要求提供的生产导出和日志可能暴露敏感网络及身份信息
原文依据:2 处该 Skill 要求结构化导出和日志,并盘点用户、群组、内部应用、目标地址、隧道、DNS、防火墙、DLP、TLS 例外及合规日志。这些资料可揭示内部拓扑、安全规则、身份结构和业务活动。
如果用户把未清理的生产资料提交给未经批准的 AI 服务、共享工作区或不受控的会话,相关服务的运营者或其他工作区成员可能获得这些敏感信息。
这是迁移评估所需的合法资料,但其中包含身份、内部应用、地址、隧道、安全策略、例外和活动日志;若上传给模型或交给未获授权的人员,可能暴露内部拓扑、访问关系及业务活动。用户可要求作者说明资料会发送到哪里、保留多久,并仅提供脱敏、最小范围的导出。
1. Identify the source stack: Zscaler ZIA, Zscaler ZPA, Palo Alto NGFW/Prisma/GlobalProtect, legacy VPN/SWG/SD-WAN, or other.2. Request exports and logs before mapping. Prefer structured exports over screenshots or prose summaries.3. Build an inventory: identities, groups, apps, destinations, connectors/tunnels, DNS/URL/firewall/DLP/TLS policies, objects/lists, locations/sites, exceptions, hit counts, and compliance logging.4. Produce a mapping plan: source object, Cloudflare One target resource, confidence, prerequisites, unsupported/partial mappings, and manual decisions.查看另外 1 个位置
- ZIA: URL filtering, firewall filtering, SSL inspection, DLP, custom URL categories, IP groups, network services/service groups, users/groups/departments, locations, GRE tunnels, and static IPs.- ZPA: app segments, segment groups, server groups, app connectors/connector groups, access policies, IdP/group mapping, private DNS domains, ports, and protocols.- Palo Alto/Prisma: security/NAT/decryption rules, address/service objects and groups, URL categories, HIP profiles, GlobalProtect config, Prisma Access remote network/service connection config, zones, tags, logs, and hit counts.