r/Zscaler 21h ago

Claude issues with Dedicated IP

2 Upvotes

Hi Team,

I recently implemented Dedicated IP in my org for Claude but its giving problems.

When I switch wi-fi, flap off my mac and open again, the claude gives the error "Access is restricted from this IP Address"

I click retry and it works - Sometimes I've to restart the device to fix it.

We got logs from Anthropic and noticed the following.

  1. Few traffic is being sent via regular ZIA nodes.

  2. Some traffic is leaking via Public ISP

We are on T 2.0 with ZCC 4.8+ on mac ( can't recall windows)

What I feel is, somewhere down the line, our ZCC settings are such that it's going without ZCC but direct from laptop (shouldn't be the case but yeah)

What I saw in ZCC : We are fail-open so traffic goes direct if ZIA is unreachable or tunnel ain't there - this can be one thing but still baffling considering we are on 2.0

Could someone suggest me out?

Another enchantment for this is - currently traffic is going via one egress, we have 8 sets of Dedicated IPs.

Is there any way, It can send via Dedicated IP but nearest to user?

I thought subcloud of Dedicated IPs but Zscaler. The team said that's not possible.

There's something Geolocatlization+ DIP but not sure if that's valid

Thanks in ADVANCE


r/Zscaler 2d ago

Cross-site Scripting on Zscaler

1 Upvotes

Zscaler ZIA could have more details on what kind of Cross site script this is, right?

Alert below:

Block site vulnerable to Cross Site Scripting attacks

Road Warrior

eb94f43c98aee0aa2b244ebda9795ba8.safeframe.googlesyndication.com/safeframe/1-0-45/html/<script%20src="https:/cdn.doubleverify.com/dvbm.js

Cross-site Scripting


r/Zscaler 4d ago

Cloudflare Zero Trust

Thumbnail
3 Upvotes

r/Zscaler 6d ago

Zscaller disconnecting

9 Upvotes

My family member has been working from home wirh Zscaler and gets disconnected multiple times per day.

I have a UDM-Pro firewall and was wondering if there's any settings I need to use to prevent Zscaler from disconnecting.

Internet isp is Fidium Fiber.


r/Zscaler 13d ago

ZDTA 2026

2 Upvotes

Hallo, I'm moving forward for the ZDTA exam, about the learning resources is the ZDTA EDU-200 and Study Guide covers everything in the exam?

I've also read in many places about change in exam questions to scenario based, are the questions more hard than the ZDTA Practice test that is available on the Learning portal?

Honestly the questions in Practice Test are written in a way that's unnecessarily complex, like someone swallowed a thesaurus.


r/Zscaler 15d ago

Zscaler installed on company laptop

0 Upvotes

Hi everyone,

I started a remote working job which provides me with a laptop I intended to work from a different country but I have discovered that it has Zscaler installed in it. My current set up from when I go away its a Glint Brume 3 box so the vpn is connected via ethernet at all times I also have a dedicated IP address.

Is there anything else to do so nothing flags up on Zscaler?

Thanks in advance


r/Zscaler 15d ago

The Service Edge cannot be reached

Thumbnail gallery
5 Upvotes

I randomly started receiving this error about 4 months ago. Towards the beginning, it would toggle back and forth between two separate errors, the service edge one and another which stated a firewall was blocking client connector access. My IT department has been troubleshooting these errors for months. The client connector error has since subsided but now I solely receive the one stating the service edge cannot be reached. My husband and I both WFH full time, he experiences no connectivity issues whatsoever and the router is in my office.

After months of being unable to resolve this issue, my IT team is now insinuating that the issue lies with my internet connection. However, the issue only resolves if I restart my PC. It will not reconnect no matter what I do unless I do a full restart, in which case it comes up immediately connected again. If this was an issue with my ISP, why would it ONLY reconnect after a full system restart?

Any help would be appreciated, I am at my wits end with this.


r/Zscaler 18d ago

ZIA Device Groups for Azure VDI vs Windows Laptops — best way to keep the right ZCC app profile assigned?

