T Techclick ← All lessons
Zscaler · ZIA · Interactive lesson

ZIA scenarios symptom then Web Insights

Ticket: Priya in Bengaluru cannot open portal.vendorsaas.example. Slack says “Zscaler is blocking it — add a bypass.” That is not a diagnosis. ZIA is five desks in one cloud: forwarding, identity, SSL inspect, URL/app policy, then the log. Proof is one Web Insights row for that user, URL and minute — Policy Action, Policy Reason, SSL Policy Reason, Location, Traffic Forwarding. Lab user priya@apexfreight.example, location APEX-BLR-WAN, GRE source 203.0.113.10.

16 min read · L2 primary · Quiz at end

After this page you can

Lessons · Zscaler series · ZIA scenarios

This page vs SSL, GRE and auth deep-dives

This lesson is the ticket method: user wording → one Insights row → smallest safe fix. Decrypt vs pinned-app exemptions live on SSL inspect. Tunnel build lives on GRE/IPSec. SAML/SCIM live on authentication. Do not start those pages until you can name the layer from a symptom.

SSL inspection · GRE & IPSec · Authentication · ZIA command center

Hero · the user talks to a browser; you talk to Insights
Laptop through a ZIA cloud proxy to an Insights log board
Mood, not a wiring diagram. Exact path is in the SVG: Priya’s GET hits a Service Edge only if PAC, ZCC or GRE forwarded it. Policy Reason is a log field, not a Slack sentence.
Quick answer

Write the symptom (user, device, location, URL, time, error). Prove forwarding first — no Web Insights row means PAC returned DIRECT, Z-Tunnel never formed, or GRE is down. Then read identity: User must be the email, not the location name. Then read Policy Action / Policy Reason (URL, DLP, threat) and SSL Policy Reason (Inspected / Not inspected because of SSL policy / O365 bypass / Zscaler best practices). One scoped change. Retest the same flow. A global bypass is the last move, not the first answer.

Why a symptom is not a policy

The day-one ticket is always the same: “The site is blocked, so URL filtering is wrong.” Wrong. A timeout, a certificate warning, a Zscaler block page, a SAML loop and “it works at home” are five different desks. Editing URL Filtering because Priya saw a padlock error wastes the change window and still leaves the CA undeployed.

Three silent-zero states look identical from the chair (site will not load):

A block page is not a URL category

SSL inspect can block on a bad server certificate. Cloud App Control block ends evaluation before URL Filtering. DNS Control can fail the name before HTTP starts. Read Policy Reason and the log family (Web / Firewall / DNS / Tunnel) before you touch a rule.

Five desks, one request

Treat ZIA as five objects that fire in order. Skip a desk and you “fix” the wrong one.

Path · symptom, forwarding, identity, policy reason
Four glass panels labeled Symptom, Forwarding, Identity, Policy reason
Feel of the order. Exact fields — Traffic Forwarding, User, Policy Reason, SSL Policy Reason — are in the SVG and the Insights mock. Do not read the last panel as “add a bypass.”

Forwarding

PAC, ZCC (Z-Tunnel 1.0/2.0), GRE or IPSec must send the flow to a Service Edge. Proof: Traffic Forwarding on the Web row, or Tunnel Insights for GRE/IPSec.

Identity

SAML (or other auth) plus location. User = email when Enforce Authentication worked. Location name in User = unauthenticated. Group rules will miss.

SSL inspect

SSL Inspected Yes/No. SSL Policy Reason names why: Inspected, Not inspected because of SSL policy, O365 bypass, UCaaS, Zscaler best practices, failed client handshake.

URL / app / DLP

URL Category, URL Filtering Policy Name, Cloud App rule, then DLP. Policy Reason strings such as Not allowed to browse this category live here — after decrypt, not before.

Say this out loud

If it never reached ZIA, policy cannot be the cause. If the user is unknown, group policy cannot be the cause. If SSL was not inspected, URL path and DLP cannot be the cause. Read the Insights row. Then change one thing.

