ZIA

Firewall Policy Test

Validate outbound TCP destination-port access through the endpoint's active ZCC and ZIA path.

Custom Port Test

Test a specific destination port against the dedicated firewall probe host.

firewallprobe.zscalerps.com

Ports

100

Allowed

0

Blocked / Unreachable

0

Not Testable

30

Top 100 Security-Relevant TCP Ports

A curated set of common Internet, remote-access, infrastructure, database, middleware and frequently exposed application ports.

Common Internet & Web

Common web, mail, proxy, file-transfer and Internet-facing application ports.

Remote Access & Infrastructure

Administrative, directory, Windows, remote-access and infrastructure-control ports.

Databases, Apps & High-Risk

Database, cache, middleware, orchestration, developer and frequently exposed application ports.

Why are some ports Not Testable?

Modern web browsers intentionally restrict connections to certain TCP ports for security reasons. For these ports, the browser blocks the connection locally before any network traffic is generated.

Because no connection leaves the browser, the request never reaches ZCC, ZIA, or the firewall probe. Therefore, this portal cannot determine whether that port would be allowed or blocked by the ZIA Firewall policy.

Not Testable does not mean Blocked by ZIA. It indicates a browser limitation only.

These restrictions help prevent malicious websites from using a browser to communicate with sensitive non-web services such as SSH, Telnet, SMTP, DNS, RPC, and other infrastructure services.