T Techclick ← All lessons
Zscaler · Client Connector · Interactive lesson

Green icon ≠ working — Client Connector war-room

02:10. Slack: a phone photo of a green Client Connector tray. Salesforce is spinning. L1 already restarted the laptop. The icon is not a verdict. This war-room is five official facts — Service Status, ZIA / ZPA enabled, forwarding profile, PAC, auth loop — each mapped to one first click and one field you paste before you change anything.

~20 min read · L2 primary · Quiz at end · Lesson 4 · Auth + ZCC deploy

⚡ Quick Answer

Green tray icon is not a verdict. War-room for Service Status, ZIA/ZPA enabled, forwarding profile, PAC, and auth loops — official help.zscaler.com only.

After this page you can

Quick answer (say this out loud)

Service Status answers “is the app even connected, and is Internet & SaaS / Private Access turned on?” ZIA Enabled / ZPA Enabled answers “is this user entitled for that service?” Forwarding Profile answers “for this trusted-network type, is the action Tunnel, Tunnel with Local Proxy, or None?” PAC answers “did the device download a valid PAC, and does it DIRECT the IdP?” ip.zscaler.com answers “did this browser hit a ZIA Public Service Edge?” A green tray is ZSATray. It is not a Web row and it is not an enrolled tunnel.

1. Why the green icon lies

Operators collapse five client failures into one screenshot. The service is Off. The user is not entitled for ZIA. The forwarding profile action for Off-Trusted is None. The PAC URL is invalid, so enrollment never finished. The IdP is hairpinned through the tunnel, so SAML loops. Those are five first clicks. The tray being green only means the UI process is alive.

This page is the war-room for the agent. Lesson 4 ships the install and the App Profile. The evidence desk proves the cloud after the packet leaves the laptop. Here you prove the five facts on the device before you open URL policy.

Hero · wings are not a tunnel
Laptop with glowing wings beside a process map — the icon looks healthy; the process tree is the real story
Notice: the laptop looks shielded. The process map to the left is the ticket. Quote Service Status and ZIA / ZPA enabled before you trust the wings.
Interview line

If they say “Client Connector is green, so Zscaler is working,” do not agree. Say: “The tray is ZSATray. I read Service Status, then whether Internet & SaaS and Private Access are enabled, then the Forwarding Profile action for this network type, then PAC, then ip.zscaler.com. Green is not a Public Service Edge.”

2. Concept — five client facts

Memorise five named objects before you click. Each is allowed to prove one thing. Over-claiming the tray is how you ship a bad App Profile at 02:00.

1 · Service Status

On the device, in Client Connector. Official: Using Zscaler Client Connector. Shows connection status and lets the user Turn Off Internet & SaaS, Private Access, ZDX, or Endpoint DLP for a timed window. Green tray ≠ service On.

2 · ZIA / ZPA enabled

Entitlement, not the icon. Device fingerprint Help: ZIA Enabled is True if the user is entitled for Internet & SaaS; ZPA Enabled is True if entitled for Private Access. False means there is no tunnel to chase.

3 · Forwarding Profile

Admin path: Infrastructure → Connectors → Client → Forwarding Profile for Platforms. One action per network type: On-Trusted, Off-Trusted, VPN-Trusted, Split VPN-Trusted. Actions you will actually see: Tunnel, Tunnel with Local Proxy, None.

4 · PAC

The PAC URL lives on the forwarding profile (and App Profile PAC Configuration). Error 3016 = PAC URL is not valid. Error 3017 = PAC file is not valid. A failed PAC download stops Client Connector from authenticating the user.

5 · Auth loop

If IdP / ACS traffic is forced through the tunnel or a PAC that does not DIRECT the IdP, SAML never completes. Exempt the IdP and ACS first. Do not disable Client Connector for the org.

Hard words, once

App Profile = who + OS + which Forwarding Profile. Forwarding Profile = how, per network type. Z-Tunnel 2.0 = all ports; 1.0 is web ports. Export Logs = More → Troubleshoot → ZIP for support. ZSATray = UI; ZSATunnel = tunnel process.

