Blog de Zscaler

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Products & Solutions

How to Find Which ISP is Slowing Down Your Users

image
CYNTHIA TU
julio 22, 2026 - 7 Min de lectura

Every network operations team eventually faces the same scenario: a wave of tickets from users in one region complaining that "everything is slow." Your internal network looks healthy, your monitoring tools show green, and yet users are frustrated. The problem is almost always somewhere you can't directly see — a last-mile ISP, a transit carrier, or a routing change at a peering point.

This is the core problem ZDX Network Intelligence was built to solve. In this post, we'll walk through exactly how to identify which ISP or specific hop is responsible when user experience degrades.

Why traditional tools can't answer "which ISP?"

Network monitoring tools were designed for a world where IT controlled the network end-to-end. In that world, you could see every link, every router, and every hop traffic crossed. In today's world — hybrid workforces, SaaS apps, zero trust architectures — that's no longer how traffic flows.

Most user traffic now leaves the corporate perimeter immediately and traverses networks you don't own: the user's home ISP, an intermediate carrier, the SaaS provider's edge. Traditional network monitoring tools go silent the moment traffic leaves your control. Synthetic monitoring tells you a probe location can reach the app, but not whether your actual user can. Application monitoring tells you the app is performing, but not whether the path to it is.

The result is what we hear constantly from NetOps teams: "We can prove our network is fine, but we can't prove anything else."

How ZDX Network Intelligence sees what other tools can't

ZDX takes a different architectural approach. Because ZDX is delivered through the Zscaler Zero Trust Exchange — the same cloud that secures user traffic — every user's session naturally flows through Zscaler's inline cloud. That gives ZDX a vantage point inside the user's actual path, not just at fixed probe locations.

Every five minutes, the Zscaler Client Connector launches lightweight cloud probes that collect telemetry — latency, packet loss, jitter — along the user's exact route to each monitored application. Machine learning baselines this data continuously and flags deviations. The result is end-to-end visibility from the user's device, across last-mile ISPs and intermediate ISPs, through the Zscaler cloud, to the destination application.

Step 1: Identify where the problem is concentrated

When tickets start coming in, the first question is whether the problem is widespread or localized. Open the ZDX Network Intelligence dashboard for a global view of network performance. Routes are color-coded by severity — red for critical, yellow for minor — so problem areas are visible at a glance.

Filter by region, department, or location to narrow the scope. If users in São Paulo are reporting slowness but users in Frankfurt aren't, you've immediately confirmed it's a regional issue rather than a global one — and you can stop wasting time investigating systems that don't matter.

Step 2: Drill into BGP Autonomous Systems

Once you've localized the problem, the next question is which ISP or carrier is involved. ZDX aggregates probe telemetry by BGP Autonomous System Number (ASN), which is how the internet actually organizes itself. Each ISP, transit carrier, and major network operates one or more ASNs.

Click into the affected region and ZDX shows you the BGP ASNs your users' traffic is crossing. Each ASN displays its observed latency, packet loss, and contribution to user experience scores. The ASN at the top of the latency chart is your suspect.

For example, if users in São Paulo show heavy latency on a transit carrier's ASN that they don't normally cross, you've found the routing change that's causing the problem.

Step 3: Drill into specific hops and routers

ASN-level analysis tells you which carrier; hop-level analysis tells you which specific routers and links inside that carrier are the problem. ZDX lets you drill from BGP AS down to individual hops within that AS, showing per-hop latency and packet loss.

This is where the investigation gets concrete. You might find that a single peering point between two carriers is dropping 8% of packets, or that a specific router is adding 90ms of unexpected latency. With this level of detail, you have evidence to escalate to the carrier with — not just a complaint that "something is slow."

Step 4: Use Peer Impact Analysis to confirm scope

Before escalating to a carrier, you want to know: is it just my organization affected, or are others seeing the same thing? ZDX Peer Impact Analysis answers this directly. It shows whether other Zscaler customers traversing the same ISP path are experiencing the same anomaly.

If the dashboard shows three other Zscaler customers on that link are affected, the issue is widespread and external. You have strong evidence the carrier is the source — not your network, not your security stack, not the application. That changes the conversation completely. Instead of arguing internally about whose fault it is, you have data to go to the carrier with.

This is a capability unique to ZDX. No other DEM tool can give you cross-customer visibility into shared internet paths because no other tool sits at this scale on the inline cloud.

Step 5: Reroute through a better-performing path

ZDX doesn't just diagnose — it gives you the data to fix the issue. Network Intelligence benchmarks packet loss and latency across the ISPs serving your users and highlights better-performing paths. With the data in hand, you can configure ZIA to route users to a better-performing Zscaler data center, bypassing the underperforming ISP.

This is one reason customers report up to 98% faster issue detection and resolution with ZDX — because finding the issue and fixing it happen on the same platform, in the same workflow.

A real example: Careem's NetOps workflow

Careem operates across 14 countries with thousands of remote customer service representatives. Before ZDX, when CSRs reported slowness, the NetOps team had to investigate manually — often spending hours determining whether the issue was internal or with the CSR's home ISP.

CIO and CISO Peeyush Patel describes the change: "Using ZDX we can rule out our network in minutes and focus the CSR's attention on their internet connectivity issue. Sometimes, we can suggest settings that will help. On other occasions, we can empower individuals to get a resolution from their ISP by providing them with information generated by ZDX, including intuitive visual diagrams and reports."

The result for Careem: a 62% reduction in mean time to resolve, supporting a doubling of the customer service workforce on the same InfoSec team.

Set custom alerts for proactive detection

The five steps above describe reactive investigation — what to do when tickets come in. The bigger ROI of Network Intelligence is proactive detection. Set custom alert thresholds for latency, packet loss, or ZDX Score deviation, and ZDX notifies you when ML-baselined behavior shifts before users notice.

Alerts route to email, IM, ServiceNow, and other ticketing systems via webhook, so they slot into the workflow your NetOps team already runs.

What's next

If you found this useful, check out the ZDX webpage for more information on deeper capabilities, including multipath visualization, real user monitoring, and Device Score and Remediation. See Network Intelligence in action against your own environment.

FAQs

ZDX Network Intelligence aggregates probe telemetry by ISP and BGP Autonomous System Number, with routes color-coded by severity. Drill from a global view down to specific ASNs and individual hops inside each ASN.

Peer Impact Analysis shows whether other Zscaler customers are experiencing the same network anomaly on the same ISP path, instantly distinguishing internal issues from carrier-wide problems.

Yes. ZDX continuously baselines ISP performance and flags deviations such as latency spikes, elevated packet loss, and routing changes that signal a brownout or blackout.

Probes run every five minutes, and ML baselines are updated continuously. Most anomalies are detected and surfaced within one probe cycle.

Yes. The Zscaler Client Connector runs on user devices regardless of network — home ISP, public Wi-Fi, mobile hotspot — and ZDX collects telemetry from wherever the user actually is.

form submtited
Gracias por leer

¿Este post ha sido útil?

Exención de responsabilidad: Este blog post ha sido creado por Zscaler con fines informativos exclusivamente y se ofrece "como es" sin ninguna garantía de precisión, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por errores u omisiones ni por las acciones que se tomen basándose en la información proporcionada. Cualquier sitio web o recurso de terceros enlazado en esta publicación de blog se proporciona únicamente por conveniencia, y Zscaler no se hace responsable de su contenido ni de sus prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, acepta estos términos y reconoce ser el único responsable de verificar y utilizar la información de manera adecuada según sus necesidades.

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Al enviar el formulario, acepta nuestra política de privacidad.