Customer was trying to exclude all the file with extension .css from being protected but was not excluded even after adding in the Ignore Ext list of the ACO.
R12.8.x
Access Gateway
Disabling the double dot rule in the ACO of Access Gateway resolved the issue.
DisableDotDotRule = yes