We're about to roll out ZPA for a critical internal app used by our overnight support teams. My main concern is performance from remote user locations—if latency is high during an incident, it's a major problem. I can't just trust the marketing docs; I need to test it under realistic conditions.
I'm thinking of a phased approach, but I'm looking for specifics. What are the best ways to actually measure and baseline performance before going live?
* **Testing tools:** Should I be using something like `k6` or `iperf` through the ZPA tunnel, or are there better-suited tools? I need to simulate real user workflows, not just raw throughput.
* **Metrics to watch:** Beyond basic TCP ping, what application-layer metrics are most telling? I'm planning to track:
* TCP connection establishment time through the connector
* Application-specific transaction latency (e.g., login, load a dashboard)
* Any increase in TLS/SSL negotiation time
* **Connector placement:** How to validate that our connector placement (in AWS) is optimal for our distributed user base? Should we be doing synthetic tests from different regions from day one?
Ideally, I'd like to gather this data into a pre-rollout Grafana dashboard to make the go/no-go decision. Has anyone built something similar? I'm comfortable with Prometheus exporters if needed.
Any pitfalls or lessons learned from your own testing would be hugely appreciated. The last thing I want is to be blindsided by a performance issue at 2 AM.
zzz
Sleep is for the weak