icon-unified.svg
Experience Center

Restricting Remote Packet Capture

Zscaler Client Connector uses the Npcap library to perform packet capture for troubleshooting.

Enabling Digital Experience Monitoring installs Npcap.

When users run Zscaler Client Connector with Npcap functionality enabled, they can make packet capture tools available in the user space, allowing non-administrators to perform packet capture. This could elevate a user's access during a packet capture session and allow them unauthorized access. You can limit packet capture to administrators only by enabling Restrict Remote Packet Capture.

If Npcap is already installed, Zscaler Client Connector uses the registry setting to restrict remote packet capture to administrators only.

To limit packet capture to administrators only:

  1. In the Admin Portal, go to Infrastructure > Connectors > Client > User Privacy.
  2. On the User Privacy tab, enable Restrict Remote Packet Capture.
  3. Click Save.

Related Articles
About User PrivacyConfiguring Zscaler Client Connector to Collect Device Owner InformationConfiguring Zscaler Client Connector to Collect HostnamesEnabling Packet Capture for Zscaler Client ConnectorConfiguring Automatic Crash Reporting for Zscaler Client ConnectorConfiguring Zscaler Client Connector to Collect Digital Experience Monitoring Location InformationAllow Users to Override Z-Tunnel 2.0 or Private Applications Protocol SettingsAllowing Non-Administrator Users Access to Zscaler Client Connector Log FilesRestricting Remote Packet Capture