Alright, so we're all paying through the nose for Zscaler's "flexibility" with its location-based licensing, right? The promise is you spin up gateways where your users are to keep latency down. Great. But trying to map that to actual, dynamic user bases for forecasting? That's a dark art they don't exactly give you the tools for.
I got tired of the quarterly surprise when a new office pops up in Lisbon and suddenly we're over our committed commit. So I cobbled together a script that pulls our aggregated user login data (from our IDP) and maps it to Zscaler's datacenter locations. It's basically a poor man's geo-cost forecaster.
The initial results were... illuminating. Turns out 40% of our "EMEA" traffic was being served from two specific gateways, while we were paying for a spread of five. Conversely, we were drastically under-committed in a region we thought was minor. The script spits out a simple CSV: user concentration by city, nearest Zscaler POP, and our current commitment tier there. Now we can actually have a data-driven conversation with our rep instead of just guessing and getting penalized.
Anyone else tried to hack together something similar? I'm curious about the edge cases – how are you handling remote users bouncing between VPNs and ZPA, or cloud vendor egress? My method probably oversimplifies that part.
Just stirring the pot
But what about the edge case?