Avantec AG
Port
Zscaler Client Connector – Z Tunnel 2.0 before and after Version 3.8 – Tec-Bite
- 07 August 2026
- 10 – 100%
- Permanent position
- Port
About the job
The Zscaler Client Connector Version 3.8? But that is already outdated and Zscaler has already released Version 4.2.0.198. So why is this one so exciting now? The Zscaler Version 3.8 is so exciting because Zscaler implemented new features for forwarding options in this version. These are the two functions "Redirect Web Traffic to Zscaler Client Connector Listening Proxy" and "Use Z-Tunnel 2.0 for Proxied Web Traffic". But what can these two features do and what changes? This is precisely explained in depth in this blog post.Where is the feature found and what does it do?Both features are visible in the Zscaler Client Connector GUI under Administration | Forwarding Profile in the Forwarding Profile when forwarding is set to "Tunnel" and after selecting "Z-Tunnel 2.0", found in the dropdown menu "Z-Tunnel 2.0 Transport Settings"."Redirect Web Traffic to Zscaler Client Connector Listening Proxy" and "Use Z-Tunnel 2.0 for Proxied Web Traffic"Now that it is known where these features can be set, we turn to the description of the two features.Redirect Web Traffic to Zscaler Client Connector Listening Proxy:The Zscaler description of this setting includes that when this feature is activated, all traffic on port 80/443 is forwarded to the Zscaler Listening Proxy."Use Z-Tunnel 2.0 for Proxied Web Traffic": The Zscaler description of this feature states that traffic on the Zscaler Client Connector Listening Proxy is sent to Zscaler via Z-Tunnel 2.0. Otherwise, this traffic is sent to Zscaler via Z-Tunnel 1.0.Now that the description of the features is known, we turn to their functionality.Function of the two featuresTo understand the functionality of the two features, the forwarding operation of the Zscaler Client Connector must first be understood.Before Zscaler Version 3.8, the simplified forwarding operation was as follows. When a request came from a browser, the forwarding profile first checked whether Tunnel 2.0 should be "bypassed" or not. If the traffic was to go via Tunnel 2.0, the traffic was then checked in the app profile via the Tunnel 2.0 Configuration "Destination Exclusions" and "Destination Inclusions". If the traffic matched the "Destination Inclusions", it was forwarded to Zscaler based on the app profile PAC file.If the traffic had a bypass for Tunnel 2.0, it was forwarded directly to the Zscaler Client Connector Listening Proxy. Then it was forwarded based on the app profile either "DIRECT" or via Z-Tunnel 1.0 to Zscaler.Forwarding without the features "Redirect Web Traffic to Zscaler Client Connector Listening Proxy" and "Use Z-Tunnel 2.0 for Proxied Web Traffic"With Version 3.8 came the new forwarding, which works simply as follows: The traffic is now analysed directly by the browser based on the LWF Table, i.e. the Zscaler Z-Tunnel 2.0 Configuration. If the traffic matches the "Destination Inclusions", the web traffic (according to Zscaler's help page) can be forwarded on ports 80 and 443 to Zscaler via the feature "Redirect Web Traffic to ZCC Listening Proxy". This traffic is then analysed next via the app profile PAC file. If according to the PAC file the traffic should go to Zscaler, the traffic can be sent to Zscaler via Z-Tunnel 2.0 instead of via Z-Tunnel 1.0 using the feature "Use Z-Tunnel 2.0 for Proxied Web Traffic".Forwarding with the features "Redirect Web Traffic to Zscaler Client Connector Listening Proxy" and "Use Z-Tunnel 2.0 for Proxied Web Traffic"And what is the advantage of this?Advantages of the two featuresWhen reading through the two modes of operation, it is noticeable that with the new settings only one PAC file is used, and that is the app profile PAC file. This simplifies the administrator configuration on the Zscaler side. Furthermore, with the new features, Fiddler / "Charles Proxy" captures can be created again. Also, by using Z-Tunnel 2.0 with DTLS in the correct configuration, performance improvements can be achieved. One exception is if the provider blocks DTLS traffic. In that case, TLS would still have to be used for Z-Tunnel 2.0. However, even in this configuration, performance improvements can occur with the new features.Are there any disadvantages?Disadvantages of the two featuresIf the features are not configured correctly, this can affect performance and thus user satisfaction. Otherwise, we are currently not aware of any disadvantages of the two features.What does this mean now?First: The old configuration with two PAC files (forwarding and app profile PAC file) still works. That is, after Version 3.8 and without using the two features. When using the two features from Version 3.8 onwards, it is important to align the configuration to the new two features so that no disadvantages arise.Further links:www.avantec.ch/loesungen/zscaler/zscaler-secure-internet-accesswww.avantec.ch/webinareThe article Zscaler Client Connector – Z Tunnel 2.0 before and after Version 3.8 first appeared on Tec-Bite.