Flow 1 · five facts, one question each
Write user + device + UTC first · then pick the fact Green icon ≠ working five facts, not one tray Service Status App connected? ZIA / ZPA On or Off Using ZCC · device Turn Off is timed not a policy verdict ZIA / ZPA enabled Entitled? ZIA Enabled True/False ZPA Enabled True/False Device fingerprint not the tray colour Forwarding Profile How on this LAN? Tunnel / TWLP / None On / Off / VPN-Trusted Infrastructure → Client not an App Profile PAC Did PAC load? 3016 URL not valid 3017 file not valid Forwarding Profile URL failed PAC = no auth Auth loop IdP reachable? DIRECT IdP + ACS no tunnel hairpin PAC best practices do not org-disable ZCC A green tray with ZIA Off is data. There is no Salesforce row to chase in Web Insights. Turn the service back on — or fix entitlement — then reload ip.zscaler.com. Do not Activate a URL Allow.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove Service Status, then entitlement, then the Forwarding Profile action for this network type, then PAC, then the wire. I do not change URL policy, SSL, or an App Profile Rule Order until I can quote the field that made me do it.

3. Path — ticket → first check

Flowchart first. Do not open the App Profile editor until a diamond says so. Do not restart the laptop until Service Status and the two enable flags are written on the ticket.

Path · pick the branch before the restart
Decide diamond splitting into CLI, logs, trace, cluster, and audit investigation paths
Notice: the diamond is the ticket. CLI / logs / trace are later tools. On this war-room the first diamond is Service Status, not a reboot.
Flow 2 · first-check diamond
Symptom first · check second · field third What must we prove on ZCC? Service On? and entitled? ZIA / ZPA Off Service Status or Enabled = False do not hunt URL policy Stuck Authenticating PAC + IdP / ACS 3016 / 3017 / loop DIRECT the IdP first Internet not in ZIA Forwarding Profile action + network type then ip.zscaler.com VPN on the laptop Forwarding Profile VPN-Trusted + bypass official VPN error Still failing Export Logs ZIP + Run Diagnostics then evidence desk ip.zscaler.com = not a Zscaler IP → stop. There is no Web row to chase. Fix service / entitlement / PAC / forwarding action. Then reload My IP. Diamond = decision. Do not Activate a URL rule from the bottom box. App Profile path is Infrastructure → Connectors → Client → Windows → App Profiles. Forwarding Profile path is Infrastructure → Connectors → Client → Forwarding Profile for Platforms.

Read the diamond first. An auth loop never starts in a Cloud App rule. A VPN-detected disable never starts in SSL inspection. Off-cloud My IP never starts in Blocked Policy Name.

4. How to choose — first check + proof field

Print this next to the Client Connector window. If you cannot recite the proof field, you are not ready to edit an App Profile.

If the ticket says…First check (official path)Proof fieldDo not open first
Green icon, “Zscaler is on,” SaaS still dead On the device: Client Connector → Service Status; confirm Internet & SaaS / Private Access are not Turned Off Service Status + ZIA / ZPA On · or ZIA Enabled / ZPA Enabled True A new URL Allow
Stuck on Authenticating / SAML redirect loop after enroll Forwarding Profile PAC + App Profile PAC Configuration; confirm IdP + ACS are not hairpinned PAC DIRECT for IdP/ACS · or error 3016 / 3017 Org-wide Turn Off of ZCC
“PAC URL is not Valid” / cannot authenticate Infrastructure → Connectors → Client → Forwarding Profile for Platforms → PAC URL Error 3016 (URL) or 3017 (file) A Cloud App rule
Third-party VPN up; ZIA tunnel dropped Same Forwarding Profile — VPN-Trusted action + VPN hostname / IP bypass (Help: ZCC Errors + PAC best practices) Official “active VPN” error + VPN-Trusted action Disable SSL inspection
Service Status looks connected; browser is off-cloud On the failing browser: https://ip.zscaler.com, then the Forwarding Profile action for the detected network type My IP “didn’t come from a Zscaler IP” + action = None / wrong trusted type ZPA Access Policy
App Profile is not the Forwarding Profile

Help keeps them as two objects. The App Profile (Windows / macOS / Linux / iOS / Android tab) names who matches and which Forwarding Profile to download. The Forwarding Profile names Tunnel / Tunnel with Local Proxy / None per On-Trusted, Off-Trusted, VPN-Trusted, Split VPN-Trusted. Editing Rule Order will not fix a None action on Off-Trusted.

