Esper Remote Viewer blocked by Zscaler — configure ZIA to allow Esper traffic
Android
When Zscaler Internet Access (ZIA) is active on your corporate network, Esper Remote Viewer sessions fail to connect or time out immediately after launch.
Why this happens
Zscaler ZIA inspects and filters all outbound traffic, including the WebSocket and WebRTC connections that Esper Remote Viewer relies on. When Esper's service endpoints are not explicitly permitted in your ZIA policy, Zscaler blocks or intercepts these connections before they reach Esper's infrastructure. Disabling or bypassing Zscaler confirms the connection succeeds, which isolates ZIA as the cause.
Before you start
Confirm ZIA is the cause before involving your network team:
- Attempt a Remote Viewer session on your corporate network with Zscaler active — the session fails or hangs.
- Attempt the same session with Zscaler bypassed or disabled — the session connects successfully.
If both tests fail, the issue is not Zscaler-related. Contact Esper Support for further diagnosis.
Step 1: Obtain the Esper endpoint list for your region
- Contact Esper Support and request the complete list of IP addresses, IP ranges, and domain names required by Remote Viewer for your specific tenant and region. The endpoint list varies by region, so confirm your tenant's region when you request it.
- Save the list provided by Esper Support — you will share it with your Zscaler administrator in the steps below.
Step 2: Choose the correct ZIA configuration method
Work with your Zscaler administrator to apply one or both of the following options, depending on how your ZIA policy is configured.
Option A — Add Esper endpoints to the ZIA firewall allowlist
Use this option if ZIA is blocking outbound connections to Esper's IP ranges or domains at the firewall level.
- Share the Esper endpoint list (IPs, IP ranges, and domains) with your Zscaler administrator.
- Ask your Zscaler administrator to add these entries to the allowlist by navigating to ZIA Admin Console → Policy → Firewall → IP Allowlist / Destination Groups.
- Allow up to 15 minutes for the policy change to propagate across your network before testing.
Option B — Bypass SSL inspection for Esper domains
Use this option if ZIA's SSL inspection is breaking the WebSocket or WebRTC connections Remote Viewer uses, even when the firewall allowlist is in place.
- Share the Esper domain names from the endpoint list with your Zscaler administrator.
- Ask your Zscaler administrator to add Esper's domains to the SSL inspection bypass list by navigating to ZIA Admin Console → Policy → SSL Inspection → Bypass Rules.
- Allow up to 15 minutes for the policy change to propagate before testing.
Step 3: Test the Remote Viewer connection
- Open the Esper Console and navigate to Devices & Groups.
- Select the affected device and open the Remote Viewer tab.
- Start a Remote Viewer session while Zscaler is active on your network.
If this doesn't resolve it
If Remote Viewer sessions still fail after your Zscaler administrator has applied the allowlist and bypass rules:
- Ask your Zscaler administrator to capture a Zscaler traffic log or HAR file during a failed Remote Viewer attempt, showing which specific destination is being blocked and the reason code.
- Note the exact error behavior in the Esper Console — whether the session times out, shows a connection error, or fails silently.
- Contact Esper Support and include:
- The Esper endpoint list you were provided in Step 1
- The Zscaler traffic log or HAR file showing the blocked destinations
- The ZIA policy changes your administrator applied
- Your tenant name and region
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments