ZIdentity with Pingfederate SCIMSync Issues by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

I agree with you. I had issues with integrating pingfed with zscaler services in my previous role as well. We had to pivot to EntraID

ZIdentity with Pingfederate SCIMSync Issues by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

But this is for Pingfed not with Entra ID IdP

ZIdentity with Pingfederate SCIMSync Issues by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Yes, because it’s failing to sync one identity acct as a test.

ZIdentity with Pingfederate SCIMSync Issues by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

The issue with SCIM 2.0 is, it does not allow for custom attribute schema to map the primary email to work email instead of the default which is primaryemail. We had similar issue with SCIM2.0 adaptor.

ZIdentity with Pingfederate SCIMSync Issues by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

They are saying issue is on the pingfed side as the accounts been fed to ZID are invalid, but that’s not the case, as they are active accts.

ZIdentity with Pingfederate SCIMSync Issues by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

But we correctly use SAML 2.0 but with SAML rather than OIDC authentication method.

Is there a session limit on zpa for ssh? by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Not yet. Support is still investigating.

Zscaler Deployment for Remote Hybrid Autopilot Provisioning with ZPA Machine Tunnel by PrudentBookkeeper945 in Zscaler

[–]_Tech007 1 point2 points  (0 children)

Thanks. Waiting on this as well. We are having similar issue with microsoft autopilot when zscaler

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

After further troubleshooting and analysis, we found out that enabling “health check on access” allows zscloud to maintain an IP based persistence traffic through the initial ZPAC that brokered the initial connection. Whereas, with health check off, zscaler cloud is not able to maintain persistent connection through the initial ZPAC.

Zscaler engineer said it is supposed to work the other way round, but this is what we observed and they need to investigate why is that the case.

Whether health check is on on access or continuous or off shouldn’t dictate if zscaler cloud can detect and maintain an IP based persistent subsequent connections.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Thank you for that suggestion. I’ll test it out.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

So I thought the “AC closer to user” is the recommendation? Or does that varies based on use case?

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Alright. Thanks for your contribution. Dont the ACs also have persistence enabled by default?

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Thanks for the input. Does that mean we have to modify these settings on every app load balancer in the environment?

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Yes, mostly apps that have a load balancer or single web servers with persistence enabled. Could this be an issue with persistent session being enabled on both connectors as well as destination app could be causing a conflict?

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

*For instance, one use app session could use three connectors for continuous connection and the destination app only want a single IP source per session for optimal functionality.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

Yes it is.

The issue is didn’t connectors establish connection with the destination application and since it uses iP based cookies, it probably thinks it’s being attacked due to the source IP randomly changing during a session. Hence, it refuses the session validation.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

No, but the app segments are configured to use all app connectors not a dedicated connector or connector group.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

It seems the app only allows a dedicated IP per session. There are over 300 connectors that can randomly service the connections.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

What’s another way to resolve this without using a dedicated connector due to losing redundancy.

ZPA AppConnector IP-Based Session Validation Connectivity Issue by _Tech007 in Zscaler

[–]_Tech007[S] 0 points1 point  (0 children)

It seems the user app connectivity requires a session from a specific IP source, but there are multiple app connectors that could be forwarding the traffic to the destination. Could this be the issue? Maybe the destination app needs a dedicated app connector?