ZTNA segmented applications not working
search cancel

ZTNA segmented applications not working

book

Article ID: 374216

calendar_today

Updated On:

Products

Symantec ZTNA

Issue/Introduction

Cloud SWG users accessing internet sites using WSS Agents.

To provide access to internal applications, a ZTNA integration performed with Cloud SWG.

After connecting from their WSS Agent hosts successfully, and authenticating via SAML, users cannot seem to resolve or access any of the segment applications. No error message is reported other than the standard connectivity error.

 

Environment

Cloud SWG.

ZTNA.

Cause

No 'identity provider' selected as part of the WSS / Cloud SWG integration.

Resolution

Make sure that the 'Identity provider integration' ZTNA settings for WSS reference the same SAML IDP server that is used with Cloud SWG, as shown below:

 

If this is not the exact same SAML identity provider, it is imperative that the name identifier sent in the SAML assertion on the Cloud SWG side match a user with the same identifier on the ZTNA side e.g. if the Cloud SWG SAML assertion has a subject NameID of [email protected], the identity provider on the ZTNA side must have a user with this matching identity.