Symptom → Web Insights

Existing session first only in your head: write the six-tuple before you open Admin. Then filter Insights to that tuple. Empty result is a forwarding ticket, not a missing allow.

Flow 1 · Priya GET portal.vendorsaas.example · 10:14 IST
1 Symptom user · URL · time 2 Forward? PAC / ZCC / GRE 3 Identity User = email? 4 SSL SSL Policy Reason 5 URL / app Policy Reason 6 Logs › Insights Logs › Web — one row is the close User=priya@apexfreight.example · Location=APEX-BLR-WAN · Forwarding=GRE Policy Action=Blocked · Reason=Not allowed to browse this category · SSL=Inspected Miss at step 2: empty Insights. Do not add a URL allow. Fix PAC / ZCC / GRE first. Miss at step 3: User = location name. Group URL rules never fired. Fix SAML / Enforce Authentication. Cloud App Control block ends evaluation — URL Filtering never runs. SSL Do Not Inspect hides path and DLP. Source: About Insights Logs; Web Insights Logs columns; Policy Reasons; SSL Policy Reason runbook.

Read left → right, then the gold bar. Empty log is a forwarding miss. Policy Reason is the URL/app/DLP verdict after identity and SSL.

Insights fieldLab value you wantIf missing / wrong
Userpriya@apexfreight.exampleLocation name or blank = NoAuth. Group/dept rules skipped.
LocationAPEX-BLR-WANRoad Warrior on an office desk = GRE/IPSec or location IP miss.
Traffic ForwardingGRE / PAC File / Zscaler Client ConnectorEmpty Web log: PAC DIRECT or tunnel down. Check Tunnel Insights.
SSL InspectedYes for path/DLP ticketsNo + SSL Policy Reason names the bypass (SSL policy, O365, best practices).
SSL Policy ReasonInspectedCertificate warning with Inspected = client does not trust the inspect CA.
Policy Action / ReasonBlocked · Not allowed to browse this categoryThat string is URL Filtering. Bad server certificate is SSL, not URL.
URL Category / Policy NameProfessional Services · URL_Block_ProductivityCustom category or Cloud App rule may have won first. Do not allow the whole super-category.

Which ticket is this

Keep these five. They are the unique ZIA interviews. DLP, QUIC, DNS and sandbox are the same method on a different Insights family — do not start there.

Flow 2 · five tickets from one symptom
User wording → match the evidence, not the adjective “blocked” SSL cert not trusted SSL Inspected=Yes deploy inspect CA scoped Do Not Inspect URL Zscaler block page category + rule name custom URL / CAC not allow-all PAC no Insights row or IdP 307 loop DIRECT for IdP ${GATEWAY}:80 GRE / IPSec whole office Road Warrior Tunnel Insights location source IP Auth repeat prompt User=location IdP exemption SCIM group Do not mix desks. A GRE-down office is not a URL category bug. Pinned apps: scoped SSL Do Not Inspect, not global decrypt off. IdP hairpin: PAC DIRECT + Authentication Exemptions. Source: SSL/TLS Inspection; Writing a PAC File; GRE/IPSec locations; SAML troubleshooting; Policy Reasons.

Five columns, five tickets. If the evidence is Road Warrior from 203.0.113.10, you are in the GRE column.

User saysTicketFirst evidenceSkip
Certificate not trusted / NET::ERR_CERTSSLSSL Inspected = Yes, SSL Policy Reason = Inspected. Browser trust store missing Zscaler inspect CA. Firefox has its own store.Disable SSL inspection for the org.
Zscaler block page on a business siteURLPolicy Reason = Not allowed to browse this category. URL Category + URL Filtering Policy Name + user/group.Allow the whole super-category. Ignore Cloud App Control if it already blocked.
Works at home, fails in office — or no log at allPACTraffic Forwarding empty / PAC File vs DIRECT. PAC download, ${GATEWAY}, RFC1918 and IdP DIRECT.Hard-coded Service Edge VIP in PAC (System Audit flags this).
Whole floor loses ZIA / location is Road WarriorGRE / IPSecTunnel Insights: Tunnel Type GRE or IPSec IKEv2, source IP, Location. Client External IP vs location object 203.0.113.10.A URL allow for one user.
Login loop / mapped as unknownAuthUser = location name. Browser 307 to IdP through ZIA. Administration › Advanced Settings › Authentication Exemptions.Turn off Enforce Authentication for every location.

