Zscaler is preventing Pulse Secure VPN to install it's route

We noticed that Zscaler is preventing Pulse Secure VPN to install it’s route.
Due to this we are unable to access our VPN dependent sites even though Pulse Secure is connecting fine.

We are observing this issue only with Ubuntu & macOS.

Any thoughts/suggestions on this ?

Thanks,
Rahul Vennu

Are you using ZCC for internet access access and private access. ?
Have you bypassed pulse secure IPs on Zscaler under VPN bypasses?
Zscaler destinations like hub IPs and SE IPs should bypassed from VPN for better performance.

Hello Ramesh,

We are using ZCC for Internet Access.

Our Pulse Secure is a Split Tunnel configuration & yes, we have already by-passed the VPN gateway in the App Profile as well.

Thanks,
Rahul Vennu

Any suggestions ?

Thanks,
Rahul V

Hi Rahul,

Are you using ZIA Tunnel 1.0 or Tunnel 2.0 for your split tunnel config ?
Is your Linux and MacOS using the same Forwarding Profile as your other OS App Profiles ?

G

Hello Gerhard,

We are on Z-Tunnel 2.0.
Yes, our Linux & macOS are using same Forwarding Profiles as other OS App Profile (i.e. windows)

Thanks,
Rahul V

Can you share a screenshot or explain the options configured under your Forwarding profile ?
Specifically how “FORWARDING PROFILE ACTION FOR ZIA” is configured when ‘Off Trusted Network’

G

Here is our Configuration for the Forwarding Profile

Tunnel Driver Type: Packet Filter Based

FORWARDING PROFILE ACTION FOR ZIA

On Trusted Network: NONE
VPN Trusted Network: Tunnel (Z-Tunnel 2.0 with DTLS)
Off Trusted Network: Tunnel (Z-Tunnel 2.0 with DTLS)

System Proxy is set to NEVER for all the three

Thanks,
Rahul Vennu

As you are using Split tunnel Vpn I’d suggest changing your VPN to None rather than Tunnel.

This will allow the corporate ranges included in your split tunnel config and everything else via Tunnel 2.0

Hope this helps

G

Ok, I will try this & let you know.

Thanks,
Rahul V

Hello Gerhard,

Tried it.
But its the same issue still.

Thanks,
Rahul Vennu

Hi Rahul,

That’s super odd !
I can only suggest a Support Ticket then but kindly share the fix when possible

G