5. Do — runbook Side A → B → C

Side A proves the agent on the laptop. Side B proves the two Admin objects that laptop downloaded. Side C proves the wire and packages logs. On a messy Sev-2, do them in this order until a field lights up.

Side A — Device: Service Status, services, Troubleshoot

  1. Open Client Connector, not the Admin Portal

    On the failing device, open the app. Official: Using Zscaler Client Connector. Read Service Status. Confirm whether the user (or a remote admin) used Turn Off on Internet & SaaS, Private Access, ZDX, or Endpoint DLP. Help: the app disables those services for a period of time and then re-enables them. A timed Off is not a URL block.

  2. Read ZIA and ZPA as two switches

    Internet & SaaS Off explains a dead browser and an off-cloud My IP page. Private Access Off explains a dead private FQDN even when Salesforce works. Dashboard Help also tracks ZIA Service Turn Off and ZPA Service Turn Off counts across enrolled devices — use that if more than one laptop flipped.

  3. If the UI is up but the tunnel is not, prove the processes

    Official allowlist: ZSATray is the UI, ZSATunnel handles traffic tunneling, plus ZSAService on Windows. Traffic-forwarding runbook: allowlist ZSATunnel.exe, ZSATray.exe, ZSAService.exe (and ZDPService.exe if Endpoint DLP is in scope). A living tray with a dead ZSATunnel is a process ticket, not a policy ticket.

  4. Use the official Troubleshoot section before you reinstall

    Path: More → Troubleshoot. Official actions: Run Zscaler Diagnostics (one-time snapshot of network state), Restart Service, Export Logs (ZIP to your support admin), Start Packet Capture (Help: Enabling Packet Capture — set Run Session For first). Do not start a capture on a production laptop without a duration and a change note.

Zscaler Client Connector · Service Status
Training mock · not live

Device / Client Connector / Service Status

Service Status

priya@lab.example
Win-Offnet-Default
Off · Turn Off used 01:58 UTC
On
True
True
TRAY: green · ZSATray running
ZIA: Internet & SaaS is Off — Help: user can disable Internet & SaaS / Private Access / ZDX / Endpoint DLP for a period.
PROOF: do not open URL policy. Turn the service back on, then reload ip.zscaler.com.

Source: Zscaler Help — Using Zscaler Client Connector (Service Status; disable Internet & SaaS, Private Access, ZDX, Endpoint DLP); Viewing Device Fingerprint Information (ZIA Enabled, ZPA Enabled); Troubleshooting Zscaler Client Connector (Export Logs, Restart Service, Run Zscaler Diagnostics). Lab identities only. Training mock · not live.

Windows — prove the official processes (read-only)
sc query ZSAService
tasklist | findstr /i "ZSATunnel ZSAService ZSATray"

REM Official allowlist names: ZSATray = UI, ZSATunnel = tunneling, ZSAService = service
REM If ZSATray is up and ZSATunnel is missing, the tray can still look green.

Side B — Admin: App Profile, Forwarding Profile, PAC

  1. Confirm which App Profile the device actually has

    Path: Infrastructure → Connectors → Client → Windows (or macOS / Linux / iOS / Android — the OS is the tab). App Profiles. Official fields: Name, Rule Order (ascending numerical order — lowest number wins), Status = Enabled, Forwarding Profile drop-down. A VIP profile at order 4 never matches if Default-Win sits at 1. Source: Configuring Zscaler Client Connector App Profiles.

  2. Open the Forwarding Profile that App Profile names

    Path: Infrastructure → Connectors → Client → Forwarding Profile for Platforms → Add Forwarding Profile (or the existing profile). Read the action for the network type the laptop thinks it is on: On-Trusted, Off-Trusted, VPN-Trusted, Split VPN-Trusted. If you use Z-Tunnel 2.0, Help requires a forwarding profile with Z-Tunnel 2.0 selected. Source: Configuring Forwarding Profiles; About Z-Tunnel 1.0 & Z-Tunnel 2.0.

  3. Read the PAC URL on that profile

    Error 3016 PAC URL is not Valid = the URL on the forwarding profile is wrong. Error 3017 PAC File is not Valid = the file itself is invalid. A failed PAC download stops Client Connector from authenticating the user — check network connectivity to the PAC host. Source: Zscaler Client Connector Errors.

  4. If a third-party VPN is in the picture, stay on this object

    Official error: Client Connector detects an active VPN — check the forwarding profile. Help on App Profiles / PAC: add the VPN gateway hostname or IP to the system PAC so Tunnel with Local Proxy can DIRECT that traffic. Do not start by killing SSL inspection.

admin.zscalerthree.net · Infrastructure → Connectors → Client → Forwarding Profile for Platforms
Training mock · not live

Infrastructure / Connectors / Client / Forwarding Profile for Platforms / Edit

Forwarding Profile · Win-Offnet-ZT2

Tunnel · Z-Tunnel 2.0
None
Tunnel with Local Proxy
https://pac.lab.example/win-offnet.pac
Network typeActionWhat it proves
Off-TrustedTunnelWFH should hit a ZIA Public Service Edge
On-TrustedNoneIf trusted-network detection is wrong, WFH goes DIRECT
VPN-TrustedTunnel with Local ProxyAdd VPN gateway to system PAC (Help)

Source: Zscaler Help — Configuring Forwarding Profiles for Zscaler Client Connector (path: Infrastructure → Connectors → Client → Forwarding Profile for Platforms); About Forwarding Profiles; Best Practices for Using PAC Files with Zscaler Client Connector. Lab names only. Training mock · not live.

admin.zscalerthree.net · Infrastructure → Connectors → Client → Windows → App Profiles → Edit Windows Policy
Training mock · not live

Infrastructure / Connectors / Client / Windows / App Profiles / Win-Offnet-Default

Windows Policy

Win-Offnet-Default
1
Enabled
Win-Offnet-ZT2
IdP login.microsoftonline.com + ACS must return DIRECT — do not hairpin SAML

Source: Zscaler Help — Configuring Zscaler Client Connector App Profiles (Rule Order ascending; Status; Forwarding Profile; PAC Configuration). Identity click-path: Lesson 4 · Authentication and ZCC deploy. Training mock · not live.

Side C — Proof: My IP, auth exemption, Export Logs

  1. Prove the browser hit a Public Service Edge

    On the user’s device open https://ip.zscaler.com. Official: Verifying a User’s Traffic is Being Forwarded to the Zscaler Service. If the page says the request did not come from a Zscaler IP, stop. There is no Policy Action to chase. Fix Service Status / entitlement / PAC / forwarding action, then reload.

  2. If the ticket is an auth loop, exempt IdP + ACS first

    PAC best practices + App Profile PAC Configuration: IdP and ACS must not be forced through the tunnel. A STRICTENFORCEMENT install whose pre-enroll PAC does not DIRECT the IdP bricks its own SSO path — that is a token / PAC ticket, not a “disable ZCC” ticket. Full Entra gallery / ACS runbook: Lesson 4 and the gold authentication lesson.

  3. Package official logs before you escalate

    More → Troubleshoot → Export Logs writes a ZIP for your support admin. Remote path (Help: Configuring User Access to Support Options): Enrolled Devices → Device Details → Fetch Logs. Quote Service Status, Forwarding Profile name, PAC error if any, and the My IP sentence in the same note as the ZIP.

  4. Only then open the evidence desk

    On-cloud My IP plus a still-failing SaaS URL is a Web Insights ticket. A private FQDN is User Activity. Slow + Allowed is ZDX. Those tools are the next lesson — they are not the first click when the tray is the question. Evidence desk.

Green success on each side

6. Five war-room tickets

These five land every quarter. Memorise first check + proof field. Times and identities below are lab-only.

TicketSymptomFirst checkProof field
ZCC-01Green tray; Salesforce spinningService StatusInternet & SaaS Off — or ZIA Enabled = False
ZCC-02Stuck Authenticating after enrollPAC + IdP/ACS exemptionPAC does not DIRECT IdP/ACS · or 3016 / 3017
ZCC-03“PAC URL is not Valid”Forwarding Profile PAC URLError 3016 (URL) or 3017 (file)
ZCC-04Cisco / GlobalProtect up; ZIA diedForwarding Profile VPN-TrustedOfficial active-VPN error + bypass / action
ZCC-05Service looks On; My IP off-cloudForwarding action + trusted-network typeAction None on the type the laptop detected

ZCC-01 — Green icon, service Off

02:12 · P2. Priya on a hotel network. Slack photo of a green tray. Salesforce spins. L1 already drafted a URL Allow for salesforce.com.

First check: on her Client Connector, Service Status. Official: Using Zscaler Client Connector — the user can disable Internet & SaaS (and Private Access, ZDX, Endpoint DLP) for a period.

If ZIA is Off: quote that line. Turn it back on (or wait for the timed re-enable). Reload ip.zscaler.com. There is no Blocked Policy Name yet.

If ZIA is On and ZIA Enabled is False: entitlement — the user is not entitled for Internet & SaaS in Client Connector. That is an App Profile / service-assignment ticket, not a Salesforce Allow.

Trap

Do not trust a colleague’s tray screenshot from a different laptop. The proof is Service Status on the failing device. A green ZSATray with Internet & SaaS Off is working as designed.

ZCC-02 — Auth loop after enroll

02:25 · P2. New hire enrolls. Browser bounces login.microsoftonline.com → Zscaler ACS → IdP again. L1 wants Client Connector uninstalled “so they can get in.”

First check: PAC on the Forwarding Profile the pre-enroll POLICYTOKEN / App Profile is using. Confirm the IdP and the ACS are not forced through the tunnel.

Proof field: a PAC DIRECT (or equivalent bypass) for the IdP and ACS. If the PAC failed to download, you will see the official PAC-download error — authentication cannot start until that file loads. Error 3016 / 3017 live on the same object.

Close

I would not disable Client Connector for the org. I would exempt IdP + ACS, re-test the same user, then finish enrollment. Identity click-path: Lesson 4 · Auth + ZCC deploy.

ZCC-03 — 3016 / 3017 PAC

02:40 · P2. Overnight someone edited the PAC host. Half the WFH fleet cannot authenticate. The tray still looks installed.

First check: Infrastructure → Connectors → Client → Forwarding Profile for Platforms → the PAC URL on the profile those devices use.

Proof field: 3016 PAC URL is not Valid if the URL is wrong; 3017 PAC File is not Valid if the file is invalid. Help: a failed PAC download stops Client Connector from authenticating the user. Fix the URL or the file, confirm the device can reach it, then re-auth one pilot — not a tenant-wide Force re-auth.

Trap

Help also notes 3016 / 3017 can appear for admins merely browsing the forwarding profile or app profiles pages. Quote the error from the user device before you declare a fleet outage.

ZCC-04 — Active VPN detected

02:55 · P2. Contractor connects corporate GlobalProtect, then Client Connector reports ZIA is down. L1 wants SSL inspection disabled.

First check: Zscaler Client Connector Errors — this class of error occurs if Client Connector detects an active VPN. Check the forwarding profile. Read VPN-Trusted (and Split VPN-Trusted) actions. Add the VPN gateway hostname / IP to the system PAC if you are on Tunnel with Local Proxy (official PAC best practices).

Proof field: the official active-VPN wording plus the VPN-Trusted action you intended. A None action on VPN-Trusted is a design choice — quote it; do not “fix” it with SSL.

Close

I would leave SSL alone. I would quote the VPN error, the forwarding-profile action for VPN-Trusted, and the PAC bypass for the VPN gateway. Then retest Salesforce with both agents up.

ZCC-05 — Connected agent, off-cloud browser

03:10 · P2. Service Status looks healthy. Internet works. ip.zscaler.com says the request did not come from a Zscaler IP. Someone typed “Zscaler is down” in the channel.

First check: which trusted-network type did the laptop detect, and what is the Forwarding Profile action for that type? A hotel laptop that matches On-Trusted (fragile DNS / DNS suffix criteria) will take the On-Trusted action — often None — and go DIRECT. Tunnel with Local Proxy plus a missing system proxy does the same for browser traffic.

Proof field: the official off-cloud sentence on My IP, plus the network type + action pair. Then fix detection or the Off-Trusted action (Tunnel / Z-Tunnel 2.0 is the usual WFH intent). Reload My IP on the same browser.

