zscaler client connector stuck on "connecting"
Fixes Zscaler Client Connector hanging at connecting. Covers service status, trusted network detection, and app profile issues. Use when the connector never establishes the tunnel. Not for policy-blocked websites after connection.
TL;DR
Check the Zscaler service status page first, then verify the device is enrolled and the app profile is assigned. If the connector spins on "connecting" with no error, restart the Zscaler service and check for conflicting VPN clients or firewall software.
The error
Connecting... (spins indefinitely, never reaches "Connected")Steps
- Check the Zscaler status page and the admin's cloud status. Expected: no ongoing incident. Do not troubleshoot a cloud outage as a client problem.
- In the client, open More > About and confirm enrollment: the device should show as enrolled to the right cloud. Expected: enrolled. Unenrolled devices spin forever.
- Check for conflicting software: any other VPN client, or third-party firewall, running at the same time. Expected: none active. Two tunnel drivers fight each other.
- Restart the service: Windows services > "Zscaler Tunnel" > restart, or reboot the machine. Expected: connector proceeds past connecting within a minute.
- In the ZIA admin portal, confirm the user's app profile and that their location is not excluded in a way that breaks enrollment. Expected: profile assigned. Collect client logs (More > Diagnostics) before escalating.
When to use
- Client Connector never leaves "connecting"
- Fresh installs that never connected
When not to use
- Connected but specific sites blocked (policy issue)
- Slow performance on an established tunnel
Compatibility
- Zscaler Client Connector 3.x/4.x; ZIA/ZPA tenants
Variants
Connects then immediately disconnects
Usually a policy or authentication failure, not a connectivity failure. Check the admin's client logs.
"Authentication failed" during connecting
The device or user auth is rejected; check IdP integration and enrollment.
Why it happens
"Connecting" covers enrollment validation, tunnel setup, and policy download. A failure at any stage with no clear error surfaces as an endless spinner, so the checklist eliminates the stages in order.
Edge cases
- Trusted network detection misconfigured: the client may try to bypass Zscaler on networks it thinks are corporate.
- macOS upgrades: the system extension approval may need re-granting after major OS updates.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstlnE-HT2MvBRYup0tRQ0eg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.