"Connection failure: Could not send data due to dropped connection by the ICAP server" accessing DLP enabled sites
search cancel

"Connection failure: Could not send data due to dropped connection by the ICAP server" accessing DLP enabled sites

book

Article ID: 368247

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG Data Loss Prevention Cloud Detection Service for ICAP

Issue/Introduction

Users successfully accessing internet sites via Cloud SWG using WSS Agent.

To provide protection against data leakage, a DLP integration was activated with a set of policies.

Users uploading data to DLP enabled sites were getting 503 errors, with following ICAP specific error reported back:

"Connection failure: Could not send data due to dropped connection by the ICAP server"

Access logs confirmed the same ICAP errors reported with additional info in ICAP status fields, and confirming that we could not fail open to serve the request:

 ICAP_COMMUNICATION_ERROR fail_open_unavailable 

DLP Enforcer server logs not showing any requests for the sites reporting 503 errors.

Environment

Cloud SWG.

DLP integration.

WSS Agent.

Cause

DLP configuration on Cloud SWG not complete.

Resolution

Removed and re-added the DLP configuration within the Cloud SWG Portal.

Additional Information

Requests from the Proxy to upstream DLP service were missing one key identifier for this tenant, rendering the request invalid.