Use policy-based routes to send all Ztunnel2 traffic directly to the internet to avoid double-encapsulation. If policy-based routing isn't possible, configure ZCC's Trusted Network Detection to use Ztunnel1 when on the corporate network, and enable authentication and IP surrogacy at the location level to maintain user attribution.