"Domain bypass count" in WSS Agent Diagnostic Log might be different than the number of bypassed domains
search cancel

"Domain bypass count" in WSS Agent Diagnostic Log might be different than the number of bypassed domains

book

Article ID: 383100

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

WSS Agent displays a number of bypassed domains in the Diagnostic Log ("Domain bypass count") which can be different than:
• a number of "Bypassed Domains" in "Connectivity > PAC File Bypasses"
• a number of "Domain Bypass List" and "Global Bypass Domains" in "Connectivity > Agent Traffic Manager > Traffic Bypass Rules"

for example:

Environment

WSS Agent

Resolution

With the Agent Traffic Manager (ATM) rollout, the place to configure bypasses for WSS Agent has changed (to "Connectivity > Agent Traffic Manager > Traffic Bypass Rules").

When ATM was fully enabled, the domains and IPs configured in bypass lists were copied from the old place (which is called "PAC File Bypasses" now) to ATM:

  • "Bypass List Destination" contains the domains configured by the customers
  • "Global Bypass Domains" contains the default domains Broadcom adds to all customers

The value of "Domain bypass count" is the number of unique domains from the following rules/lists:

  • "Bypass List Destination"
  • "Global Bypass Domains"
  • Custom rules added in the "Traffic Bypass Rules".

Since in the ATM the custom rules can specify different source (so can be applied only for certain users or groups for example), WSS Agent on different machines can show different number of bypassed domains now.