Runbook Side A / B / C

Side A is the symptom tuple. Side B is Insights. Side C is one scoped change. Do not start at C.

Side A — write the tuple before Admin

  1. Six fields, one screenshot

    User, device OS, office vs home, URL (full), timestamp, exact error (block page vs cert vs timeout vs SAML). Lab: priya@apexfreight.example, Win11, APEX-BLR, https://portal.vendorsaas.example/invoices, 10:14 IST, Zscaler block page. Source: ZIA Traffic Forwarding Troubleshooting Runbook — collect before you filter.

  2. Name the forwarding guess

    Office desk with GRE: expect Traffic Forwarding = GRE and Location = APEX-BLR-WAN. WFH ZCC: Zscaler Client Connector, Road Warrior. Browser PAC only: PAC File. If you cannot name it, you are not ready for a policy edit.

Ticket header — paste into the change window
user:     priya@apexfreight.example
url:      https://portal.vendorsaas.example/invoices
when:     2026-09-05 10:14 IST
error:    Zscaler block page (not a cert warning)
fwd:      office GRE 203.0.113.10 → APEX-BLR-WAN
expect:   URL allow for Professional Services, this host only
proof:    Web Insights row + Policy Reason before/after

Side B — one Insights row

https://admin.zscaler.net/ · Logs › Insights Logs › Web
Training mock · not live

Logs › Insights Logs › Web · last 15 min

Web Insights Logs

priya@apexfreight.example
portal.vendorsaas.example
APEX-BLR-WAN
GRE
Blocked · Not allowed to browse this category
Professional Services · URL_Block_Productivity
Yes
Inspected

Source: About Insights Logs; Web Insights Logs columns (User, URL, Location, Policy Action, URL Category, SSL Inspected, SSL Policy Reason). Traffic Forwarding values include GRE, IPSec Tunnel, PAC File, PAC File over GRE Tunnel, Zscaler Client Connector. Experience Center path is Logs › Insights Logs › Web. Classic Admin may still say Analytics › Web Insights Logs.

  1. Empty table = stop

    Widen time ±10 min. Drop User filter (auth miss). Still empty: PAC/ZCC/GRE. Open Tunnel Insights for GRE/IPSec. Do not create a URL allow for a request ZIA never saw.

  2. Read SSL before URL

    Cert warning + SSL Inspected = Yes → CA/trust ticket. SSL Policy Reason = Not inspected because of SSL policy → a Do Not Inspect rule already won; URL path is hostname-only. O365 / UCaaS / Zscaler best practices are designed bypasses — do not “fix” them with decrypt.

  3. Read Policy Reason as a string

    Not allowed to browse this category is URL Filtering. Access denied due to bad server certificate is SSL. Cloud App Control block means URL Filtering was not evaluated. Source: Policy Reasons.

Side C — five scoped fixes

Change the desk the row named. Activate. Retest Priya, same URL, same path. Save the new Insights row.

SSL — inspect CA, not decrypt-off

Deploy the Zscaler intermediate/root used for inspection to Windows/macOS/mobile via GPO/MDM. Firefox: its own cert store. Pinned SaaS: Policy › SSL Inspection → Do Not Inspect for that application/URL category, not a global off. Show Notifications on a block rule forces decrypt to paint the EUN — that is why a “Do Not Inspect” still shows Inspected. Source: About SSL Inspection; SSL Policy Reason runbook; Inspected despite Do Not Inspect.

URL — custom host, not allow-all

Policy › URL & Cloud App Control. If Professional Services is blocked on purpose, add portal.vendorsaas.example to a custom URL category and allow that category for Priya’s group above the block. Do not open the super-category for the org. Confirm Cloud App Control did not already block. Source: URL Filtering; Block policy configured but access gets allowed.

