Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Forwarding Corporate Location Traffic to Zscaler ZIA

Zscaler
08/03/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this series of short videos, we'll be taking a look at recommendations for forwarding your traffic to the Zero Trust Exchange. This is part 5, forwarding traffic from locations. For known locations where you have deployed enterprise-grade internet gateways, you have the ability to build GRE or IPsec tunnels to the Zero Trust Exchange. The choice between the two will largely depend on two factors. First, tunnels can normally be built from gateway routers or SD-WAN boxes. Depending on the type and model of equipment, these will support one or both tunnel types. Secondly, GRE tunnels require a static IP address at the site. Whenever possible, Zscaler recommends using GRE rather than IPsec tunnels, as GRE has greater throughput and has the least amount of overhead. We also recommend that customers forward traffic via GRE without a NAT device between users and the ZIA service edge, with surrogate IP and authentication enabled in the ZIA location settings. This will ensure that traffic is properly load-balanced and that user-identity-based policies are applied to all traffic. Finally, we require two tunnels be configured to two different public service edges for each location, in an active, standby configuration. We strongly recommend setting up monitoring and automated tunnel failover for these tunnels as a best practice. Finally, as a reminder, Zscaler recommends installing ZCC on all user devices. However, remember that using Ztunnel2 on trusted network when traffic is also routed through a GRE or IPsec tunnel is not recommended, as this would double-encapsulate non-web traffic and slow down the processing of your user traffic. To address this, Zscaler recommends using policy-based routes to route all Ztunnel2 traffic directly to the internet. Note that the full list of Zscaler IPs is published online on our website within the config.zscaler.com pages. It's recommended that you subscribe to the trust portal notifications for your Zscaler cloud to receive updates whenever these change, as routes will need to be configured on each device where a GRE or IPsec tunnel is built, to bypass Ztunnel2 traffic from being forwarded inside said tunnel. If policy-based routing is not possible, then an alternative option is to use the ClientConnector Trusted Network Detection settings and configure ZCC to use Ztunnel1 when it detects that it is on the corporate network. Note that this method requires enforcing authentication and IP surrogacy at the location level to maintain user attribution on non-web traffic. You can then configure sublocations in the ZIA admin portal for each type of non-user traffic, such as traffic from IoT devices or guest Wi-Fi traffic, in order to disable authentication and attribution for that non-user traffic. That's it for this video. Thanks for watching!

TL;DR

  • Zscaler recommends GRE tunnels over IPsec for forwarding corporate location traffic to ZIA due to greater throughput and lower overhead, though tunnel type choice depends on gateway equipment support and static IP availability.
  • Deploy two tunnels per location to different public service edges in active-standby configuration with automated failover monitoring, and forward traffic without NAT devices while enabling surrogate IP and authentication for proper load balancing.
  • When using ZCC on corporate networks with location tunnels, implement policy-based routing to send Ztunnel2 traffic directly to the internet, or configure trusted network detection to switch ZCC to Ztunnel1 mode to prevent double-encapsulation.

Summary

This technical tutorial demonstrates how to forward traffic from corporate locations to Zscaler Internet Access (ZIA) using GRE or IPsec tunnels. The video covers tunnel selection criteria based on gateway equipment capabilities and static IP availability, with Zscaler recommending GRE tunnels for superior throughput and lower overhead. Key configuration guidance includes deploying tunnels without NAT devices, enabling surrogate IP and authentication for proper load balancing and user-identity policies, and establishing active-standby tunnel pairs to different public service edges with automated failover monitoring. The session also addresses the challenge of running Zscaler Client Connector (ZCC) on corporate networks where location-based tunnels are already deployed, explaining how to prevent double-encapsulation of non-web traffic through policy-based routing or trusted network detection settings. Additional configuration options for handling IoT devices and guest Wi-Fi traffic through sublocations are covered to maintain proper traffic attribution while accommodating different device types on the corporate network.

Chapters

0:00 - Introduction
0:14 - Forwarding Location Traffic
0:43 - GRE vs IPsec Tunnels
1:50 - ZCC on Trusted Networks

Key Quotes

0:43 "Whenever possible, Zscaler recommends using GRE rather than IPsec tunnels, as GRE has greater throughput and has the least amount of overhead."
0:53 "We also recommend that customers forward traffic via GRE without a NAT device between users and the ZIA service edge, with surrogate IP and authentication enabled in the ZIA location settings."
1:33 "Using Ztunnel2 on trusted network when traffic is also routed through a GRE or IPsec tunnel is not recommended, as this would double-encapsulate non-web traffic and slow down the processing of your user traffic."

FAQ

Why does Zscaler recommend GRE tunnels over IPsec for forwarding location traffic?

GRE tunnels provide greater throughput and have the least amount of overhead compared to IPsec tunnels. However, the choice between the two depends on what your gateway equipment supports and whether you have a static IP address at the site, as GRE requires a static IP.

How should I configure ZCC when users are on the corporate network that already has GRE or IPsec tunnels to ZIA?

Use policy-based routes to send all Ztunnel2 traffic directly to the internet to avoid double-encapsulation. If policy-based routing isn't possible, configure ZCC's Trusted Network Detection to use Ztunnel1 when on the corporate network, and enable authentication and IP surrogacy at the location level to maintain user attribution.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • SASE
  • SSE
  • Zero Trust
  • Technical Deep Dive
  • How-To
  • GRE tunnels
  • IPsec tunnels
  • traffic forwarding
  • Zero Trust Exchange
  • Zscaler Client Connector
  • network configuration
  • surrogate IP
  • policy-based routing
  • trusted network detection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Forwarding Corporate Location Traffic to Zscaler ZIA

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Age of AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Age of AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-age-of-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-revolutionizing-identity-attacks-same-tactics-enhanced-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version