XE75 Pro and Zscaler

There seems to be an incompatibility between Zscaler VPN and the Deco XE75 Pro. I cannot maintain a stable connection to Zscaler from my work laptop while on my home WiFi.
I have been able to get around the problem by using a Meraki VPN to connect to my office network and Zscaler maintains a stable connection then. This is not ideal as the office network connection is quite slow.
This didn't use to be a problem.
Any help with getting the XE75 Pro working with the Zscaler would be greatly appreciated.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content

Hi, welcome to the community.
There is a beta firmware that might help with the report issue. If you're interested, you can find it in the Message box.
It could revert to the official 1.2.14 directly via web UI.
Wait for your reply.
Best regards.
- Copy Link
- Report Inappropriate Content
See if the following helps if not please get back to me.
Zscaler Client Connector and Deco routers can have interoperability issues, particularly when using the Zscaler Client Connector in Tunnel mode and the Deco router's VPN feature. Zscaler recommends using Tunnel with Local Proxy or a packet filter-based tunnel with Deco's VPN due to potential conflicts with IP layer routing. Some users have reported performance issues, such as slow upload speeds or dropped connections, when using Zscaler with a Deco router in router mode. Setting the Deco to Access Point (AP) mode or ensuring the Zscaler client is up to date can help mitigate these problems.
Here's a more detailed explanation:
Interoperability Issues:
Tunnel vs. Tunnel with Local Proxy:
.
Zscaler Client Connector in Tunnel mode works on the IP layer, which can conflict with how Deco's VPN (particularly L2TP/IPSec) handles routing. This can lead to performance degradation or traffic being blocked.
Split Tunneling:
.
If the Deco's VPN is set up in split-tunnel mode, where only some traffic is routed through the VPN, Zscaler may not recognize it as a "VPN Trusted Network," causing it to apply the wrong forwarding profile settings.
Default Route Detection:
.
Zscaler Client Connector looks for a default route in the routing table to identify a VPN connection. If the Deco's VPN doesn't set a default route (or uses a different mechanism to capture traffic), Zscaler might not recognize it as a VPN.
Troubleshooting Steps:
- Update Zscaler Client Connector:
Ensure the Zscaler Client Connector is up to date.
- Set Deco to Access Point Mode:
Temporarily switching the Deco to Access Point mode can help isolate the issue and determine if it's related to the Deco's routing functionality.
- Configure Zscaler for Local Proxy:
If using Tunnel mode, consider switching to Tunnel with Local Proxy or Tunnel (Packet Filter Based) in the Zscaler Client Connector portal, according to Zscaler.
- Check VPN Settings:
Ensure the Deco's VPN settings are correctly configured and that it's properly handling traffic routing.
- Consider Bypasses:
If using a specific VPN for internal resources, you can configure Zscaler to bypass that VPN connection using network bypasses in the Zscaler Client Connector Portal app profile, says Zscaler.
- Copy Link
- Report Inappropriate Content
@DavidCA For XE75 Pro, for whatever reason, V2 latest firmware is not the same as V2.60 latest firmware. I guess make sure you have the appropriate latest firmware for the specific model you have...
- Copy Link
- Report Inappropriate Content

Hi, welcome to the community.
There is a beta firmware that might help with the report issue. If you're interested, you can find it in the Message box.
It could revert to the official 1.2.14 directly via web UI.
Wait for your reply.
Best regards.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@David-TP Thanks, I am going to install the beta firmware soon and will let you know if it worked.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 179
Replies: 7
Voters 0
No one has voted for it yet.