Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

These are the phases of the integration deployment:

Phases

Overview

Guide

Important considerations

NSS Server deployment

You will deploy and install the required NSS Servers in your AWS account where you will receive the NSS Feeds from Zscaler Nanolog.

How to set up an NSS server

Each NSS Server accepts a maximum of 8 NSS feeds. Firewall and DNS feeds require a separate NSS server.

Devo In-House Relay deployment

You will deploy a Devo Relay in your AWS account to receive the TCP feeds from NSS Servers.

How to set up the Devo Relay

Docker images can be easily deployed to EC2 or ECS in AWS. Configure the Devo In-House Relay security group so that it can be reached from the NSS servers.

Devo Relay rule creation

You will set up a new rule in your Devo account for each NSS Feed that you plan to receive from your deployed NSS Servers.

Defining a relay rule

Check our Devo Relay settings proposal for Zscaler NSS feeds.

Devo token and endpoint configuration

You will create a token classifying the events and HTTP ingestion, then you will assign it to the Devo endpoint corresponding to your Devo cloud region.

HTTP endpoint

Once you have copied you’re the API key, you can set up the Cloud NSS integration in your Zscaler console.

NSS feeds creation

You will set up your planned NSS Feeds in your Zscaler account.

How to set up an NSS feed

Check our Devo Relay settings proposal for Zscaler NSS feeds.

NSS server final checking

You will check that the TCP connections from NSS Server to Devo Relay have been established.

Troubleshooting NSS

-