Avantec AG
Port
Zscaler Internet Access Forwarding – AVANTEC
- 07 August 2026
- 100%
- Permanent position
- Port
About the job
Tunnel 2.0, GRE, PAC File, Tunnel 1.0, direct proxy entry, IPSec or a combination of the various forwarding options? What is best practice? Which method is required for which devices? Many proxy administrators and security officers face this question when planning the configuration of Zscaler or adapting their configuration to current possibilities. To shed some light in the darkness or rather, to ignite some light on the horizon, the following outlines the various forwarding methods and combination possibilities.Forwarding MethodsThe following table provides a brief overview of the forwarding methods and their possible uses.Forwarding MethodDescriptionDevicesUse CaseDirect Proxy EntryThe direct proxy entry can be set in the system settings of the respective device and is used for any proxy-capable traffic.Clients, ServersAvailability testing Zscaler & TroubleshootingPAC FileThe PAC file forwarding can be set in the system settings, for example via GPO. It forwards any proxy PAC-capable trafficClients, ServersClients & Server tests and troubleshootingPAC File combined with GRE or IPSec TunnelThe PAC file forwarding can be set in the system settings, for example via GPO. It forwards any proxy PAC-capable trafficClients, ServersClients & Servers for corporate sitesZscaler Client Connector Tunnel with local ProxyDirect forwarding of Zscaler traffic via local proxy for proxy PAC-capable traffic.ClientsClients in combination with additional client VPN solutionsZscaler Client Connector Tunnel Version 1.0Transparent forwarding of any HTTP/HTTPS traffic on ports 80 and 443 to Zscaler.ClientsClients Windows, Linux & MacOS as well as Android and iOSZscaler Client Connector Tunnel Version 2.0Transparent forwarding of any traffic to Zscaler regardless of ports and protocols.*ClientsClients Windows, Linux & MacOS as well as Android and iOSGRE & IPSec TunnelsTransparent or explicit forwarding of traffic to Zscaler via defined routing on the GRE or IPSec-capable endpoint device.Clients, Servers, IoT, Guest Wifi networksServers, IoT devices or in combination with clients using PAC files.*There are individual protocols that cannot be sent via Zscaler Tunnel 2.0 due to their protocol structure.So far so good. The forwarding methods are now known, but which should be used?Forwarding for my companyWhich forwarding method should be used in the company depends on the company’s infrastructure. Likewise, the forwarding methods at Zscaler have developed significantly in recent years. The following two examples show different use cases for different companies.Example 1 – "Greenfield" CompanyThe "Greenfield" company currently has no security in the area of proxies. Firewalls are also being replaced by new appliances. Security for clients (everywhere), servers and IoT devices is to be developed.In this case, the following forwarding is recommended:Clients: Zscaler Client Connector with Tunnel 2.0Servers: GRE tunnel with source-based routing or, if a PAC file is desired, with destination-based routing using Global ZEN IP addressesIoT: GRE tunnel with source-based routingThis forwarding is recommended because the use of the Zscaler Client Connector allows features such as captive portal detection, authentication and traffic forwarding on clients for all ports and protocols to be controlled. The use of the GRE tunnel for servers and IoT devices enables transparent forwarding to Zscaler. Using the GRE tunnel allows advantages such as creating sublocations based on internal IP addresses to be used.Example 2 – Company "VPN product will only be replaced in 3 years"The company "VPN product will only be replaced in 3 years" has just purchased a VPN product that must be compatible with Zscaler forwarding. The company has no IoT devices but does have servers. The customer’s location has no fixed public IP address.In this case, the following forwarding is recommended:Clients: Zscaler Client ConnectorOn Trusted Network, i.e. internal: Tunnel 2.0VPN Trusted Network, i.e. connected via VPN: Tunnel 2.0 if possible, otherwise Tunnel with local ProxyOff Trusted Network, i.e. as a "RoadWarrior": Tunnel 2.0Servers: IPSec tunnel with source-based routing or, if a PAC file is desired, with destination-based routing using Global ZEN IP addresses.This forwarding is recommended because the above-mentioned advantages can be used by using the Zscaler Client Connector. For the On, VPN and Off Trusted Network, it can be decided which forwarding method should be used. The IPSec tunnel is recommended because it can also establish the tunnel via FQDNs. The advantage of sublocations is also given. However, the IPSec tunnel does not have the same throughput capabilities as the GRE tunnel (250-400 Mbps versus 1000 Mbps).PAC File directly or via GREDuring implementation in both companies, the question arises whether the PAC file should be downloaded directly or via GRE/IPSec.For answering this question, some background is necessary. It is important to know that the Zscaler Client Connector also includes a PAC file for traffic forwarding. What happens if the Zscaler Client Connector has to download the PAC file via GRE tunnel and the tunnel has an error and can no longer connect? Exactly, all clients with a Zscaler Client Connector as well as all servers with a PAC file cannot download the PAC file anymore and can lose access to Zscaler and thus to the internet. The easiest workaround for clients and servers to adjust the PAC file is thus prevented, as the PAC file is not available for the clients.For this reason, it is recommended that the PAC file can be downloaded directly. For servers without internet access, any PAC file used can also be hosted internally.Global ZEN IP addresses and destination-based routing – what is that?Earlier there was mention of Global ZEN IP addresses and destination-based routing. These two keywords belong to forwarding PAC file with IPSec or GRE tunnel. First, the explanation of the Global ZEN IP addresses. These IP addresses can be processed in all Zscaler datacentres but should only be used in combination with a GRE or IPSec tunnel. For the use of the Global ZEN IP addresses, destination-based routing is recommended for routing in the GRE tunnel. By setting the proxy entry to the Global ZEN IP address in the PAC file, the traffic can then be routed via tunnel to Zscaler.And why should one do that? A valid question! This forwarding offers the advantage that the same PAC files can be used internally worldwide. Furthermore, routing on the GRE or IPSec-capable device of the respective location can basically be set up the same way, just to different Zscaler datacentres. This helps to create a uniform setup in the company. Various backup variants can also be stored in the PAC files, which, for example, trigger the targeting of another Zscaler datacentre through a tunnel switch. Here too, it is advantageous if the PAC file is downloaded directly and not via the GRE or IPSec tunnel.And now? Yes, now the light on the horizon should shine a little brighter.UNCODE.initRow(document.getElementById("row-unique-0"));The article Zscaler Internet Access Forwarding first appeared on Tec-Bite.