Zscaler Cloud Connect

I am looking for a solution which should meet below requirement (solution could be mix ZIA, ZPA, Cloud Connector)
remote user client machine → Public Cloud resource access (Azure)
remote user client machine → ZIA/ZPA exception
remote user client machine → non http/s ports to Internet
remote user client machine → Azure–> S2S VPN

Does ZIA/ZPA support non http/https ports for exception ?
Does Zscaler Cloud connector has ability to forward the traffic to 3rd party firewall(in Azure)
(remote client machine -->Cloud Connector(Azure)—>PAFW(Azure)–>Internet

Your swift response is highly appreciated.

Wondering if you’re referring to Third-Party Proxy Chaining for the ‘forward the traffic to 3rd party’.

Thanks for the response.
No I am referring 3rd party firewall. As i shown in the traffic flow.
I have 4 use cases see below. From the remote machine i need to achieve.

remote user client machine → Public Cloud resource access (Azure)
remote user client machine → ZIA/ZPA exception
remote user client machine → non http/s ports to Internet (takes the PIP of PAFW in azure cloud)
remote user client machine → Azure–> S2S VPN