Skip to content

Zscaler Runbook & Troubleshooting Guide

Overview

This runbook covers common Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) issues, diagnostic steps, and resolution paths for support/NOC teams.


1. Quick Reference

Component Purpose Client Check
ZIA Secure internet/SaaS traffic Zscaler Client Connector → Internet Security: ON
ZPA Secure private app access Zscaler Client Connector → Private Access: ON
ZCC Zscaler Client Connector (endpoint agent) System tray icon status
ZDX Digital Experience monitoring ZDX app / portal

Key URLs to check status: - https://trust.zscaler.com (service status by cloud) - Admin portal: https://admin.<cloud>.net (e.g., zscaler.net, zscloud.net)


2. Initial Triage Checklist

  1. Identify scope — Single user, group, site, or global?
  2. Identify service — ZIA, ZPA, or both affected?
  3. Check Zscaler Trust Portal for active incidents on the customer's cloud.
  4. Confirm ZCC status on affected endpoint(s):
  5. Is the app running?
  6. Is it connected (green icon) or disconnected/error (red/yellow)?
  7. Check policy assignment — is the user in the correct policy group/location?
  8. Reproduce issue — browser test, curl test, or app-specific test.

3. Common Issues & Fixes

3.1 ZCC Won't Connect / Shows "Disconnected"

  • Restart ZCC service (Zscaler Client Connector → Exit → relaunch, or restart the ZSAService/ZSATunnel service).
  • Check local firewall/AV isn't blocking Zscaler processes (ZSAService.exe, ZSATunnel.exe, ZSATray.exe).
  • Verify DNS resolution to Zscaler cloud endpoints.
  • Check for VPN conflicts (split tunneling issues, other VPN clients running simultaneously).
  • Re-enroll device if certificate/auth token is stale: