Unable to connect to msftconnecttest.com with WSS Agent
search cancel

Unable to connect to msftconnecttest.com with WSS Agent

book

Article ID: 248622

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

When WSS Agent (WSSA) was active, connections to msftconnecttest.com were failing.

The WSSA 'Bypassed Traffic' section did not have an IP or Domain bypass added for the domain.

WSSA can fail to load due to OS network connectivity issues.

Cause

The WSS Agent should bypass the following domains: 

  • msftncsi.com
  • msftconnecttest.com
  • www.msftconnecttest.com
  • dns.msftncsi.com
  • ipv6.msftconnecttest.com

Requests to these domains should not be sent via the WSSA tunnel because it can interfere with the Windows Network Connectivity Status Indicator (NCSI) service and disrupt the WSS Agent connectivity logic.

Resolution

Ensure that the OS "captive portal" detection domains listed above are not in the WSSA "Domain Tunnel List" (ATM > Always Intercept Rules > "Domain Tunnel List").

The "captive portal" detection domains should NOT be intercepted or tunneled to the CloudSWG service (bypass them from WSSA).

Intercepting these domains can interfere with captive portal detection and cause network connectivity issues.

These domains must be resolvable by DNS (or else the OS cannot detect captivity).  WSSA relies on the OS to determine if the machine is on a captive network.

Additional Information

Network Connectivity Status Indicator (NCSI)