Start where the problem happens.
Diagnostics live in the same client as VPN, ZTNA, RBI, and PQC. Associate observations with the active tunnel, device, resource, and observation window.
Meet the unified clientStart with the employee’s experience. Follow the connection. Give your team an explanation they can act on.
Read the architectureDNS and TCP succeed, but no TLS response is observed before the 30-second timeout. Two internal comparison connections complete.
Client-side evidence cannot establish whether the origin received the ClientHello, or whether a gateway, path issue, or server caused the silence.
Correlate the destination, time window, and session with gateway inspection events and origin TLS logs. Check SNI policy and destination-specific routing.
Administrator review · No automated policy changePacket timing explains what happened on a connection. Identity, browser, and policy evidence help explain why.
Diagnostics live in the same client as VPN, ZTNA, RBI, and PQC. Associate observations with the active tunnel, device, resource, and observation window.
Meet the unified clientCompare healthy and affected flows, correlate authorized sources, and distinguish measured facts from hypotheses. Every next step starts with evidence.
Explore the audit capabilityReview the finding, source records, and collection scope. Approve remediation through existing policy controls, with an auditable decision trail.
Explore administrator controlsCapture coverage depends on platform support and configured routes. TLS certificate and PQC negotiation details come from endpoint or gateway instrumentation. RBI events come from the remote session. These sources complement packet observations without pretending encrypted application content is visible.