What is a Branch Connector?
A Branch Connector is a Zscaler component that connects the traffic of devices at a site to the Zscaler cloud, the Zero Trust Exchange. It routes traffic to the cloud for inspection and policy enforcement, including for devices that cannot carry a Client Connector, such as printers, IoT and OT systems, or servers. According to Zscaler, it scales from a small branch office up to a large campus and data centre. As part of the Zero Trust Branch approach, it connects an entire site directly to the cloud instead of routing traffic through central data centres. That extends Zero Trust protection to places a pure client approach cannot reach.
Branch Connector in detail
Not every device can carry software. Printers, cameras, sensors, machine controllers, and many servers cannot be fitted with a Client Connector, yet they still need a controlled path onto the network and the internet. That is exactly the gap the Branch Connector closes: it sits at the site and carries the traffic of the devices behind it to the Zero Trust Exchange, where policies apply and traffic gets inspected.
It differs from the Client Connector in the level at which it works. The Client Connector operates on the individual endpoint, the Branch Connector at site level. In the Zero Trust Branch approach, it provides the direct, inspected connection of a site to the cloud and so reduces the dependence on the classic detour through a central data centre. That makes it a component in its own right in operations, one that, like any component, needs placement, capacity, and monitoring.
Why the Branch Connector matters in Zscaler operations
The Branch Connector extends the reach of Zero Trust into areas a client alone cannot cover. In branch offices, production environments, and sites with many clientless devices, it becomes the gateway to the cloud. For operations, that cuts two ways: protection gets broader, but there is now another component whose health and load need watching. For site connectivity, the approach often replaces cumbersome workarounds with a direct, inspected connection.
That puts the Branch Connector into the troubleshooting chain. If a user at a connected site reports a problem, the cause can lie with the device, the local network, a policy, the path through the Branch Connector, or the cloud. Whoever works through this chain in order, rather than jumping to blame a single component, finds the cause faster. In everyday work, that orderly approach is exactly the difference between a guess and a finding.
Common sources of error
- Assuming a client for every device: the Branch Connector covers clientless devices at the site, not a client installed on every endpoint.
- Overlooking the Branch Connector in the troubleshooting chain: the path through the site is one of the causes to check, not just the device and the cloud.
- Confusing the Branch Connector with the Client Connector: site level and endpoint level are two different things.
- Capacity and placement left unplanned: a site's size and load belong in the design stage early on, not only once it is already in operation.
Branch Connector in practice: how CentaurNexus puts it in context
CentaurNexus is an operations cockpit that looks at the tenant through the official Zscaler OneAPI, regardless of how a site connects, whether through the Client Connector on the endpoint or through the Branch Connector at the site. If a user at a connected site reports a problem, Connectivity Triage Map helps place the cause in plain language: device, network, policy, or Zscaler. That keeps initial diagnosis structured even across mixed sites, instead of ending in guesswork. The article below shows how the question of cause gets answered in minutes: Is it Zscaler or the Wi-Fi?.
Related terms
Frequently asked questions about the Branch Connector
A Branch Connector is a Zscaler component that connects the traffic of devices at a site to the Zscaler cloud, the Zero Trust Exchange. It routes traffic to the cloud for inspection and policy enforcement, including for devices that cannot carry a client. According to Zscaler, it can be deployed from a small branch office up to a data centre.
The Zscaler Client Connector runs as software on a single endpoint and routes its traffic to the cloud. The Branch Connector sits at the site and covers the traffic of the devices behind it, without installing software on each one. Both bring traffic to the Zero Trust Exchange, but they work at different levels.
Mainly devices that cannot carry a client: printers, cameras, IoT and OT systems, servers, and specialised hardware. For these, the Branch Connector creates a path into the Zero Trust Exchange without installing anything on the device itself. That extends protection to areas a pure client approach cannot reach.
Zero Trust Branch is the approach of connecting an entire site directly and securely to the Zscaler cloud, instead of routing traffic through central data centres. The Branch Connector is the component that implements it. The goal is simpler site connectivity with direct, inspected cloud access instead of cumbersome workarounds.
It enables a direct, inspected connection of a site to the cloud, reducing dependence on the detour through a central data centre. Whether it replaces existing links depends on the particular network design. In many Zero Trust Branch designs, it takes on the role that used to belong to costly site-to-site links.
- Zscaler Help Portal: Zscaler Cloud & Branch Connector - help.zscaler.com
- Zscaler Help Portal: Step-by-Step Configuration Guide for Zero Trust Branch - help.zscaler.com
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.