I had forgotten about some logs in c:\windows\system32\log files which can be very useful.
The logs can at least show that connections are being made and what is being accessed via IIS. The logs are IIS generated and are not ZEN specific. XTIER does report some logs to this directory. You can control XTIER logging with these following keys.
(MT) ZENworks Middle Tier Server logging on Windows servers is enabled in the registry
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Novell\XTier\Configuration\XTLOG
Output: %System Root%\System32\LogFiles\Xtier
http://support.novell.com/cgi-bin/search/searchtid.cgi?10093312.htm
I also found that packet traces are a big asset.
If you can authenticate to https://serverip/oneNet/nsadmin then the zenworks ZDM agent should be able to authenticate also.
Comments more than welcome as I left a lot out.