Override Threat Risk Score in Edge SWG and ASG
search cancel

Override Threat Risk Score in Edge SWG and ASG

book

Article ID: 223792

calendar_today

Updated On:

Products

ProxySG Software - SGOS ISG Proxy ASG-S200 ASG-S400 ASG-S500

Issue/Introduction

A URL or resource may be blocked by Edge SWG or ASG policy because the Threat Risk Score returned by Intelligence Services exceeds the configured threshold. Use the steps below to override the assigned Threat Risk Score for a specific domain.

Environment

Edge SWG, ASG, and ISG Proxy environments.

Resolution

To override the Threat Risk Score for a specific domain, add a CPL rule to your local policy file.

  1. Access the local policy file on the ProxySG or ASG.
  2. Add the following CPL rule:

cpl


<Proxy>
  url.domain=example.com variable.url.threat_risk.effective_level(1)

  1. Replace example.com with the URL domain you wish to override.
  2. Save and install the policy file.

For more information on the CPL variable variable.url.threat_risk.effective_level, see url.threat_risk.effective_level. For instructions on adding CPL to a local policy file, see Add CPL to a local policy file on the ProxySG.

Additional Information

If issues persist, verify policy activation and ensure logs indicate that the expected policy is being matched. For assistance with log retrieval, see How to collect logs for support analysis. For further assistance, contact Broadcom Support.