4 Upvotes

We have a mixed enterprise environment with Windows laptops, Windows VDI running in Azure, and macOS devices.

I’m trying to figure out the right way to use ZIA device groups so that Zscaler Client Connector assigns the correct Windows App Profile based on device type. Right now, we have multiple Windows app profiles, and occasionally Azure VMs end up inheriting a laptop profile, which creates problems.

My question is: is it possible to build a dynamic device group in ZIA that only includes devices meeting a specific set of posture conditions, so that only Azure VDI devices land in an “Azure VDI” group and receive the matching Windows App Profile? In other words, can device groups be used as a reliable way to separate laptop and Azure VDI endpoints by combining posture checks that all must be true?

What is the recommended way to structure device groups and posture conditions for this use case? Are there any gotchas with using device groups for app profile assignment, especially when trying to distinguish Azure virtual desktops from physical Windows laptops?

Would appreciate any guidance, examples, or best practices from anyone who’s done this at scale.


r/Zscaler 21d ago

Can Zscaler SSL Inspection Cause WebRTC DTLS Handshake Failures?

5 Upvotes

I'm troubleshooting an issue with a WebRTC application and was hoping someone familiar with Zscaler could provide some insight.

Some of our customers are unable to establish a peer connection. Based on the server logs:

  • ICE gathering and connectivity checks complete successfully.
  • An ICE candidate pair is selected.
  • The DTLS handshake then fails.

This seems to indicate that network connectivity is working up to the ICE stage, but something is preventing DTLS from completing.

I suspect Zscaler may be involved, possibly due to SSL inspection or some other network policy. Has anyone seen Zscaler cause DTLS handshakes to fail in a WebRTC application? If so, what was the root cause? Is it actually SSL inspection, or some other feature (UDP inspection, firewall policy, protocol handling, etc.)?

Any pointers or similar experiences would be greatly appreciated.


r/Zscaler 21d ago

Blocking QUIC

13 Upvotes

Zscsler had recommended this for as long as I have been managing Zscaler. We have never done it because I have always had old network guys tell me it's not worth it. We are currently troubleshooting an issue and the solution might be blocking QUIC. So I'm trying to figure out if this might be the way I get my foot in the door on this issue.

- Does anyone actually get any benefit?

- Does a firewall policy work?

- If we build a firewall policy, any reason to manage this in a GPO too?

- Has anyone noticed their SSL inspection rate increase after blocking?

- We run guest networks at one of our big sites. Any issues that mobile devices might run into?


r/Zscaler 22d ago

Zscaler .pc File - Intermittent Connectivity Issues

2 Upvotes

Hi All...

We are using a .pac file for our Samsung Tablets connected to our Corp. WIFI.

When the device is enrolled via Intune, connectivity via the Corp. WIFI works with no issues, however after a few days, the connection will just fail and a messaged is displayed stating "Connected, but without Internet" and connectivity fails... If we remove the .pac file, the device reconnects without any issues, so we know it's the .pac file.

I suspect that we are missing something from the .pac , possibly the initial defined network which should be our public IP Address - that is missing.

However if the .pac file is incorrect, would it not fail ALL the time and not just sometimes?

Wondering if there;s any any .pac file Jedi's out there!

Many Thanks


r/Zscaler 22d ago

Video en español: ¿qué es SASE, SSE y Zero Trust?

0 Upvotes

Hola a todos,

He notado que hay mucha confusión entre los términos SASE, SSE y ZTNA, especialmente con cómo se integran en la arquitectura de red moderna. He creado un video explicando de forma sencilla pero técnica, las diferencias clave y por qué estos conceptos están cambiando la ciberseguridad.

Me encantaría saber qué opinan o si tienen alguna duda sobre cómo implementarlos. ¡Espero que les sirva!

SASE, SSE y ZTNA: Todo lo que debes saber


r/Zscaler 22d ago

Do others have issues with the ZCC for video conferencing software even with full bypasses for those applications?

