Symantec Enterprise Security Cloud (SESC) has the Cloud SWG policies enabled to allow SEP clients connect to Cloud SWG in tunnel mode.
macOS Clients are unable to connect to Cloud SWG using the SEP agent.
From the SESC interface, admins sees "At risk - malfunctioning (Web and Cloud Access Protection)" warning.
Windows Clients are all working without issues.
SEP users previously had the Web and Cloud Access Protection in PAC file mode but were migrating to tunnel mode.
Cloud SWG.
Web and Cloud Access protection policies configured through SESC.
Incorrect token installed in the SEP policy.
Make sure that the SEP configuration for SEP macOS clients includes the token from the highlighted field below.
When running tunnel mode with macOS clients, the PAC file mode token will not work.