Zscaler Cisco Anyconnect



Hello! We are currently deploying Zscaler App to customer and having compatibility issue with Cisco AnyConnect Secure Mobility Client. The agent is only for Network access control.
We found that the issue happen when user switch from wired network to wireless network. Both network are also connected to the same corporate network internally. When user switch network, the Cisco AnyConnect Secure Mobility Client will act as NAC solution and check for 3 things before allow the user connect to internal corporate network:

Anyconnect

The Zscaler Cloud Security Platform elastically scales to your users' traffic demands, even hard-to-inspect SSL. Zscaler processes more than 100 billion transactions at peak periods and performs 120,000 unique security updates each day. Any threat detected in. Jan 19, 2018 Allow a Local Proxy Connection Procedure Step 1 Open the VPN Profile Editor and choose Preferences (Part 2) from the navigation pane. Step 2 Select (default) or unselect Allow Local Proxy Connections.

  1. Check if the PC is domain-joined
  2. Check the Antivirus is installed
  3. Check the Virus signature is up-to-date
    After all checking are compliant, user will be allowed to access the internal corporate network.
Zscaler cisco anyconnect app

After installed Zscaler App, we found on Zscaler App that when switch between network, the ZApp will show message that indicate not able to reach internet. This is normal since Cisco agent need to complete the checking before allow the network. However after the Cisco agent completed the checking and show compliant, the ZApp still showing the same error message. We observed the symptom on the affected PC as below:

Zscaler Cisco Anyconnect Windows 10

  • Not able to access any internal website
  • Not able to access internet
  • not able to resolve DNS with internal DNS server
    The issue remain the same when we try to restart the checking on Cisco agent.
    The issue is Intermittent and it does NOT happen every time when switch between network.
    It could only be resumed when user restart the PC.

Cisco Anyconnect And Zscaler

May I know if there is any previous experience sharing that install Zscaler App to Cisco ISE agent environment, or any other NAC solution?