Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

IPv6 Traffic Forwarding in Zscaler Zero Trust Exchange

Zscaler
08/09/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this series of short videos, we'll be taking a look at recommendations for forwarding your traffic to the Zero Trust Exchange. This is part 6 covering IPv6 traffic. As IPv6 gradually replaces IPv4, enterprises and service providers are migrating their internal networks to IPv6 to overcome IPv4 exhaustion and other shortcomings of the protocol. Additionally, mobile internet access has accelerated the depletion of the IPv4 address space, leading service providers to deploy IPv6-only addresses to mobile devices. Although Zscaler's cloud infrastructure can handle IPv6 traffic, the majority of Zscaler's public service edges today do not support IPv6. The exception are some public service edges on the Zscaler3 cloud. It is recommended that you activate the Prioritize IPv4 over IPv6 setting in the app profile so that traffic sent to the Zero Trust Exchange is preferentially forwarded as IPv4. In cases where you need to forward IPv6 traffic to the Zero Trust Exchange, there are several recommendations and limitations to keep in mind. For destinations that support IPv4, the recommended method of forwarding user traffic with IPv6 as transport is to use Zscaler Client Connector with Ztunnel2, which will automatically translate the traffic to IPv4. For locations, you should route the IPv6 traffic through an IPv4 GRE or IPsec tunnel, which will accomplish the same thing. For destinations that do not support IPv4, you will need to ensure you have enabled the Enable IPv6 resolution for Zscaler Domains field in the Zscaler Client Connector portal. Otherwise, you will need to route your traffic through an ISP-provided NAT64 gateway. For ZPA, App Connectors and ZPA Private Service Edges are dual-stack aware, meaning IPv4 and IPv6 run simultaneously alongside each other. An IPv4 endpoint through Zscaler Client Connector to access an IPv4 application on a server is supported for TCP, UDP, and ICMP-based connections. The same is true for an IPv6 endpoint through ZCC to access an IPv4 application on a server. However, an IPv4 or IPv6 endpoint through Zscaler Client Connector to access an IPv6-only application on a server is only partially supported, and only TCP-based connections are supported for direct IPv6 communications from an App Connector to a server. That's it for this video. Thanks for watching!

TL;DR

  • Most Zscaler public service edges do not currently support IPv6, though the cloud infrastructure can handle it; exceptions exist on the Zscaler3 cloud.
  • For ZIA deployments, activate 'Prioritize IPv4 over IPv6' in app profiles and use Ztunnel2 or GRE/IPsec tunnels to translate IPv6 traffic to IPv4.
  • ZPA App Connectors support dual-stack operation with full IPv4-to-IPv4 connectivity across TCP, UDP, and ICMP, but IPv6-only application access is limited to TCP connections only.

Summary

This technical tutorial addresses IPv6 traffic forwarding to Zscaler's Zero Trust Exchange, a critical consideration as enterprises migrate from IPv4 to overcome address exhaustion. While Zscaler's cloud infrastructure supports IPv6, most public service edges currently do not, with exceptions on the Zscaler3 cloud. The video provides specific configuration guidance for both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) deployments. For ZIA, the recommended approach is to prioritize IPv4 over IPv6 in app profiles, with fallback options including Ztunnel2 for automatic IPv4 translation or GRE/IPsec tunnels for location-based traffic. For ZPA, App Connectors and Private Service Edges operate in dual-stack mode, supporting IPv4-to-IPv4 connections fully across TCP, UDP, and ICMP protocols, while IPv6-only application access faces limitations with only TCP-based connections supported for direct communication. The guidance emphasizes workarounds for current IPv6 limitations while acknowledging the ongoing industry transition to IPv6 addressing.

Chapters

0:00 - Introduction
0:15 - IPv6 Support for ZIA
0:54 - Configuration Recommendations
1:59 - IPv6 for ZPA

Key Quotes

0:39 "Although Zscaler's cloud infrastructure can handle IPv6 traffic, the majority of Zscaler's public service edges today do not support IPv6."
0:54 "It is recommended that you activate the Prioritize IPv4 over IPv6 setting in the app profile so that traffic sent to the Zero Trust Exchange is preferentially forwarded as IPv4."
2:36 "However, an IPv4 or IPv6 endpoint through Zscaler Client Connector to access an IPv6-only application on a server is only partially supported, and only TCP-based connections are supported for direct IPv6 communications from an App Connector to a server."

FAQ

Why doesn't Zscaler fully support IPv6 on all public service edges?

While Zscaler's cloud infrastructure can handle IPv6 traffic, the majority of public service edges currently do not support IPv6, with exceptions on the Zscaler3 cloud. The recommended workaround is to prioritize IPv4 over IPv6 in app profiles and use translation mechanisms like Ztunnel2 or GRE/IPsec tunnels.

What are the limitations for accessing IPv6-only applications through ZPA?

IPv6-only application access through ZPA is only partially supported. While IPv4-to-IPv4 connections support TCP, UDP, and ICMP protocols, IPv6-only applications accessed through Zscaler Client Connector only support TCP-based connections for direct communication from App Connectors to servers.


Categories:
  • » Cybersecurity » Zero Trust
  • » Webinar Library » Zscaler
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • SASE
  • SSE
  • Technical Deep Dive
  • How-To
  • IPv6 migration
  • Zero Trust Exchange
  • Zscaler Internet Access
  • Zscaler Private Access
  • dual-stack networking
  • IPv4 translation
  • GRE tunnels
  • IPsec tunnels
  • App Connectors
  • Ztunnel2
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: IPv6 Traffic Forwarding in Zscaler Zero Trust Exchange

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Aug
                  13

                  Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                  08/13/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/27/2026
                    01:00 PM
                    08/27/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version