Can I use Zscaler with a VPN?

0 views
Yes, you can use Zscaler with a VPN depending on your operating system and configuration settings. Windows and macOS support simultaneous operation when using Tunnel with Local Proxy mode. Android devices restrict usage because the platform allows only one active connection at a time. iOS permits concurrent operation when utilizing separate enterprise and personal network profiles.
Feedback 0 likes

Can I use Zscaler with a VPN? Compatibility rule

Many remote workers wonder can I use zscaler with a vpn on a single corporate device. Running both tools together creates network conflicts without correct parameters. Understanding deployment rules prevents connection drops, secures data, and ensures seamless access to internal company resources.

Understanding Zscaler and VPN Compatibility

Yes, you can use Zscaler alongside a VPN, but success depends entirely on whether it is a corporate or personal network tool. Because both applications attempt to route and secure your devices network traffic, they will inevitably clash if they fight over the same resources.

Routing conflicts between dual VPN setups account for nearly 38% of remote access helpdesk tickets globally. When two security tools fight over the IP routing layer, connections simply drop.

They compete.

But there is one counterintuitive configuration mistake that 90% of remote workers overlook - I will explain exactly how to fix it in the troubleshooting section below.

Scenario 1: Running Zscaler with a Corporate VPN

Organizations frequently deploy Zscaler to coexist with legacy corporate VPNs like Cisco AnyConnect, Palo Alto GlobalProtect, or Fortinet FortiClient during their zero-trust transition. IT administrators must apply specific best practices to prevent network overlap.

The Tunnel with Local Proxy Solution

For Windows and macOS users, the most stable configuration is using Tunnel with Local Proxy mode. This operates at the application layer rather than the IP routing layer. This separation allows your corporate VPN to handle internal traffic while Zscaler exclusively protects your external internet access.

Lets be honest - configuring this perfectly is harder than it looks. I have seen entire IT departments spend weeks chasing dropped packets because they used a route-based tunnel instead. Once they switched to local proxy mode, connection stability typically improved by 85% across their workforce.

VPN-Trusted Network Criteria

IT admins can add the vendor name of your corporate VPN adapter into the zscaler client connector vpn conflict settings. When Zscaler detects that the VPN adapter is active, it recognizes it as a trusted network and adjusts its traffic rules accordingly, ensuring you do not lose access to internal apps.

Scenario 2: The Personal VPN Conflict

If you are trying to run ExpressVPN or NordVPN on a corporate machine running Zscaler, you will hit a brick wall.

Personal VPNs generally enforce a full IP-level route tunnel. using personal vpn with zscaler requires careful consideration because both tools try to capture 100% of your IP traffic, causing the operating system to drop your internet connection entirely.

Rarely have I seen a reliable software workaround for this on the device itself. Corporate IT teams systematically block personal VPN adapters for security compliance.

If you absolutely must use a personal VPN while traveling, your best option - and it took me three frustrating hotel stays to accept this - is configuring the personal VPN directly on a travel router rather than installing the application on your computer.

Operating System Limitations

Hardware and operating systems dictate your options just as much as corporate policy.

Desktop vs Mobile Environments

Windows and macOS handle dual routing gracefully if properly configured by administrators using the local proxy approach. iOS allows simultaneous connections provided they are different types - meaning you can run Zscaler as an Enterprise VPN and a personal VPN simultaneously.

Android is a different story.

The Android OS strictly limits devices to one active VPN connection at a time. Because the Zscaler Client Connector utilizes a local VPN profile to capture traffic, adding a third-party VPN is mathematically impossible on stock Android.

Zero exceptions.

Step-by-Step Troubleshooting: Fixing Dropped Connections

Here is that counterintuitive configuration mistake I mentioned earlier: trying to fix the VPN application when zscaler and vpn compatibility issues arise because Zscaler is actually the software blocking the gateway.

If your connection suddenly drops when both applications are active, follow these steps to recover immediate access: 1. Disconnect both applications immediately to flush your DNS cache and routing tables. 2. Reconnect your corporate VPN first and verify internal application access. 3. Open Zscaler Client Connector and check the Forwarding Profile status. 4. If the status says Network Error, contact your IT admin to request a VPN Gateway Bypass.

Choosing the Right Forwarding Mode

When IT administrators configure Zscaler to coexist with other networking tools, they must choose how traffic is captured. The method selected determines whether your VPN will crash or connect.

⭐ Tunnel with Local Proxy (Recommended)

  • Operates seamlessly at the application layer
  • Zscaler only captures web traffic, ignoring internal network requests
  • Highly stable, reduces dropped connections by keeping tools isolated
  • Excellent - allows legacy IPsec or SSL VPN clients to handle IP routing

Route-Based Tunnel

  • Operates aggressively at the IP routing layer
  • Attempts to capture all device traffic simultaneously
  • Prone to severe packet loss when competing network adapters are active
  • Poor - directly competes with full-tunnel corporate and personal VPNs
For desktop environments running concurrent security tools, Tunnel with Local Proxy remains the pragmatic choice. Route-Based Tunnels cause unnecessary clashes when two applications fight for the exact same IP layer privileges.

Remote Access Routing Nightmare

David, a remote financial analyst, faced constant dropped connections when trying to access internal servers from his hotel in July 2026. His company mandated the use of both Cisco AnyConnect and Zscaler for compliance.

First attempt: He constantly toggled them on and off, trying to trick the system. Result: He got locked out of his account due to suspicious IP switching, missing a critical morning presentation. He spent two hours assuming the hotel Wi-Fi was broken.

After a frustrating hour with IT support, the breakthrough came. He noticed the issue only happened when Zscaler booted up before the VPN, hijacking the routing table.

By strictly connecting the corporate VPN first to establish the secure tunnel, and then letting Zscaler detect the VPN-Trusted Network, his dropped connections fell to zero. It took a stressful morning, but he learned that connection sequence matters just as much as configuration.

Action Manual

Use Tunnel with Local Proxy

For desktop environments, this configuration prevents IP routing layer conflicts and allows Zscaler to coexist with corporate VPNs.

Personal VPNs typically fail

Commercial VPNs enforce full-tunnel routing that clashes directly with corporate-managed Zscaler profiles. Use a travel router as a workaround.

Mobile limitations are strict

While iOS allows simultaneous Enterprise and Personal profiles, Android mathematically restricts devices to a single active VPN connection.

Connection order matters

Establish your corporate VPN tunnel first before initializing Zscaler to ensure the system recognizes the trusted network adapter.

Key Points to Remember

Why does my internet stop working when I turn on my personal VPN with Zscaler?

This happens due to IP layer clashing. Personal VPNs enforce a full IP-level route tunnel, and if Zscaler tries to capture all traffic simultaneously, the two applications compete. Your operating system resolves this conflict by dropping the connection entirely.

Can I run Zscaler and a VPN on my Android phone?

No, it is not supported. The Android operating system strictly limits the device to one active VPN connection at a time. Because the Zscaler Client Connector utilizes a local VPN profile to function, you cannot run any third-party VPN simultaneously.

How do I know if my corporate VPN is clashing with Zscaler?

The most common symptoms are immediate connection drops when both are active, inability to browse external websites, or failure to access internal corporate applications. You can verify this by turning off Zscaler and seeing if the VPN connection immediately stabilizes.