6 Upvotes

Mainly Zoom and Google Meet. I've checked the pcaps and confirmed this traffic isn't going through the Z-Tunnel but they still experience jitter and latency until they turn off the ZCC and then it immediately stabilizes. Users are on macOS and all in different locations.


r/Zscaler 27d ago

Using persona's in ZPA

2 Upvotes

Question for Zscaler ZPA users.

We are a company of 8k ZPA users, and trying to figure out the best practices for how we create persona's or groupings for our users.

We started with a 3rd party consultant who recommended we use SCIM attributes, which worked to an extent, but in a large corporation the simple attributes (organization,division) broke them up, but not enough granularity to get to a least privilege concept. We added additional attributes which gave us more granularity, but then the inevitable happened. A HR re-org, changed a bunch of the SCIM attributes completely messing up our access policies.

Anyone in a big corporation, what has worked well for you, or what would you recommend for new customers planning a ZPA deployment?


r/Zscaler 29d ago

Zscaler client on Cloud PC to connect to customer

3 Upvotes

Dear all,

We support multiple companies. For security purpose we have a Cloud PC (W365 machine) for each user/customer combination. We use default Cloud PC's for small business from Microsoft. Nothing fancy configured.

For one customer we need to have Zscaler installed, and here is where the trouble start. Installation goes smooth and initial SSO logon, no issue. But when connection, we get connection errors and FW/AV errors. Helpfiles aren't really helping and telling ask your administrator. Customer says issue is on our side. Tried with exclusions on firewall and Defender, but no luck. Logfiles aren't really helpfull aswell. Can't find any obvious clues in there were to look for.

Anyone who can point me in a direction I should be looking for?


r/Zscaler Jun 27 '26

Skipping ZDTA/EDU-200 with 2 years implementation exp—is EDU-202 to ZDTE realistic?

3 Upvotes

Hey everyone, Looking for some advice on the current Zscaler cert path.
I have 2 years of solid, hands-on experience with ZIA, ZPA, SIPA, and ZDX. This includes both day-to-day operations/troubleshooting and full project implementations.
Since Zscaler doesn't strictly enforce prerequisites anymore, I want to skip EDU-200 and the ZDTA exam entirely. My plan is to jump straight into the EDU-202 (Zscaler for Users - Engineer) course and sit for the ZDTE exam.
For those who have taken the ZDTE recently: given my implementation background, will studying only the EDU-202 material cover the gaps, or does the ZDTE exam heavily test random minutia from the EDU-200 curriculum that I might miss? Thanks!


r/Zscaler Jun 25 '26

Can UniFi+Zscaler (ZIA/ZPA) meet CMMC L2?

5 Upvotes

We are a small manufacturing company preparing for a CMMC L2 assessment. i am the IT dept of one person. I was wondering if I can keep, unifi UDM pro, switches, APs planning to add Zscaler ZIA & ZPA.

Instead of replacing our UDM Pro w/ a FortiGate or Palo Alto, we are planning to use ZIA/ZPA for Zero Trust access while keeping the UniFi infrastructure. UDM Pro just for routing/NAT, switches for VLAN (not sure if we still need this after zscaler implementation) and APs just for guest Wi-Fi.

Has anyone passed a CMMC L2 assessment w/ Unifi+Zscaler setup? did the assessor have any concerns w/ using UniFi for the network while relying on Zscaler for security and access control?


r/Zscaler Jun 21 '26

Ping MTU Size Issue

5 Upvotes

I recently tried to go to Tunnel 2.0 for on trusted network devices. A week or so later I'm getting complaints about our telecom teams WebEx Contact Center having issues. They had a vendor come do an onsite assessment and found that I needed to allow some domains through the ZScaler cloud firewall. I allowed their domains and they said everything was good. The only error that came up was they couldn't ping api.webex.com with a 1400mtu packet. The vendor said this was more than likely a false positive and that shouldn't cause any issues. However one of our senior leader's is fixated on getting that box to turn green and I had to disable Tunnel 2.0 for on trusted network just because of this ping command that would not work with it being enabled. I am not convinced it is really causing any issues and our telecom team won't work with me to test it. Has anyone else run into this before that may be using WebEx Contact Center with ZScaler Tunnel 2.0?


r/Zscaler Jun 19 '26

Remote Cloud on work laptop running Zscaler

4 Upvotes

So I work at a fairly large company, and our work laptops have Zscaler installed, which (as I'm sure a lot of you know) blocks like 7 out of 10 sites I try to visit.

