New Features and Enhancements The following enhancements were added as part of the Zero Trust Branch 8.1.2 release: DTLS-Based Internet & SaaS Connectivity Support and Location Enhancements Added support for DTLS-based connectivity to Internet & SaaS, enabling secure, higher-throughput tunnels with automatic fallback to TLS when DTLS is unavailable. This update aligns new Zero Trust Branch deployments with Zero Trust Branch groups and sublocations to simplify branch onboarding while providing greater flexibility for transport options. For existing sites, you can create a new location that supports Zscaler Tunnel (Z-Tunnel) and associate it with the site. You can enable Zscaler Tunnel (Z-Tunnel) for a site on the Connectivity tab. See image. Use DTLS tunnels in Traffic Forwarding policy rules that are currently configured to use IPSec tunnels. The following location enhancements were added: Support for location templates while adding new sites. This applies only for new deployments. Existing sites and appliances cannot be switched to new location types without full redeployment. See image. Beginning with version 8.1.2, the new locations created for Zero Trust Branch sites would create corresponding Internet & SaaS locations with VPN credentials with the Workload type. For these sites, you can switch from IPSec tunnel to Zscaler Tunnel (Z-Tunnel). Custom Internet & SaaS (ZIA) Gateway Objects Support You can define custom ZIA Gateway objects to steer traffic to specific gateways for policy enforcement, performance, routing, regional compliance requirements, configure primary and secondary gateways with failover for resiliency, and pin sites to a gateway for troubleshooting. See image. Support for Hub Deployment in Microsoft Azure and Amazon Web Services (AWS) Added support for deploying a hub in AWS and Azure, with downloadable ISO, Virtual Hard Disk (VHD), and Open Virtual Appliance (OVA) images, helping standardize and accelerate cloud-based deployments while reducing manual setup. For AWS, you must download the OVA image and convert it to Amazon Machine Image (AMI) using the AWS CLI. You can access these images from Service Portal > Zero Trust Branch > Settings > ZTB Images. Support for China Deployments Added support for China deployments in Zero Trust Branch, enabling consistent Zero Trust connectivity for branches in China, including support for bootstrap, provisioning, and back-end communications, custom Internet & SaaS (ZIA) gateway selection, connectivity to China public Internet & SaaS and Private Access data centers, and support for partner-hosted Private Access brokers. Support for Internet Group Management Protocol (IGMP) Querier Added support for the IGMP Querier on Layer 2 VLANs, enabling the Zero Trust Branch appliance to periodically transmit IGMP Query messages and maintain multicast group membership for more reliable multicast traffic across VLANs. See image. The IGMP Querier supports IGMPv2 and IGMPv3. Ensure that the appropriate version is configured for your environment. Private Access (ZPA) Log Level Configuration Added support for configuring ZPA log levels on Zero Trust Branch appliances. See image. ZPA Logs must be enabled only for active appliances. Management Interface Enhancement Added support for both in-band and out-of-band management interfaces in Zero Trust Branch to provide stronger management-plane isolation. Admins can configure management access using a loopback interface within the main routing domain or a dedicated physical interface in a separate management Virtual Routing and Forwarding (VRF) instance for isolated access. See image. Support for Link Layer Discovery Protocol (LLDP) Added support for LLDP on Zero Trust Branch interfaces to discover neighboring devices and display device information, including device identity, port descriptions, OS versions, and management IP addresses, helping simplify troubleshooting and validate physical connectivity. See image. LLDP is enabled by default on LAN, HA, and management interfaces. You can enable it manually on other interfaces as needed. LLDP works only when the out-of-band management interface is configured. Border Gateway Protocol (BGP) Route Filtering Added support for BGP prefix filtering using import and export maps to control inbound and outbound route advertisements. See image. The route map filters for both import and export options allow filtering by including or excluding IP prefixes. See image. The following limitations apply: Network object groups with FQDN members cannot be used for route filtering. Only one export and one import route-map is supported per BGP peer or neighbor. Only user-defined network object groups can be used in route-maps. Route matching supports only IP-based prefix lists. AS-PATH, MED, and Communities are not supported. System and WAN Health Monitoring Added support for real-time and historical monitoring of tunnel, connectivity, system and WAN health, including appliance resource utilization, WAN bandwidth usage, interface state changes, and WAN performance metrics. Admins can monitor CPU, memory, disk usage, interface status, throughput, latency, jitter, packet loss, WANMon scores, and timestamped interface Up/Down events, and they can run on-demand WAN speed tests to validate link performance and troubleshoot connectivity issues. See image. Weight-Based High Availability (HA) Added support for weighted interface tracking