Zscaler Troubleshooting

Diagnose proxy, forwarding, SSL inspection and web filtering issues.

0 / 18 steps completed

Evidence:Browser observedServer observedPossibleUser providedNot detectable from browser

Zscaler Connectivity

Public egress as seen by independent services, plus Zscaler indicators.

Public IP…
IPv4—
IPv6—
ASN—
ISP / organisation—
Country—
Zscaler-related headersNone observed

Status

Each line shows how the information was obtained.

Internet connectivityBrowser observedRunning
HTTPSBrowser observedRunning
Proxy not observedPossibleRunning
No TLS inspection indicatorPossibleRunning
Zscaler block page not detectedBrowser observedRunning
No Zscaler indicatorPossibleRunning
Zscaler cloud connectivity (ZCC ↔ cloud)Not detectable from browserUnknown

Zscaler Detection

Indicators from headers, readable HTTPS responses and egress ownership.

Not run yet

Certificate issuer, subject, SAN and validity are not exposed to web pages by browsers — they are shown as "Not detectable from browser". Check them in the browser's padlock menu (issuer "Zscaler Root CA" or your corporate CA indicates inspection).

Not run yet.

ZIA Service Edge

Where requests appear to leave for the Internet.

Public IP—
Reverse DNSNot available
ASN—
Organisation—
Country—
Approximate region—
Detected service providerNo known security provider matched
Cloudflare edge (browser)—

The exact Zscaler Service Edge is not exposed by public APIs and is not guessed here.

Internet Egress

Solid = observed · dashed = assumed / possible.

Browser

this workstation

Local network

assumed

Proxy / ZCC

not observed

Internet

egress IP…

Open ip.zscaler.com — Zscaler's own page says whether this browser is going through Zscaler (visual check by the technician).

Z-Tunnel Diagnostics

This result only reflects what the browser can observe. It does not determine which Z-Tunnel version is in use — Z-Tunnel 1.0 and 2.0 have different capabilities and architectures, and the version cannot be inferred from a simple web test.

Not run yet.

Modern Web Protocols

Protocol versions are only shown when the browser or a trace endpoint reports them.

Not run yet.

Cloud Firewall

Only the configured destinations are tested — no port scanning. Failures read as 'Possible firewall restriction'.

Not run yet — use ↻ or Run Full Diagnostic.

Forwarding Diagnostics

Indirect indicators of how traffic is forwarded.

System proxy settingsNot accessible from browser Not detectable from browser
PAC URL in useNot accessible from browser Not detectable from browser
WPADNot accessible from browser Not detectable from browser
HTTP proxy headers—
Direct vs proxied behaviour—

What to check on the endpoint

  • Zscaler Client Connector running (system tray icon)
  • Forwarding Profile assigned (ZCC → More → forwarding profile)
  • Trusted Network status (Trusted / VPN-Trusted / Off-Trusted)
  • System proxy settings (OS network settings)
  • PAC configuration (browser / OS / App Profile PAC)
  • Tunnel status (ZCC → Internet Security → Service status)

Forwarding Profiles decide ZCC behaviour depending on whether the device is on a trusted, VPN-trusted or off-trusted network.

Zscaler Client Connector

Entered by the technician — never detected automatically. User provided

ZCC installed
ZCC running
User authenticated
ZIA enabled
ZPA enabled
Tunnel status
Network
Non-browser apps work

ZCC Troubleshooting

Step-by-step checklist. 'Unknown' means not confirmed — not failed.

  1. 1.Is Zscaler Client Connector running?User providedUnknown
  2. 2.Is the user authenticated?User providedUnknown
  3. 3.Is ZIA enabled?User providedUnknown
  4. 4.Is the tunnel connected?User providedUnknown
  5. 5.Is the device on a trusted network?User providedUnknown
  6. 6.Is traffic forwarded through Zscaler?PossibleUnknown
  7. 7.Does HTTPS work?Browser observedUnknown
  8. 8.Does URL filtering work?PossibleUnknown
  9. 9.Does SSL inspection work?PossibleUnknown
  10. 10.Do non-browser applications work?User providedUnknown

"URL filtering works" and "SSL inspection works" are only marked OK when a test observed the corresponding behaviour.

PAC Test

The PAC is fetched only from the URL you enter. It is never executed on the server.

Tip: set a default PAC URL in Admin / Test Configuration to include it in the full diagnostic.

SSL Inspection

Not run yetPossible
TLS interception detection depends on what the browser exposes and is not, on its own, proof of Zscaler SSL Inspection. Web pages cannot read certificate issuer, subject, SAN, expiry or chain — open the padlock menu on an affected site to confirm the issuing CA.

Per-domain TLS

TLS availability observed from the browser; certificate fields marked as not detectable. Expert mode shows every field.

Not run yet — use ↻ or Run Full Diagnostic.

SSL Bypass Diagnostics

Domains configured as exempt from inspection (edit them in Admin). Compared with a normally inspected reference.

DomainHTTPSCertificate / issuerLoadingPossible inspection

Not run yet.

To confirm a bypass, compare the certificate issuer in the padlock menu of a bypassed site with an inspected one.

ZIA URL Filtering

Expected categories come from the configured matrix (plus custom URL categories). Results are observations — never 'blocked by Zscaler'.

0 Allowed0 Blocked0 Partial0 Unknown

Pick a profile to run the category tests.

Expert mode: click a row for DNS, HTTP status, redirects, response time and block-page details. "Blocked" means the browser failed while the server reached the destination — possible filtering on the workstation path.

Zscaler DNS Diagnostics

A / AAAA / CNAME via server-side DoH, correlated with reachability from this browser.

Server DNS uses a public resolver and is not the workstation's resolver. Workstation resolution is inferred from whether the browser could reach the domain. Security test domains are harmless pages designed for testing — no real malicious domain is ever used.

Not run yet — use ↻ or Run Full Diagnostic.

Cloud Applications

Basic access (main page + sign-in page) vs advanced functionality (API, resources, WebSocket). An app can be reachable while some features are blocked.

Not run yet — use ↻ or Run Full Diagnostic.

YouTube Diagnostics

Each component is tested separately. An iframe loading does not mean a video can play.

Video playback cannot be verified automatically. Press play below: if the player loads but the video never starts, video streams (googlevideo.com) are likely restricted.

Not run yet — use ↻ or Run Full Diagnostic.

YouTube iframe embed

Iframe load event only Browser observed

Loading

Download Control

Small, harmless sample files generated by this app (no executables). Detects file-type blocking, content replacement and timeouts.

Not run yet — use ↻ or Run Full Diagnostic.

CDN / External resources

Not run yet — use ↻ or Run Full Diagnostic.

Timeline

Run the full diagnostic to generate a Diagnostic ID.

  1. ·Internet connectivityRunning
  2. ·dnsRunning
  3. ·httpsRunning
  4. ·proxyRunning
  5. ·SSLRunning
  6. ·filteringRunning
  7. ·youtubeRunning
  8. ·websocketRunning
  9. ·appsRunning
  10. ·downloadRunning
  11. ·cacheRunning
  12. ·corsRunning

Diagnostic Engine

Observations and possible explanations — never a definitive diagnosis.

Observations

  • No data yet

Possible explanations

  • None suggested

No test run yet.

Further investigation required.

Zscaler Connectivity Diagnostic report

…