* * deny — ~/field-guide

the field guide

A troubleshooting field guide for SSE administrators — starting with Zscaler's stack (ZIA, ZPA, ZDX, ZCC) — organized by symptom, not by product menu. When something breaks, you open this, find the symptom, and follow the diagnostic path someone has already walked.

what it will cover

The problems that generate tickets, escalations, and 2 a.m. bridge calls: authentication that fails for some users and not others, traffic that takes the wrong path, tunnels that won't build, policies that don't match when they obviously should, and the client-side states that explain all of the above.

Every entry follows the same structure: symptom → what it usually is → how to confirm → how to fix → how to keep it from happening again. Written by a practitioner who runs this stack in a large production environment, independent of any vendor.