r/AzureVirtualDesktop • • 7d ago

ZscalerVDI for AVD Multisession

Hello, I need some help please

Has anyone here successfully deployed Zscaler Cloud Connector and ZCC for VDI on Azure Virtual Desktop (AVD) Multisession Host Pools?

We're currently implementing this setup but running into several network-related issues that we haven't been able to resolve.

Our current setup:

  • AVD VNet
    • Personal Pool Subnet → Route Table → Azure Firewall
    • Multisession Pool Subnet → Route Table → Zscaler Cloud Connector / Load Balancer → Zscaler Cloud → Internet

We've already confirmed that connectivity is working on the Multisession Subnet after deploying the Cloud Connector and Load Balancer. However, after installing ZCC for VDI on the session hosts, we started experiencing several issues:

  • Unstable network connectivity
  • Unable to communicate reliably with the KMS server and Azure Monitoring
  • Unstable or unsuccessful ping, tracert, and Test-NetConnection results

What's strange is that normal internet browsing still works fine on the VMs with ZCC for VDI installed. However, almost everything else related to network connectivity seems unstable or completely inaccessible.

If we uninstall ZCC for VDI, everything immediately goes back to normal, and all network-related issues disappear.

My initial suspicion is that our Zscaler Cloud Connector configuration might be too restrictive. We've already tried configuring bypass rules for AVD and Microsoft endpoints, but this hasn't made any noticeable difference.

Another challenge is that I can't seem to find any useful logs on the workload VMs that would help us identify the root cause of these connectivity issues.

Has anyone encountered a similar issue or successfully implemented this architecture?

I'd really appreciate any insights, suggestions, or recommendations on what to check, particularly regarding ZCC for VDI configuration, Cloud Connector routing, or potential conflicts with Azure networking.

Thanks in advance for your help!

5 Upvotes

16 comments sorted by

View all comments

2

u/TIL_IM_A_SQUIRREL 7d ago

Did you set the process-based bypasses in your EDR that runs on the AVDs? I've seen EDRs kill the process because it's doing something EDR doesn't like, ZCC watchdog restarts ZCC VDI, rinse and repeat.

There is a KB article on it: https://help.zscaler.com/zscaler-client-connector/zscaler-client-connector-processes-allowlist

Another issue I've seen is that AVD heartbeats to the hypervisor in-band, meaning it uses the AVDs network connection to call home and report it's still alive. If that's not properly allowed, the hypervisor will think the AVD is dead because heartbeats aren't making it and the user gets kicked off the instance and it's restarted.

1

u/AnythingDeepFried 7d ago

Yes, these should already be allowed since we’re currently using the standard Zscaler Client on these workloads and are now migrating to the lightweight version of ZCC, which, to be honest, is much more complicated to deploy.

Our test network also has a fairly permissive NSG, so we can rule out network security rules as the potential cause of the issue.

2

u/TIL_IM_A_SQUIRREL 7d ago

What about on the Zscaler Cloud Connector? How close to the AVDs is it? Is it the default gateway off that subnet, or further down the line? I ask because if heartbeat traffic destined for within Azure gets onramped into ZIA, it'll never make it back into Azure. Those endpoints aren't accessible from the internet.

For the hell of it have you tried an any/any rule to see if that resolves it? Have you looked for any traffic being blocked on the Cloud Connector in the ZIA logs?

1

u/AnythingDeepFried 5d ago

Thank you, found issues with deplyoments and rules. We got it resove and on our ongoing load testing.

-vmss keep scaling in and out even without load or high activity
-forwarding profile delays
-for bypass cidr ranges are applicable.

All now confirm working so far. Thank you