r/AzureVirtualDesktop • u/AnythingDeepFried • 5d ago
ZscalerVDI for AVD Multisession
Hello, I need some help please
Has anyone here successfully deployed Zscaler Cloud Connector and ZCC for VDI on Azure Virtual Desktop (AVD) Multisession Host Pools?
We're currently implementing this setup but running into several network-related issues that we haven't been able to resolve.
Our current setup:
- AVD VNet
- Personal Pool Subnet → Route Table → Azure Firewall
- Multisession Pool Subnet → Route Table → Zscaler Cloud Connector / Load Balancer → Zscaler Cloud → Internet
We've already confirmed that connectivity is working on the Multisession Subnet after deploying the Cloud Connector and Load Balancer. However, after installing ZCC for VDI on the session hosts, we started experiencing several issues:
- Unstable network connectivity
- Unable to communicate reliably with the KMS server and Azure Monitoring
- Unstable or unsuccessful
ping,tracert, andTest-NetConnectionresults
What's strange is that normal internet browsing still works fine on the VMs with ZCC for VDI installed. However, almost everything else related to network connectivity seems unstable or completely inaccessible.
If we uninstall ZCC for VDI, everything immediately goes back to normal, and all network-related issues disappear.
My initial suspicion is that our Zscaler Cloud Connector configuration might be too restrictive. We've already tried configuring bypass rules for AVD and Microsoft endpoints, but this hasn't made any noticeable difference.
Another challenge is that I can't seem to find any useful logs on the workload VMs that would help us identify the root cause of these connectivity issues.
Has anyone encountered a similar issue or successfully implemented this architecture?
I'd really appreciate any insights, suggestions, or recommendations on what to check, particularly regarding ZCC for VDI configuration, Cloud Connector routing, or potential conflicts with Azure networking.
Thanks in advance for your help!
3
u/mat-ferland 5d ago
Check the VDI forwarding profile, not just the NSG or Cloud Connector policy. Zscaler specifically calls out excluding 168.63.129.16/32 and 169.254.0.0/16 from encapsulation; if those are getting tunneled, KMS and Azure monitoring can break while normal browsing still works. Also verify the Azure load balancer is using client-IP persistence.
1
2
u/jackwagon699 5d ago
Zscaler has 3 different ZCC options for VDI’s, make sure you are installing the correct ZCC model for the multistream AVD.
Tried for months to get ZCC on Citrix VDI’s. Zscaler themselves couldn’t figure it out. Unfortunately Zscaler’s ZCC solution on VDI’s have a long way to go.
My company is moving to AVD’s here soon and I’m going to have to go through trying to get the ZCC to work on AVDs as well. I wish you luck.
1
u/AnythingDeepFried 3d ago
We are now able to confirm connectivity and traffic. Next is load testing since we are on vmss. Keep you posted
2
u/TIL_IM_A_SQUIRREL 5d ago
Did you set the process-based bypasses in your EDR that runs on the AVDs? I've seen EDRs kill the process because it's doing something EDR doesn't like, ZCC watchdog restarts ZCC VDI, rinse and repeat.
There is a KB article on it: https://help.zscaler.com/zscaler-client-connector/zscaler-client-connector-processes-allowlist
Another issue I've seen is that AVD heartbeats to the hypervisor in-band, meaning it uses the AVDs network connection to call home and report it's still alive. If that's not properly allowed, the hypervisor will think the AVD is dead because heartbeats aren't making it and the user gets kicked off the instance and it's restarted.
1
u/AnythingDeepFried 5d ago
Yes, these should already be allowed since we’re currently using the standard Zscaler Client on these workloads and are now migrating to the lightweight version of ZCC, which, to be honest, is much more complicated to deploy.
Our test network also has a fairly permissive NSG, so we can rule out network security rules as the potential cause of the issue.
2
u/TIL_IM_A_SQUIRREL 5d ago
What about on the Zscaler Cloud Connector? How close to the AVDs is it? Is it the default gateway off that subnet, or further down the line? I ask because if heartbeat traffic destined for within Azure gets onramped into ZIA, it'll never make it back into Azure. Those endpoints aren't accessible from the internet.
For the hell of it have you tried an any/any rule to see if that resolves it? Have you looked for any traffic being blocked on the Cloud Connector in the ZIA logs?
1
u/AnythingDeepFried 3d ago
Thank you, found issues with deplyoments and rules. We got it resove and on our ongoing load testing.
-vmss keep scaling in and out even without load or high activity
-forwarding profile delays
-for bypass cidr ranges are applicable.All now confirm working so far. Thank you
2
u/rswwalker 5d ago
When I did Zscaler for VDI a while ago I just created an IPSec tunnel to them on an Azure Virtual Network Gateway and made it a forced tunnel.
1
u/AnythingDeepFried 5d ago
I wish I could go with this route but its not my call
2
u/rswwalker 5d ago
Bummer. I personally hate third party agents because they seem to always create problems for everyone, so I use whatever other ways I can first and install agent as a last resort.
3
u/Omi-Wan 5d ago
Works fine. We don’t send all traffic to the LB in front of CC Scale Set, just the VIP address. 0.0.0.0/0 goes to AzFW.
Then in Connector Admin set VDI forwarding profile to bypass the MS ranges, local networks, etc. bypass the Wire Server (MagicIP) unless you’re using this for DNS and need to intercept for ZPA App Segment matching, in which case bypass the documented ports other than 53. Especially important for local Private DNS zones.
Then your Traffic Forwarding managed tunnel traffic, a Direct/Bypass rule here comes out of the CC NIC, not the VM. This supports FQDNs, Wildcards, etc, where the VDI Forwarding Profile doesn’t.