Zscaler & Zero Trust operations glossary ยท Products & platform

What is a Branch Connector?

Definition

A Branch Connector is a Zscaler component that connects the traffic of devices at a site to the Zscaler cloud, the Zero Trust Exchange. It routes traffic to the cloud for inspection and policy enforcement, including for devices that cannot carry a Client Connector, such as printers, IoT and OT systems, or servers. According to Zscaler, it scales from a small branch office up to a large campus and data centre. As part of the Zero Trust Branch approach, it connects an entire site directly to the cloud instead of routing traffic through central data centres. That extends Zero Trust protection to places a pure client approach cannot reach.

Branch Connector in detail

Not every device can carry software. Printers, cameras, sensors, machine controllers, and many servers cannot be fitted with a Client Connector, yet they still need a controlled path onto the network and the internet. That is exactly the gap the Branch Connector closes: it sits at the site and carries the traffic of the devices behind it to the Zero Trust Exchange, where policies apply and traffic gets inspected.

It differs from the Client Connector in the level at which it works. The Client Connector operates on the individual endpoint, the Branch Connector at site level. In the Zero Trust Branch approach, it provides the direct, inspected connection of a site to the cloud and so reduces the dependence on the classic detour through a central data centre. That makes it a component in its own right in operations, one that, like any component, needs placement, capacity, and monitoring.

Why the Branch Connector matters in Zscaler operations

The Branch Connector extends the reach of Zero Trust into areas a client alone cannot cover. In branch offices, production environments, and sites with many clientless devices, it becomes the gateway to the cloud. For operations, that cuts two ways: protection gets broader, but there is now another component whose health and load need watching. For site connectivity, the approach often replaces cumbersome workarounds with a direct, inspected connection.

That puts the Branch Connector into the troubleshooting chain. If a user at a connected site reports a problem, the cause can lie with the device, the local network, a policy, the path through the Branch Connector, or the cloud. Whoever works through this chain in order, rather than jumping to blame a single component, finds the cause faster. In everyday work, that orderly approach is exactly the difference between a guess and a finding.

Common sources of error

Branch Connector in practice: how CentaurNexus puts it in context

CentaurNexus is an operations cockpit that looks at the tenant through the official Zscaler OneAPI, regardless of how a site connects, whether through the Client Connector on the endpoint or through the Branch Connector at the site. If a user at a connected site reports a problem, Connectivity Triage Map helps place the cause in plain language: device, network, policy, or Zscaler. That keeps initial diagnosis structured even across mixed sites, instead of ending in guesswork. The article below shows how the question of cause gets answered in minutes: Is it Zscaler or the Wi-Fi?.

See in the live demo how user problems get classified in a structured way, regardless of how the site connects.Watch the live demo

Related terms

Frequently asked questions about the Branch Connector

What is a Branch Connector?

A Branch Connector is a Zscaler component that connects the traffic of devices at a site to the Zscaler cloud, the Zero Trust Exchange. It routes traffic to the cloud for inspection and policy enforcement, including for devices that cannot carry a client. According to Zscaler, it can be deployed from a small branch office up to a data centre.

What is the difference between Branch Connector and Client Connector?

The Zscaler Client Connector runs as software on a single endpoint and routes its traffic to the cloud. The Branch Connector sits at the site and covers the traffic of the devices behind it, without installing software on each one. Both bring traffic to the Zero Trust Exchange, but they work at different levels.

Which devices benefit from the Branch Connector?

Mainly devices that cannot carry a client: printers, cameras, IoT and OT systems, servers, and specialised hardware. For these, the Branch Connector creates a path into the Zero Trust Exchange without installing anything on the device itself. That extends protection to areas a pure client approach cannot reach.

What is Zero Trust Branch?

Zero Trust Branch is the approach of connecting an entire site directly and securely to the Zscaler cloud, instead of routing traffic through central data centres. The Branch Connector is the component that implements it. The goal is simpler site connectivity with direct, inspected cloud access instead of cumbersome workarounds.

Does the Branch Connector replace classic site links?

It enables a direct, inspected connection of a site to the cloud, reducing dependence on the detour through a central data centre. Whether it replaces existing links depends on the particular network design. In many Zero Trust Branch designs, it takes on the role that used to belong to costly site-to-site links.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.