Edge is not forming tunnels to closer Zscaler POPs deployed later.
search cancel

Edge is not forming tunnels to closer Zscaler POPs deployed later.

book

Article ID: 383266

calendar_today

Updated On:

Products

VMware VeloCloud SD-WAN

Issue/Introduction

Once the edge has formed tunnels to existing Zscaler POPs, edge does not recalculate and establish tunnels to Zscaler POPs which are deployed/provisioned later by Zscaler.

Resolution

  • This is an expected behavior.
  • Once the edge forms the tunnel to existing POPs, it won't automatically choose and form tunnels to to any other closer POP which is deployed afterwards by Zscaler.
  • Reboot of the edge might also not help in this case.
  • Removing and adding back the CSS profile on edge should do the job here. 

Sample example-

  • Assume edge device is located in Perth, Australia.
  • A CSS profile is attached to edge and edge forms tunnel to Canberra and Melbourne POP for example.
  • Zscaler brings up another POP in perth later.
  • Edge won't recalculate anything and it wont choose/form tunnels to Perth POP.
  • We have to remove and add back the CSS config on edge to let the edge form tunnels to nearest Zscaler POPs.