We're using ZScaler, but don't have Adaptive Transport enabled, so I'm not of much help here. Definitely going to keep it on my radar if we do go that route. I will say that we have to continually talk to the ZScaler team because of issues we see in general.
n
Nick Casagrande
08/18/2023, 2:23 PM
zscaler sounds very interesting, however the feedback ive heard isn't amazing and makes me shy away from it. very cool tech though, but if it doesnt work, meh
s
Shane Swacus
08/18/2023, 3:57 PM
I'll keep this updated on what I find out.
d
dale scriven
08/18/2023, 7:09 PM
Zscaler converts pretty much everything to TCP. Hence the break In comms. Also when you get it working by default it's effects performance loads and also your traffic can be seen coming from any number of zscaler cloud egress IP's. It's horrible. Basically make your like easy and get the zscaler admins to bypass your gateway URLs. Including cnames, and any gslb vips.
s
Shane Swacus
09/20/2023, 2:14 PM
So we pretty much narrowed it down to the UDP/TCp 443 needing to be excluded. However, zscaler support wants the ip addresses instead of the fqdn. I dont think that is reasonable. This also has the same impact on the Windows 365 pc's as well, MS wants them to not do anything to their fqdn and zscaler support says they need IP.
d
dale scriven
09/20/2023, 2:30 PM
hmm the ip request's doesn't sound right to me, I dont administer zscaler for our place but the team that do only every ask us for FQDNS. theres a few zscaler docs that talks about configuring bypass using URL's as well. So that doesn't feel quite right but I dont specifically know.