Zscaler & Zero Trust operations glossary · Access & traffic

What is a forwarding profile?

Definition

A forwarding profile is a configuration unit in Zscaler Client Connector that determines whether and how a device’s traffic is forwarded to the Zscaler cloud. It sets the path, for example via tunnel, via a PAC file, or not at all, and is assigned depending on the device’s detected network location: the corporate network often has a different rule than working from home or on the road. The profile is therefore the switch that decides whether and how a device gets inspected by the Zero Trust Exchange at all, before requests go out to the internet or to internal applications.

Forwarding profile in detail

Client Connector works from a list of Trusted Networks, which administrators define in advance within the tenant, using criteria such as reachable internal systems or DNS responses, and map to one or more forwarding profiles. When one of these stored criteria matches, the client assigns the associated forwarding profile, for example tunnelling via Z-Tunnel, proxy-based forwarding through a PAC file, or no forwarding at all for purely internal, trusted networks. Profiles can also be configured differently per user group or device type.

Why the forwarding profile matters in Zscaler operations

A wrongly assigned forwarding profile is one of the most common causes of helpdesk tickets: pages fail to load, internal applications are unreachable, or policies seem to have no effect. Without visibility into a device’s currently active profile, it is hard to tell whether a problem sits with the network, the client, or the Zscaler cloud. For support, the profile is therefore one of the first questions for any traffic issue. How a user’s active forwarding behaviour becomes visible directly in a support context is shown in our video on the support cockpit.

Common sources of error

Forwarding profile in practice: what CentaurNexus contributes

In Connectivity Triage Map, CentaurNexus brings together the ZDX chain and the current policy status, and attributes anomalies to the network, the device or the Zscaler side, without the helpdesk needing Zscaler admin rights of its own. That makes it faster to establish whether a reported problem is related to the active forwarding profile. The guide Is it Zscaler or the Wi-Fi? Root cause analysis in minutes walks through the approach in detail.

See in the live demo how Connectivity Triage Map separates forwarding and network problems.Watch the live demo

Related terms

Frequently asked questions about the forwarding profile

What is a forwarding profile in Zscaler?

A forwarding profile is a rule in Zscaler Client Connector that determines how a device’s traffic reaches the Zscaler cloud, for example via tunnel, PAC file, or not at all. Which profile applies depends on the detected network location: the corporate network often has a different rule than café Wi-Fi on the road.

How does Zscaler recognise which forwarding profile applies?

Client Connector checks characteristics of the current network, such as reachable internal servers or DNS responses, against a list of trusted networks. When there is a match, the profile stored for it applies. The details of this detection logic depend on the Zscaler configuration in the tenant.

Why the forwarding profile matters in Zscaler operations

A wrongly assigned profile is one of the most common causes of support tickets: pages fail to load, VPN and Zscaler collide, or policies seem to have no effect. Without visibility into the active profile, troubleshooting stays a guessing game between the network, the client and the cloud side.

What is the difference between a forwarding profile and a PAC file?

A PAC file is one possible tool within a forwarding profile, determining the right proxy for individual requests. The forwarding profile is the higher-level rule that decides in the first place whether traffic is tunnelled, forwarded via PAC, or accessed directly.

Does a wrong forwarding profile also affect security?

Yes. If a profile without Zscaler forwarding applies by mistake, traffic passes the Zero Trust Exchange uninspected. That matters particularly for mobile devices outside the corporate network, and should be tightly controlled in the configuration.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.