Cannot access any sites via VeloCloud Edge device when integrated with Cloud SWG
search cancel

Cannot access any sites via VeloCloud Edge device when integrated with Cloud SWG

book

Article ID: 381609

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG VMware Edge Intelligence Appliance

Issue/Introduction

VeloCloud Edge device has SSE integration into Cloud SWG.

Activating the changes correctly shows that the Velo Edge device appears in the Cloud SWG Portal location.

VeloCloud Edge monitoring shows two IPSEC tunnels successfully established with Cloud SWG side.

Users browsing to any Web site fail to get any response - the standard browser connectivity error shows that the site cannot be reached.

Authentication initially enabled, but disabled for troubleshooting purposes without any change in behaviour.

PCAPs on the client side show TCP SYN outbound requests to any Web site being accessed without any responses back.

 

Environment

Cloud SWG.

VeloCloud Edge device.

 

Cause

Bug with Common Criteria Firewall policy on the Edge.

Resolution

Disable the common criteria firewall policy on the Edge device configuration (visible from the Connectivity options as shown as enabled below).

Additional Information

PCAPs on the Cloud SWG side showed the inbound TCP SYN requests were responded to with corresponding server SYN ACK's which never made it to the client.

Since the server SYNs were coming back over the IPSEC tunnel, something on the Edge was blocking it from being routed to the user.

Looking at all enabled Edge configuration options, Edge admin disabled any non default options and identified the common criteria firewall as being the culprit.