field notes
Troubleshooting write-ups across SSE, networking, and firewalls — for problems that have plenty of search results and no actual answers. Symptom, cause, fix — with the dead ends included, because knowing what it isn't is half the diagnosis.
ZPA App Connector sizing: there is no users-per-connector number
Zscaler sizes App Connectors by throughput and utilization, never by user count. Every number they publish — 500 Mbps, the double-encryption table, N+1 — and what to do when all you have is a headcount.
Why your on-net detection flaps during network transitions
Zscaler Client Connector decides trusted vs. untrusted using seven criteria. The one most people configure first is the one the docs single out as dynamic — and a failed resolution during a network transition applies the wrong forwarding profile action. Plus the four trust categories, because VPN gets its own.
I tried to break my own PAC tester
A 26-character glob pattern froze my own tool for 35 seconds, and neither the step budget nor the size cap could see it. A security audit of a client-side tool: what held, what didn't, and why "runs in your browser" is a privacy claim rather than a safety one.
Watching your PAC file decide
Two users on the same policy couldn't reach a site. Proxy logs, lsof, tcpdump and DevTools all showed what happened after the routing decision — none of them showed the decision. How to capture a NetLog, read it, and make a PAC file narrate its own branches.
Why your PAC file's URL rules stopped working for HTTPS
Modern browsers strip the path and query from https:// URLs before your PAC file ever runs — any rule matching on the URL path is silently dead. What changed, why it was the right call, how to check your file, and what to do instead.
Writing your first PAC file: a practical cookbook
The constructive companion to the mistakes post: what each piece of a PAC file does, when to route DIRECT vs. proxy vs. cloud edge vs. local agent, OR-logic, geo-aware routing, and a full annotated example — with vendor best practices cited.
PAC file mistakes that break user traffic (and how to spot them)
A PAC file that parses cleanly can still route half your traffic somewhere you never intended. The mistakes that cause real production pain — wrong buckets, shadowed rules, copy-pasted catch-alls — and the order to debug them in.
get new field notes by email
Occasional, technical, no fluff.
ack — check your inbox for a confirmation link.
One confirmation email, then you're in. Unsubscribe anytime.