> For the complete documentation index, see [llms.txt](https://docs.thousandeyes.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.thousandeyes.com/product-documentation/global-vantage-points/endpoint-agents/tests-and-network-integrations/endpoint-agent-vpn-support.md).

# Endpoint Agent VPN Support

The Endpoint Agent provides end-to-end visibility into network nodes and metrics for traffic that traverses supported virtual private networks (VPNs). When the Endpoint Agent detects a VPN, the path visualization displays it, and the **VPN Vendor** attribute identifies the vendor in Endpoint Agent views. You can also filter each view by VPN.

{% hint style="info" %}
You can switch between the overlay path trace—the path between the VPN gateway and the application—and the underlay path trace—the path between the endpoint and the VPN gateway. You can also collapse or expand the path traces to reduce the number of visible hops.
{% endhint %}

![VPN overlay and underlay path traces](/files/-MSf0XsKdMlYW7mh4s0p)

## Supported VPNs

ThousandEyes supports the following VPNs for the Endpoint Agent:

* Cisco Secure Client (formerly Cisco AnyConnect)
* F5 BIG-IP APM VPN
* Palo Alto Networks GlobalProtect
* Pulse Secure Connect (versions released after December 1, 2020 are not supported)
* Zscaler Internet Access (ZIA)

{% hint style="warning" %}
Cisco Secure Client management tunnel mode is not supported. If an endpoint uses only a management tunnel, the Endpoint Agent does not detect it as an active VPN connection or report VPN statistics. User VPN tunnel modes remain supported.
{% endhint %}

{% hint style="info" %}
Zscaler Internet Access uses proxies, direct-only TCP traffic, and other methods. The following table lists the resulting visibility limitations.
{% endhint %}

| **Deployment Type**                                                          | **Visibility to VPN Gateway (Underlay) with TCP** | **Visibility to VPN Gateway (Underlay) with ICMP** | **End-to-End Visibility (Overlay) with TCP** | **End-to-End Visibility (Overlay) with ICMP** |
| ---------------------------------------------------------------------------- | ------------------------------------------------- | -------------------------------------------------- | -------------------------------------------- | --------------------------------------------- |
| Cisco Secure Client                                                          | Yes                                               | Yes                                                | Yes                                          | Yes                                           |
| F5 VPN                                                                       | Yes                                               | Yes                                                | Yes                                          | Yes                                           |
| Palo Alto Networks GlobalProtect                                             | Yes                                               | Yes                                                | Yes                                          | Yes                                           |
| Pulse Secure Connect                                                         | Yes                                               | Yes                                                | Yes                                          | Yes                                           |
| Zscaler via PAC file                                                         | Yes                                               | Yes                                                | No                                           | No                                            |
| Zscaler Client Connector with local proxy                                    | Yes                                               | Yes                                                | No                                           | No                                            |
| Zscaler Client Connector with LWF driver (default on Windows) and Tunnel 1.0 | Yes                                               | Yes                                                | No                                           | No                                            |
| Zscaler Client Connector with LWF driver and Tunnel 2.0                      | Yes                                               | Yes                                                | No                                           | Yes\*\*                                       |
| Zscaler Client Connector with route driver (default on macOS) and Tunnel 1.0 | Yes                                               | Yes                                                | No                                           | No                                            |
| Zscaler Client Connector with route driver and Tunnel 2.0                    | Yes                                               | Yes                                                | No                                           | Yes\*\*                                       |

{% hint style="info" %}
\*\*ICMP must be allowed on the local firewall for end-to-end visibility.
{% endhint %}

## VPN Configuration

No additional configuration is required to enable VPN support.

## Dynamic Tags

You can use dynamic tags to assign scheduled tests that run only while an endpoint is connected to a VPN. For more information, see [Manage Dynamic Tags for Endpoint Agents](https://docs.thousandeyes.com/product-documentation/global-vantage-points/endpoint-agents/configuring/dynamic-tags).

## Limitations and Caveats

* ThousandEyes recommends using TCP-based testing, as some VPNs block ICMP traffic.
* Full-tunnel VPNs do not allow traffic outside the tunnel. ThousandEyes might not provide visibility into the underlay, which is the physical connection between the endpoint and the VPN gateway.

## Additional Information

The Endpoint Agent passively monitors VPN state by inspecting the VPN client's logs. If VPN monitoring stops working or does not work as expected, open a Support case and include the VPN client version and logs.