Trap

Do not rip Z-Tunnel from one IPv6-looking My IP. Official My IP caveat: the service might not recognize IPv6 traffic that is already on-cloud. Confirm with a Web Insights row in the same minute if the path is IPv6-first. Evidence desk.

7. Traps + close-the-ticket proof

Proof · named field, then Closed
SOC desk with a green check on one monitor and a highlighted log line on the other
Notice: the left screen is a green check. The right screen is the close. Quote Service Status, PAC error, or the My IP sentence — not the tray colour.
You seeWeak closeStrong close
Green tray“Zscaler is working”Service Status + ZIA / ZPA On + ZIA Enabled / ZPA Enabled
Internet & SaaS OffNew URL AllowQuote Turn Off; re-enable; reload My IP
ZIA Enabled = FalseRestart ServiceEntitlement / App Profile assignment — user is not entitled for ZIA
SAML redirect loopUninstall ZCC for the orgExempt IdP + ACS from PAC / tunnel; re-enroll one user
Error 3016 / 3017Force re-auth the tenantFix Forwarding Profile PAC URL or file; prove the device can fetch it
Active VPN errorDisable SSL inspectionForwarding Profile VPN-Trusted action + PAC bypass for the VPN gateway
My IP off-cloud, services On“Zscaler is down”Network type + action (often None on a false On-Trusted)
Tray up, no ZSATunnelAnother URL AllowMore → Troubleshoot → Restart Service; quote process list; Export Logs
IPv6 My IP looks off-cloudRip Z-TunnelOfficial IPv6 caveat; confirm with a Web row in the same minute
Proof checklist before you leave the bridge
Interview close

I name the question, then the first check, then one official field. Service Status proves the agent. Enabled proves entitlement. The Forwarding Profile proves how this network type is supposed to send traffic. PAC proves whether authentication can even start. ip.zscaler.com proves the wire. I do not change URL policy, SSL, or an org-wide disable until that field is on the ticket. Deploy + identity: Lesson 4 · Auth and ZCC deploy. Cloud proof after the packet leaves: evidence desk.

Knowledge check

Six war-room judgments. Each maps to a first check or a proof field. Check answers, then Reset if you picked the wrong object.

Q1

WFH user sends a photo of a green Client Connector tray. Salesforce is spinning. You have not opened Admin yet. First proof?

Correct: b. Official Service Status + fingerprint enable flags. A green tray is ZSATray. Re-read Side A and ZCC-01.
Q2

A new hire is stuck in a SAML redirect loop right after Client Connector enroll. What is the first fix?

Correct: b. Official PAC / App Profile practice: do not hairpin IdP + ACS. Re-read Side C step 2 and ZCC-02. Deploy path: Lesson 4.
Q3

The user sees “PAC URL is not Valid” and cannot authenticate. Where does that error live?

Correct: a. Help: Zscaler Client Connector Errors — 3016 PAC URL is not Valid; 3017 PAC File is not Valid. Failed PAC download stops authentication. Re-read Side B step 3 and ZCC-03.
Q4

A contractor brings up a third-party VPN and Internet & SaaS drops. Official first object?

Correct: c. Official ZCC Errors + PAC best practices. SSL and App Connectors are the wrong surface. Re-read Side B step 4 and ZCC-04.
Q5

Service Status looks connected. ip.zscaler.com says the request did not come from a Zscaler IP. What is that pair allowed to mean?

Correct: d. Official off-cloud wording. Service Status is not My IP. Re-read Flow 2 bottom box and ZCC-05. Remember the IPv6 caveat before you rip Z-Tunnel.
Q6

Device fingerprint shows ZIA Enabled = False. Internet & SaaS never comes up. What is that field allowed to mean?

Correct: a. Official fingerprint field: ZIA Enabled is True if the user is entitled for ZIA in Client Connector. Re-read Concept box 2 and ZCC-01.

Sources

Related: Batch 11 · Lesson 4 — Authentication and ZCC deploy · Gold · Zscaler Authentication (Entra SAML + SCIM) · ZCC App & Forwarding Profiles · Evidence desk — first tool + proof field · Lesson 3 — traffic forwarding · 16 ZCC scenarios