in Zero Trust Branch HA deployments to enable weight-based failover decisions and reduce unnecessary failovers during transient WAN, interface, or service failures. The weigh-based failover tracks the following components: Category Components Services agn-poller securedhcp-relay agn-dhcp-uploader agn-state-monitor Processes zcc-client Containers vyos_container policy_container dnsproxy_container zeek Interface Enhancements The following enhancements were made to improve interface configuration, status visibility, and connectivity validation: Added interface utilization metrics, throughput calculations, refresh controls, and administrative status management to the Interfaces page. See image. Added support to modify speed from the UI. This setting allows manual configuration of the interface speed using a drop-down menu with the following options: GE Interface: Auto (default), 100M, 1G XE Interface: Auto (default), 100M, 1G, 10G Desired Duplex: This feature is provided to support connectivity with legacy equipment requiring specific duplex types. A drop-down menu offers the following options: Auto (default), Half, Full. Desired MTU (Maximum Transmission Unit): A number input field where the maximum permissible value is 9000. Admin Status: This control physically enables (Admin Up) or disables (Admin Down) the interface. Changing the administrative status also reflects in the link status. An Up (default) / Down toggle button is implemented for this purpose. See image. Appliance Admin Console Added Appliance Admin Console, a command-line interface, for appliance management and troubleshooting, providing configuration (starts with config ), operational (starts with run ), and status or show (starts with show ) commands with improved usability, mandatory password changes on first login, and audit logging to help prevent unintended shell access. See image. Site Health Monitoring The site Overview page includes the following widgets: Connectivity Health: Shows health status of Internet & SaaS IPSec tunnels. It also includes an option to probe Private Access endpoints to check if the endpoints are reachable from the site. Critical Services Health: Shows the status of various components of Zero Trust Branch. See image. Low Bandwidth Mode Support Added low bandwidth mode for Zero Trust Branch appliances running version 8.1.2 or later to optimize performance in bandwidth-constrained environments. See image. The following limitations apply when low bandwidth mode is enabled: Asset Discovery is disabled. Configuration updates can take up to an hour if the configuration control channel is unavailable. Requires manual configuration from Zscaler Support for a Private Access setting configuration. DHCP Enhancements Address Conflict Detection Added a check to detect duplicate IP address conflicts before assigning DHCP leases, improving reliability and preventing IP address conflicts in the network. See image. Support for DHCP Profiles (Per-VLAN) Option Zero Trust Branch supports granular control over DHCP configurations with per-VLAN DHCP options, simplifying multi-VLAN deployments by allowing you to configure DHCP options on a per-VLAN basis for enhanced security and operational flexibility. This enhancement allows you to assign different DHCP options to different VLANs, ensuring that corporate devices receive necessary network information while guest devices are isolated from sensitive internal services. Each DHCP profile can be configured for either a DHCP Server (with custom options) or a DHCP Relay. You can create a DHCP profile and associate it with a VLAN. See image. Support for Zscaler Branch Connector Groups Added support to associate Branch Connector groups with Zero Trust Branch sites for consistent policy application in Internet & SaaS and Private Access. Support for Internet & SaaS and Private Access Sublocations Zero Trust Branch syncs with Zscaler Central Authority (CA) for obtaining sublocation definitions and applies labels to traffic origination from those locations within networks managed by Zero Trust Branch. This ensures Private Access differentiates traffic from network segments and applies policies for sublocation traffic originating from a Zero Trust Branch network. See image. ENTITY-MIB Support Added support for ENTITY-MIB for SNMP, which allows capturing host-level metrics, such as CPU and disk usage, through a host-based SNMP proxy service. UI Enhancements The following UI enhancements were added: A new field (Comment) to support adding comments while configuring static routes. See image. Support for uploading networks and MAC addresses in bulk via CSV files to create objects. See image. Option to clone forwarding policies. See image. Option to filter security policies based on the Ransomware Kill Switch indicators. See image. Support to view (read-only) system default groups. See image. An Appliance Inventory page that automatically populates appliance hardware serial numbers and provides visibility into deployed devices and their status, simplifying appliance registration for Zero Touch Provisioning and improving operational oversight. See image. Resolved Issues The following issues were resolved: Fixed an issue where failover was not triggered when the primary WAN next hop is unreachable and no distribution method was configured. Fixed an issue where certain Zscaler IP addresses were not referenced in default routing policies.