## TL;DR
Tunnel connection failed in Zscaler Client Connector usually means the client cannot reach the Zscaler cloud: a local firewall or proxy blocking it, stale client state, or a policy problem. Check the Zscaler service status first, then the local network path, then reinstall or re-enroll the client.

## The query
```text
zscaler client connector "tunnel connection failed" fix
```

## Use this when
- Zscaler Client Connector shows tunnel connection failed
- tunnel fails on one network but works on another
- tunnel broke right after a client update

## Not for
- Zscaler login or SSO failures (different error)
-  PAC file or explicit proxy config issues (check proxy settings)
- app-specific access denials after the tunnel is up

## Steps
1. Check the Zscaler service status page for an ongoing incident in the user's region. Expected output: no active incident, or a known incident you can cite
2. Confirm the machine has working internet without Zscaler, then check that required Zscaler ports and hosts are reachable. Expected output: general connectivity works and Zscaler endpoints respond
3. Restart the Zscaler Client Connector service or app and retry. Expected output: the tunnel establishes on a clean start
4. Check the client's About page for the version and compare with your deployed version; update if it is behind. Expected output: client on the supported version
5. If it still fails, uninstall and reinstall the client, then re-enroll the device. Expected output: fresh enrollment and a working tunnel
6. Collect the client logs before escalating to Zscaler support. Expected output: a log bundle attached to the support case

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_z-30DwO6IWNsHVquzdUPDQ
