Endpoint Protection for Mac blocks WSS traffic when WCAP policy is enabled
search cancel

Endpoint Protection for Mac blocks WSS traffic when WCAP policy is enabled

book

Article ID: 247861

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Symantec Endpoint Protection (SEP) for Mac blocks WSS traffic when WCAP policy is enabled.

WCAP = Web and Cloud Access Protection, SEP's integration with Symantec's WSS without requiring a standalone WSS agent
WSS = Web Security Service

Environment

SEP for Mac

Cause

There is no default rule to allow this traffic.

Resolution

Create an "Allow" rule for the required WSS traffic. See section labeled "Explicit Proxy SEP PAC File Management System or Default PAC file" in online documentation here: WSS Required Locations, Ports, and Protocols. The rule should look something like this in the Mac section of the firewall policy:

https://api-broadcom-ca.wolkenservicedesk.com/attachment/get_attachment_content?uniqueFileId=y62itIl4hPr30x2WIuOspA==

This rule is not expected to be necessary in future versions of SEP for Mac, with tighter WCAP integration allowing the traffic automatically.