Why would you do that when we do all the same functionality or better on the gateway itself using the various NGTX blades? 🙂
Personally, I haven't seen an integration guide myself.
Historically, they've wanted to use GRE, which is something we don't support.
Here's what Zscaler has to say: https://help.zscaler.com/zia/configuring-ipsec-vpn-tunnel
Part of what they say here isn't true because:
1. From R80.30, we can support MEP with DPD with third party peers.
2. What is sent down the tunnel is "all ports and protocols."
What is true is that it would require some complex configuration to send only 80/443 traffic down the VPN tunnel.
My guess is that involves NON_VPN_TRAFFIC_RULES.
And I guess you have to disable NAT-T support, as their document says.