source policies to Cloudflare One equivalents and validate coverage. Document each legacy rule's intent, then create corresponding Gateway DNS/HTTP rules, Access policies, and Tunnel routes. The skill helps you test migrated rules in shadow mode, compare allow/block decisions, and confirm DLP and TLS inspection behavior matches your baseline before switching traffic.

What vendor-specific gotchas should I know about?

cloudflare-one-migrations highlights key differences: Zscaler's connector groups and app-based routing differ from Cloudflare's DNS-centric model; Palo Alto's granular app control requires Gateway rule creativity; legacy VPN split-tunnel logic may not map directly. The skill documents partial mappings—some advanced threat feeds or custom routing may need alternative approaches—and recommends testing each vendor's migration path separately before full deployment.

SKILL.md

rendered from the published skill — quoted content, verbatim

Cloudflare One Migrations

Retrieve current Cloudflare docs, Cloudflare API schemas, and source-vendor export docs before generating exact configuration.

Workflow

  1. Identify the source stack: Zscaler ZIA, Zscaler ZPA, Palo Alto NGFW/Prisma/GlobalProtect, legacy VPN/SWG/SD-WAN, or other.
  2. Request exports and logs before mapping. Prefer structured exports over screenshots or prose summaries.
  3. Build an inventory: identities, groups, apps, destinations, connectors/tunnels, DNS/URL/firewall/DLP/TLS policies, objects/lists, locations/sites, exceptions, hit counts, and compliance logging.
  4. Produce a mapping plan: source object, Cloudflare One target resource, confidence, prerequisites, unsupported/partial mappings, and manual decisions.
  5. Create dependencies first: identity/SCIM, connectors/on-ramps, routes/DNS, lists/objects, TLS bypasses, Access

(truncated - see the full file via the links below)

Read as markdown · JSON record · Browse the source repository

File tree — 1 file
skills/cloudflare-one-migrations/SKILL.md

Related skills

Tags

vendor-consolidation security-stack-replacement policy-translation multi-product-migration zero-trust-transition infrastructure-modernization compliance-mapping rollout-orchestration