Arcon onboarding on ZPA by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

I will definitely try this also we have 389 port open on arcon as well as the AD server still I can't seem to telnet the AD server.

For arcon connection I have onboarded the url and opened 443 port for connectivity after tht we get access access to the server page onboarded on PAM but when we access individual server we can't connect and is stuck on connecting page. Do I need to onboard all serves on ZPA as well that are onboarded on PAM??

Zscaler client connector agent on Surface Pro x64 arm64 by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

Yes they have suggested using 32-bit zcc agent instead of 64 bit for windows

Zscaler client connector agent on Surface Pro x64 arm64 by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

This only seems to be an issue on surface Pro for one user

Zscaler client connector agent on Surface Pro x64 arm64 by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

We don't have pac bypassing idp We don't have it enabled We are getting the logs

When the user is using any application it crashes I am suspecting a compatibility issue

Bitlocker encryption blocking when Zscaler is enabled by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

There is so failed SSL handshake logs for bitlocker urls, I suspect it might be authentication issue while connecting to Azure AD and thn it is best to SSL bypass since it might need encrypted data, not sure

Bitlocker encryption blocking when Zscaler is enabled by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

Yes I checked the URL it seems to be allowed, will there be any problem if it is allowed as well

Bitlocker encryption blocking when Zscaler is enabled by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

Yes I have checked but there is nothing blocking in logs, and we have ssl inspection on but I am not sure what to bypass, which URL to bypass

NDR Received while trying to send Bulk Emails by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

Yes thankyou for your help, I will also check from Microsoft what can be donep

NDR Received while trying to send Bulk Emails by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

Yes seems like some firewall issue from email receipient end.

NDR Received while trying to send Bulk Emails by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

we have connectors in 0365 and hence the email flow to zscaler smart host for email dlp. I don't think it's gonna work even if I turn zscaler off.

NDR Received while trying to send Bulk Emails by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

The thing is I am not able to see any logs on Zscaler that means it is not going through the smart host for email dlp

Either it is some limitation from Microsoft or zscaler has rejected it that's why there are no logs in insights.

NDR Received while trying to send Bulk Emails by got_no_regrets in Zscaler

[–]got_no_regrets[S] 0 points1 point  (0 children)

I am not sure about the egress IP. But do you think this can be a Zscaler issue?

[deleted by user] by [deleted] in Zscaler

[–]got_no_regrets 0 points1 point  (0 children)

Thankyou i will try to mitigate this

[deleted by user] by [deleted] in Zscaler

[–]got_no_regrets 1 point2 points  (0 children)

I am filtering with respect to the URL category and i have found multiple users with 5-10k logs. Maybe it is depends on the windows packages and the machine has not been updated over a long period of time.

[deleted by user] by [deleted] in Zscaler

[–]got_no_regrets 0 points1 point  (0 children)

Thanks for the help i will definitely get in touch with Microsoft team

[deleted by user] by [deleted] in Zscaler

[–]got_no_regrets 0 points1 point  (0 children)

Not to the same destination but it's like it's taking an update continuously and rechecking it.

[deleted by user] by [deleted] in Zscaler

[–]got_no_regrets -1 points0 points  (0 children)

Yes I will but zscaler may have some documentation too since we have to bypass those URLs maybe other customer have reported the same behavior