Users seeing Cloud SWG blocked page warning or connectivity issues accessing bypassed site using WSS Agent
search cancel

Users seeing Cloud SWG blocked page warning or connectivity issues accessing bypassed site using WSS Agent

book

Article ID: 383280

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Users successfully accessing internet via Cloud SWG using WSS Agent access method.

Cloud SWG admin added a new domain to the bypass list but users accessing this domain are getting a Cloud SWG blocked page.

Cloud SWG admin has added many domain/IP/Application bypasses in the past and all worked fine.

Environment

Cloud SWG.

WSS Agent.

Domain/IP/Application bypass list.

Cause

With advanced Agent Traffic Manager now enabled on all Cloud SWG tenants (end of November 2024), the WSS Agent domain/IP/Application bypass configuration has moved into the 'Agent Traffic Manager' configuration under Connectivity and needs to be performed there.

Resolution

Add any domain, IP or application bypass to the Connectivity -> Agent Traffic Manager 'Traffic Bypass' rules. The domain, IP and application bypass list are all visible under this configuration, and any additions must be done here and not in the Connectivity -> PAC file bypasses list where Cloud SWG admin had incorrectly added it. The PAC file bypass list only applies to explicit access methods, and not to WSS Agents.

NOTE: make sure that the changes are ACTIVATED. Prior to the Agent Traffic Manager changes, IP/Domain/Application bypasses could be added and no apply or activation was needed. With this new approach, it is imperitive that the changes are activated, else the WSS Agent will not pick them up.

Additional Information

With advanced Agent Traffic Manager, the Cloud SWG admin can now configure different IP/Domain/Application bypass lists per users/groups.

For this reason, the more granular bypass list was moved from the main Connectivity page into the Agent Traffic Manager configuration page.