PAC — DIRECT for IdP and RFC1918

Hosted PAC — Policy › Forwarding Control › Hosted PAC Files
function FindProxyForURL(url, host) {
  if (isPlainHostName(host) ||
      shExpMatch(host, "*.apexfreight.example") ||
      isInNet(dnsResolve(host), "10.0.0.0", "255.0.0.0") ||
      shExpMatch(host, "login.microsoftonline.com") ||
      shExpMatch(host, "*.login.microsoftonline.com"))
    return "DIRECT";
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80; DIRECT";
}

Use ${GATEWAY} / ${SECONDARY_GATEWAY}, not a static Public Service Edge VIP (System Audit flags static PAC IPs). Port 80 is the usual explicit proxy; 9400 if something intercepts 80/443 on the path; 9443 for remote HTTPS inspect; 9480 from unknown locations still forces auth. Keep the file small (audit warns > 25 KB). Source: Writing a PAC File.

GRE / IPSec — location IP, then tunnel health

Administration › Locations: APEX-BLR-WAN static IP 203.0.113.10, failover 203.0.113.11. Logs › Insights › Tunnel Insights: Tunnel Type GRE or IPSec IKEv1/IKEv2, Location, Tunnel Source IP, status. If Web Location = Road Warrior from that public IP, the location object does not own the source — not a URL bug. Source: Tunnel Insights Logs columns; Traffic Forwarding runbook (Client External IP vs GRE).

Auth — exempt the IdP, do not disable Enforce Authentication

https://admin.zscaler.net/ · Administration › Advanced Settings › Authentication Exemptions
Training mock · not live

Administration › Advanced Settings › Authentication Exemptions

Exempted URLs

login.microsoftonline.com, *.login.microsoftonline.com, login.apexfreight.example
APEX-BLR-WAN · Enabled
SAML

Source: SAML configuration / troubleshooting — if the IdP is forwarded through ZIA and also redirected for authentication, you get a 307 loop. PAC DIRECT for the IdP host plus Authentication Exemptions. User Management: confirm SCIM group membership before blaming URL rule criteria.

Green proof

Same user, same URL, same forwarding: Policy Action Allowed (or SSL Policy Reason the exemption you intended), User still the email, Location still APEX-BLR-WAN. Priya’s original error is gone. That is the close — not “she said it works now” without a row.

One request after go-live

Priya on LAN. GRE 203.0.113.10 up. Browser PAC not in play (or PAC over GRE). GET https://portal.vendorsaas.example/invoices. Service Edge sees location APEX-BLR-WAN, SAML cookie maps User to priya@apexfreight.example, group Finance. SSL Inspection rule Inspect → SSL Inspected Yes, SSL Policy Reason Inspected. URL Filtering rule URL_Block_Productivity matches Professional Services → Policy Action Blocked, Policy Reason Not allowed to browse this category. Web Insights row exists within minutes. You add a custom category allow for that host, activate, she retries. New row: Allowed, same User/Location/Forwarding. Ticket closed.

Home laptop, ZCC Z-Tunnel 2.0: Location Road Warrior, Traffic Forwarding = Zscaler Client Connector. Same URL rule still applies if it is user/group based. If the office GRE is down, the same laptop in Bengaluru also shows Road Warrior — that is the GRE ticket, not a new URL exception.

Proof · the close is a second Insights row, not a Slack thumbs-up
Engineer verifying abstract log checkmarks on a monitor
Ops feel. Actual evidence is Web Insights columns: User, Policy Reason, SSL Policy Reason, Location, Traffic Forwarding. Artwork checkmarks are not ZIA.
What you paste in the ticket after the retest
before: Blocked | Not allowed to browse this category | URL_Block_Productivity
        SSL Inspected=Yes | SSL Policy Reason=Inspected
        Location=APEX-BLR-WAN | Forwarding=GRE | User=priya@…
after:  Allowed | URL_Allow_VendorPortal (custom category, host only)
        same User / Location / Forwarding / SSL Inspected
rollback: disable URL_Allow_VendorPortal, activate

