ZTNA Connector — Tunnel remains Inactive despite active Control Plane (NFR tenant)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ZTNA Connector — Tunnel remains Inactive despite active Control Plane (NFR tenant)

L0 Member

Hello Evryone, 

I'm tring to deploy a ztna connector on my home lab to prepare different use case for customer demo and i still have the same issue.

Environment:

  • Tenant type: NFR 
  • ZTNA Connector deployed on-prem via KVM (Proxmox VE), two-arm deployment
  • Connector image: 200v-6.2.9-ztna-connector-b3-kvm.qcow2 (and try with 6.2.5 same issue)
  • Port 1 (WAN/PublicWAN): static IP, valid gateway, DNS reachable
  • Port 2 (LAN): static IP on isolated segment, reaching target app successfully via local NAT/firewall (NGFW in front)

Steps already taken:

  1. Onboarded ZTNA Connector via Strata Cloud Manager (Onboard Connectivity to Private Apps → ZTNA Connector)
  2. Created Connector Group, Connector, and FQDN Target (private app) successfully
  3. Deployed connector VM on Proxmox/KVM — required --cpu kvm64 (not host) and a serial console (serial0) to boot successfully; confirmed via LIVEcommunity forum post referencing this exact Proxmox setup
  4. Redeployed the connector fully from scratch (new Key/Secret, new Connector object in SCM) to rule out stale state — same result
  5. Verified via ion toolkit: dump interface config 1 shows correct static IP/gateway/DNS
  6. nslookup locator.cgnx.net from the connector times out — no DNS response, despite DNS servers being reachable and correctly configured
  7. Verified no firewall blocking on local network path (NGFW + edge firewall logs show no drops for this traffic after rule adjustments)
  8. Home ISP router  configured in DMZ mode pointing to firewall WAN IP to rule out double-NAT interference

Observed status in Strata Cloud Manager:

  • Control Plane:  Active
  • Tunnel: consistently Inactive
  • Config Status: "Tunnel Config Done"
  • Diagnostic tools in SCM (Dump Overview, Packet Captures under Connector → Actions → Diagnostics) spin indefinitely and never load, across multiple connector redeployments

Question: Is there a known limitation for ZTNA Connector tunnel establishment or SCM diagnostic tooling on NFR tenants? Or is there a specific requirement (e.g., licensing scope, region availability) we may be missing for tunnel establishment to complete?



Thank's for your help

0 REPLIES 0
  • 33 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!