Description of the Anomaly
When a device re-enters the captive portal flow while its previous session is still active, a new authentication token is generated for the same IP address and site instead of reusing the existing valid session. This behavior has contributed to the authentication delays observed by end users.
Investigation Status
Following investigation with Zscaler support, it was confirmed that the issue stems from latency in the backend infrastructure during authentication validation. In the test case analyzed, the response from login.zscaler.net was delayed by approximately 28 seconds.
This delay causes the captive portal browser on iOS and Android devices to time out before the authentication flow can complete. Although authentication is ultimately validated in the background, it occurs too late for the portal window to close as expected, resulting in a degraded experience for end users.
Action Plan
We continue to work closely with Zscaler support to determine the root cause of this backend latency and identify a permanent resolution.
In the meantime, we have implemented a mitigation measure related to the authentication process: it will now be triggered less frequently, reducing how often guests encounter the 28-second delay.
We will share further updates as soon as additional information becomes available.