Traps + proof

SymptomLikely causeProof
No Web Insights rowPAC DIRECT, Z-Tunnel down, or GRE down. ZIA never saw the GET.PAC return; ZCC status; Tunnel Insights. ip.zscaler.com vs Client External IP.
Cert warning, site “blocked”Inspect CA not in the trust store (Firefox separate). Or SSL Policy Reason = bad server certificate.SSL Inspected=Yes. Browser cert path shows Zscaler intercept CA untrusted.
Block page, you already allowed the categoryCloud App Control block ends evaluation. Or User is location name so group criteria missed. Or CONNECT vs decrypted GET.Policy Reason string + User field + SSL Inspected. User Management group membership.
SAML loop / 307 stormIdP hairpinned through ZIA and also required to authenticate.PAC DIRECT + Authentication Exemptions for the IdP. Packet/HAR 307 to login.microsoftonline.com.
Office shows Road WarriorGRE/IPSec source IP not on the location. Or failover never used.Tunnel Insights source IP ≠ location static IP 203.0.113.10.
Do Not Inspect still InspectedEUN “Show Notifications” forces decrypt. Or URL was Miscellaneous then AI/ML recategorized after inspect.SSL Policy Reason runbook; Inspected despite Do Not Inspect.
QUIC / YouTube “no web detail”UDP/443 bypasses HTTPS inspect. Not a URL ticket.Firewall Insights UDP 443. Control QUIC so HTTPS falls back to TCP.
Works in Chrome, fails in FirefoxFirefox does not use the OS trust store for the inspect CA.Same Web row, different client trust. Deploy CA to Firefox policy.
Do not add a global SSL or URL bypass to “make it work”

A bypass hides the desk you needed to prove and removes inspect for everyone. Scoped custom category, scoped Do Not Inspect, PAC DIRECT for IdP, or GRE repair. Bypass is last, time-boxed, named in the ticket.

Pilot checklist

Knowledge check

Six judgment items. Submit once. Reasons point back at the section to re-read.

Q1

Priya reports a Zscaler block page on a business SaaS URL. What is the first move?

Correct: b. The block page is not the policy. Policy Reason and the rule name are. A global allow hides Cloud App Control, group mismatch and SSL. Re-read Why a symptom is not a policy and Side B.
Q2

Browser shows certificate not trusted. Web Insights: SSL Inspected = Yes, SSL Policy Reason = Inspected. First fix?

Correct: c. Inspected + untrusted cert is a CA distribution ticket. Global decrypt-off is not a fix. URL allow does not issue a trusted intercept cert. Re-read Which ticket is this (SSL) and Side C SSL.
Q3

The whole Bengaluru floor loses ZIA. Web Insights for those users shows Location = Road Warrior. GRE source should be 203.0.113.10. What is the ticket?

Correct: d. Road Warrior on an office desk means the location does not own that public IP or the tunnel is down. URL and SSL are the wrong desks. Re-read Flow 2 and Side C GRE/IPSec.
Q4

After Enforce Authentication on the PAC/GRE location, users hit a SAML redirect loop. First fix?

Correct: b. IdP through ZIA plus auth redirect is the documented 307 loop. Exempt IdP in PAC and Authentication Exemptions; keep Enforce Authentication on the location. Re-read Side C Auth and PAC.
Q5

A PAC user can open a site. Web Insights has no row for that URL and time. What does that mean?

Correct: a. No row is a forwarding miss. Insights Logs are the transaction table for traffic ZIA processed. Blocked web still logs a Policy Reason. Re-read Flow 1 miss at step 2 and Side B empty table.
Q6

What actually closes the Priya ticket?

Correct: c. Close is before/after Insights fields on the original flow. Chat confirmation without a row is not proof. Re-read Runtime and Pilot checklist.

Sources

Related: Authentication · SSL inspection · GRE & IPSec · URL + Cloud App Control · ZIA command center · ZCC troubleshooting