Disable protocol detection on Cloud SWG portal policy
search cancel

Disable protocol detection on Cloud SWG portal policy

book

Article ID: 176450

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

As an administrator, I would like to disable protocol detection when using the Cloud SWG portal policy.

Environment

Cloud Secure Web Gateway - Cloud SWG

Cause

  • Websites used non-standard services over standard ports, the workaround is to disable protocol detection.
  • Websites using unsupported ciphers suite such as TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
  • for mobile communicator applications like whatsapp or face time or etc, that utilize non-standard ports for communication
  • Websites that use mutual x509 authentication

Resolution

There is no dedicated policy setting to explicitly disable protocol detection in the Cloud SWG portal, however, Protocol detection can be disabled by adding:

  1.  Add domain/IP/Web App From Malware Scan
    Go to Policy > Content and Malware Analysis > Scanning Exemptions > Destinations

Note: SSL intercept will be disabled when protocol detection is disabled.

Additional Information