is there a sleak way to enable ZPA ICMP-access globally e.g. for a dedicated Azure VNET (e.g. /26)? Right now it seems I would have to create an app segment containing every single VNET-IP-address as application. Doable, but still a bit cumbersome. Any ideas?
And one more thing: pinging hostnames is a little awkward as always CGNAT address will respond. Pinging hostnames would be even more helpful if the particular IP-address of the pinged host(name) would be shown in the ICMP response. But I guess that’s just because of the way ZCC/Zscaler works with DNS and CGNAT for now.