ZPA to bypass ZIA?

Hello Community, when using both ZIA and ZPA, is there any recommended ZPA related traffic that we should bypass from ZIA? Reading some post here I found out that App Connector traffic needs to be send directly over the internet (no thru ZIA), is this correct?

If you use PAC based forwarding Yes synthetic ZPA public IP ranges needed to be bypassed

Yes ---- this can be done via both PAC Files — DTLS 2.0 clients require both FWD and APP Pac Files for some exclusions — also in ZPA watch for issues with Internal and External SSO authentication points that may be back hauled over split tunnel VPN connections