Esper Remote Access Blocked by Zscaler: Whitelist Zscaler IP Ranges in Your Network/ZIA Policy
Android
Title: Esper Remote Viewer blocked by Zscaler — configure ZIA to allow Esper trafficWhen Zscaler Internet Access (ZIA) is active on your corporate network, Esper Remote Viewer sessions fail to connect or time out immediately after launch.
Why this happens
Zscaler ZIA intercepts outbound traffic and, by default, blocks or performs SSL inspection on connections it does not recognise. Esper Remote Viewer relies on WebSocket and WebRTC connections to specific Esper service endpoints. When ZIA has no rule permitting those destinations, it silently drops or breaks the connection before the session can establish.
Before you begin
Confirm ZIA is the cause before changing any Zscaler policy:
- Attempt a Remote Viewer session on your corporate network with ZIA active — the session fails or hangs.
- Attempt the same session with ZIA bypassed or disabled — the session connects successfully.
If both conditions are true, follow the steps below. You will need your Zscaler administrator to apply the policy changes.
Option A: Add Esper endpoints to the ZIA allowlist
- Contact Esper Support and request the complete list of Remote Viewer service IPs, IP ranges, and domain names for your tenant and region. Esper's endpoints vary by region, so the list must be confirmed for your specific tenant before your administrator adds anything to ZIA.
- Share the confirmed endpoint list with your Zscaler administrator.
- In the ZIA Admin Console, navigate to Policy → Firewall → IP Allowlist / Destination Groups and add each Esper IP range and domain from the confirmed list.
- Save and publish the policy change, then wait for propagation across your network (typically 5–10 minutes).
- Open the Esper Console, go to Devices & Groups → [Device Name] → Remote Viewer, and start a session while ZIA is active.
Option B: Configure a ZIA SSL Inspection bypass for Esper domains
Use this option if the allowlist alone does not resolve the issue, or if your Zscaler environment performs deep SSL inspection. SSL inspection re-signs TLS certificates, which breaks the authenticated WebSocket connections Remote Viewer requires.
- Contact Esper Support and request the list of Esper domain names used by Remote Viewer for your region.
- Share the domain list with your Zscaler administrator.
- In the ZIA Admin Console, navigate to Policy → SSL Inspection → Bypass Rules and add each Esper domain as a bypass entry.
- Save and publish the policy change, then wait for propagation (typically 5–10 minutes).
- Open the Esper Console, go to Devices & Groups → [Device Name] → Remote Viewer, and start a session while ZIA is active.
If this doesn't resolve it
If Remote Viewer sessions still fail after your Zscaler administrator has applied allowlist rules, SSL inspection bypass rules, or both:
- Ask your Zscaler administrator to capture a ZIA traffic log or HAR file that shows which specific destination is being blocked or flagged during a failed Remote Viewer attempt.
- Note the exact error or behaviour visible in the Esper Console during the failed session.
- Contact Esper Support with the following:
- The Esper endpoint list you were provided
- The ZIA traffic log or HAR file showing the blocked destination
- Your Esper tenant name and region
- A description of which option (A, B, or both) your administrator applied
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments