Zscaler Connectivity
Public egress as seen by independent services, plus Zscaler indicators.
Status
Each line shows how the information was obtained.
Zscaler Detection
Indicators from headers, readable HTTPS responses and egress ownership.
Not run yet
Not run yet.
ZIA Service Edge
Where requests appear to leave for the Internet.
The exact Zscaler Service Edge is not exposed by public APIs and is not guessed here.
Internet Egress
Solid = observed · dashed = assumed / possible.
Browser
this workstation
Local network
assumed
Proxy / ZCC
not observed
Internet
egress IP…
Z-Tunnel Diagnostics
Not run yet.
Modern Web Protocols
Protocol versions are only shown when the browser or a trace endpoint reports them.
Not run yet.
Cloud Firewall
Only the configured destinations are tested — no port scanning. Failures read as 'Possible firewall restriction'.
Not run yet — use ↻ or Run Full Diagnostic.
Forwarding Diagnostics
Indirect indicators of how traffic is forwarded.
What to check on the endpoint
- Zscaler Client Connector running (system tray icon)
- Forwarding Profile assigned (ZCC → More → forwarding profile)
- Trusted Network status (Trusted / VPN-Trusted / Off-Trusted)
- System proxy settings (OS network settings)
- PAC configuration (browser / OS / App Profile PAC)
- Tunnel status (ZCC → Internet Security → Service status)
Forwarding Profiles decide ZCC behaviour depending on whether the device is on a trusted, VPN-trusted or off-trusted network.
Zscaler Client Connector
Entered by the technician — never detected automatically. User provided
ZCC Troubleshooting
Step-by-step checklist. 'Unknown' means not confirmed — not failed.
- 1.Is Zscaler Client Connector running?User providedUnknown
- 2.Is the user authenticated?User providedUnknown
- 3.Is ZIA enabled?User providedUnknown
- 4.Is the tunnel connected?User providedUnknown
- 5.Is the device on a trusted network?User providedUnknown
- 6.Is traffic forwarded through Zscaler?PossibleUnknown
- 7.Does HTTPS work?Browser observedUnknown
- 8.Does URL filtering work?PossibleUnknown
- 9.Does SSL inspection work?PossibleUnknown
- 10.Do non-browser applications work?User providedUnknown
"URL filtering works" and "SSL inspection works" are only marked OK when a test observed the corresponding behaviour.
PAC Test
The PAC is fetched only from the URL you enter. It is never executed on the server.
SSL Inspection
Per-domain TLS
TLS availability observed from the browser; certificate fields marked as not detectable. Expert mode shows every field.
Not run yet — use ↻ or Run Full Diagnostic.
SSL Bypass Diagnostics
Domains configured as exempt from inspection (edit them in Admin). Compared with a normally inspected reference.
| Domain | HTTPS | Certificate / issuer | Loading | Possible inspection |
|---|
Not run yet.
To confirm a bypass, compare the certificate issuer in the padlock menu of a bypassed site with an inspected one.
ZIA URL Filtering
Expected categories come from the configured matrix (plus custom URL categories). Results are observations — never 'blocked by Zscaler'.
Pick a profile to run the category tests.
Expert mode: click a row for DNS, HTTP status, redirects, response time and block-page details. "Blocked" means the browser failed while the server reached the destination — possible filtering on the workstation path.
Zscaler DNS Diagnostics
A / AAAA / CNAME via server-side DoH, correlated with reachability from this browser.
Not run yet — use ↻ or Run Full Diagnostic.
Cloud Applications
Basic access (main page + sign-in page) vs advanced functionality (API, resources, WebSocket). An app can be reachable while some features are blocked.
Not run yet — use ↻ or Run Full Diagnostic.
YouTube Diagnostics
Each component is tested separately. An iframe loading does not mean a video can play.
Not run yet — use ↻ or Run Full Diagnostic.
YouTube iframe embed
Iframe load event only Browser observed
Download Control
Small, harmless sample files generated by this app (no executables). Detects file-type blocking, content replacement and timeouts.
Not run yet — use ↻ or Run Full Diagnostic.
CDN / External resources
Not run yet — use ↻ or Run Full Diagnostic.
Timeline
Run the full diagnostic to generate a Diagnostic ID.
- ·Internet connectivityRunning
- ·dnsRunning
- ·httpsRunning
- ·proxyRunning
- ·SSLRunning
- ·filteringRunning
- ·youtubeRunning
- ·websocketRunning
- ·appsRunning
- ·downloadRunning
- ·cacheRunning
- ·corsRunning
Diagnostic Engine
Observations and possible explanations — never a definitive diagnosis.
Observations
- No data yet
Possible explanations
- None suggested
No test run yet.
Further investigation required.
Zscaler Connectivity Diagnostic report
…