-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Apps, Services & Software
- ZCentral
- HP RGS - Using UDP with Zscaler Private Access ZPA

Create an account on the HP Community to personalize your profile and ask a question
08-07-2024 12:55 AM
We have a user that is running HP RGS over Zscaler's ZTNA product (Zscaler Private Access), where only client-to-server initiated connection is allowed. After moving from an older VPN to Zscaler, we noticed that performance is not as good, and that only TCP packets are being used, and UDP packets don't seem to be flowing anymore.
Is HP RGS 7.7 compatible with client->server only Zscaler? or does it require some server-to-client traffic?
08-14-2024 04:16 PM
If you are using HP Velocity, which is enabled by default in the Receiver GUI settings under the performance tab, then traffic will switch from TCP to UDP. Remote Boost/RGS uses port 42966 for communicating between sender and receiver. You would need to make sure that UDP traffic is allowed through both inbound and outbound. I have helped customers out that were using RGS and ZScaler a long time ago, and there were definitely some timing issues when the connection was first initiated. Have you tried turning off HP Velocity on the receiver and then making a connection? Is the performance any better? The last release of RGS for 7.7 was 7.7.2.
Not sure how much I can help you with ZScaler settings since I use GlobalProtect for my VPN. You could try raising a case with ZScaler to see if they have any recommendations for tuning performance. I found an old document called Optimizing Performance with RGS 7.1 and have attached it here. There has been a lot of changes since RGS 7.
08-15-2024 01:55 AM
Thank you @KellyRGS for that advice.
I will try to test the options of HP Velocity. Other than "Optimizing Performance", do you have some detail flow documentation of how UDP will be setup? or how to force RGS to always use TCP?
As for Zscaler, we will also try to raise a case with them, and for that we will need to fully understand how HPRGS should be working.
Thanks.
08-16-2024 11:30 AM
By unchecking HP Velocity, you will only be using TCP. When HP Velocity is enabled, the initial handshake is TCP, but then changes to UDP. Some people find the experience better with out HP Velocity enabled. There are also things you can do to tweak your performance experience with Remote Boost. I have attached the Configuration Guide which covers the most commonly asked things on Remote Boost.
Traffic on 42966 has to go both ways and the receiver is communicating with the sender, and the sender then communicating to the receiver. We do not send data, that stays local on the sender, we only send pixels. All communication is encrypted. We usually recommend whitelisting Remote Boost so that it does not get its service shutdown by anti-virus, malware or intrusion detection software, etc.