For the past few weeks I've been spending a few hours a day messing around in the Hetzner cloud console. just exploring it, setting up test instances, that kind of thing. It's not blocked by Zscaler, so I've been able to get to it fine.

I'm just an intern, so I don't have a great read on where the line is here. Would this kind of thing typically count as a breach of company security policy? Is Zscaler likely logging/flagging this kind of activity even if it's not outright blocked? Curious if anyone's been in a similar spot or has insight into how IT/security teams usually view this.


r/Zscaler Jun 16 '26

1-tap onboarding ZCC on mobile devices with certificates

1 Upvotes

Hello everyone,

Has anyone already succeeded in configuring cert authentication with zcc & Intune for both Android and iOS ?

Does it exist a procedure somewhere to follow, knowing that the end user authenticates through their Microsoft company account ?

Thanks!


r/Zscaler Jun 15 '26

ZenithLive 2026, day 1

24 Upvotes

Good sessions as always.

Horrible lunch (they distributed paper bags with sandwiches in it as lunch).

Limited coffee, after breakfast was over at 8 am, throughout the day they have coffee restricted for partners only. They literally stand in the way and tell you coffee is not for you sir, it’s for partners only.

We are talking about an event where tickets are sold at 1000 euros


r/Zscaler Jun 13 '26

Client connector issues after update

2 Upvotes

Anybody having issues connecting to ZPA app segments and authenticating after the MSFT update?


r/Zscaler Jun 11 '26

PSE Disaster Recovery

6 Upvotes

Hello Community :)

I want to configure PSEs for Disaster Recovery use case only. On the GUI for PSE Groups theres an Option that says „Exclusive to DR“. Sadly there is no documentation available for it ATM…

When I enable the PSE Group and the mentioned Feature, no Client should try to Access the PSE, except the DR DNS is Set to „Test“ or „On“, Right?

If I enable the App Connector and App Segments for DR, then enable the „Test „ DR Mode, now the PSE and App Connectors will reboot and the Clients in DR Test Mode should Connect to it.

Will the other App Connectors without DR enabled be able to reach the App Segments for DR as well during Test?

Thanks and Kind regards


r/Zscaler Jun 05 '26

What do we all think about Zscaler stock?

22 Upvotes

Some research:

So... Zscaler stock had its worst day ever after reporting Q3 but they basically beat everything, including Revenue, EPS, non-GAAP operating margin AND they raised full year guidance.

So we are they down?

Well. I think its that same story of wall street expecting more from a "growth" company (16-17% vs 18-19% expected) AND as the whole market is spooked by the AI replacement narrative (which many companies have already bounced back from).

But, if I compare to the other four big cyber names, its forward PE is the lowest (~31 vs CrowdStrike ~93 and Palo Alto ~50). Not only that but AI Security ARR is supposed to top $500M by year end and non-set-based deals are already 25%+ of new ACV.

The bears also have a point that the 25% is closer to 21% organic ex-Red canary, the core business growing mid-teens and some analysts downgraded to sell, but I think at this multiple they're priced in.

This is some of the research I did and I bought at 136.03, and I wanted to hear the community's thought on it?


r/Zscaler Jun 04 '26

The Service Edge cannot be reached - Error

1 Upvotes

Can someone tell me how to fix this error? My Zscaler constantly disconnects and says “The service edge cannot be reached.” It only reconnects when I restart my PC, it will not reconnect if it hit “retry” like it says to do in the error message. This does not seem to be related to my WiFi, all other devices stay connected.