QMMAD + ZSCALER

Hello everyone -

Have a client using ZScaler for their vpn.  The back-end is cloud based and does not used a route based tunnel, it is dynamic.  We had to install the client manually, and it does find the console over the vpn.  When the console attempts to reply to the client, it gets lost and times out.  According to wireshark it simply "got lost".  Since the traffic was dynamic the socket request goes to the cloud then goes nowhere.

Has anyone seen this or have a remediation for it?  We have engaged zscaler and they saw the same traffic drop we saw.  Since the product is dynamic it cannot control the flow in a normal manner.  Is there any setting in the tool/registry we can force......?

Thanks for any insight...