icon-unified.svg
Experience Center

About Application Service Groups

Zscaler provides predefined application service groups to enable in your firewall filtering policy and forwarding policies.

Application service groups provide the following benefits and enable you to:

  • Configure firewall rules and forwarding rules based on the predefined application service groups provided by Zscaler.
  • Enforce condition-based actions on your network traffic, such as allowing or blocking traffic and forwarding traffic to specific destinations.

Zscaler's application services are identified at the first packet and therefore can result in the policy action hitting that first packet. The custom firmware pre-assembles the metadata received from the first packet, such as the domain and subdomains, along with their destination IP addresses, protocol types, and ports to identify the associated application service. This is different from the identification of packets for network applications. This means that policies using application services should be in a higher priority rule than a similar policy using network applications so that the former can be matched first. To learn more, see About Network Applications.

The Application Service Groups page holds a static list of application service groups that you can use as criteria when configuring your firewall filtering policy and forwarding policies. On this page, you can view the list of available service groups and search for a service group from the list.

About the Application Service Groups Page

On the Application Service Groups page (Policies > Access Control > Firewall > Application Services), you can do the following:

  1. View the list of predefined application service groups provided by Zscaler.
  2. Search for an application service group by name.
  3. Sort the application service groups alphabetically.

Related Articles
About Network ServicesConfiguring Network ServicesModifying Predefined Network ServicesAbout Network Service GroupsConfiguring Network Service GroupsAbout Network ApplicationsAbout Network Application GroupsConfiguring Network Application GroupsAbout Application Service GroupsAbout Source IP GroupsConfiguring Source IP GroupsAbout Destination IP GroupsConfiguring Destination IP GroupsAbout DNS Application GroupsConfiguring DNS Application GroupsAbout IP PoolAbout Threat CategoriesAdding Threat CategoriesAbout EDNS Client Subnet (ECS) InjectionAdding EDNS Client Subnet (ECS) PrefixesAbout DNS GatewaysAdding DNS Gateways