Cloud SWG: Recommended Deployment Guidelines for IPSEC with SAML
book
Article ID: 409754
calendar_today
Updated On:
Products
Cloud Secure Web Gateway - Cloud SWG
Issue/Introduction
Recommended deployment guidelines for IPSEC with SAML to make sure authentication is automatically completed at logon without manual user interaction.
Environment
Cloud SWG
IPSec
WSS Agent
SAML authentication
Resolution
When deploying IPSEC with SAML authentication, the following best practices are recommended to ensure a seamless and secure user experience:
- Laptops (Roaming/Remote Devices)
- All laptops should have the WSS agent deployed.
- The agent must remain active both inside and outside the organizational network.
- This ensures consistent policy enforcement, secure authentication flows, and minimal disruption for mobile users.
- Static Workstations (On-Premises Only Devices)
- For fixed desktops and on-premises workstations, deploy a logon script as part of the Windows startup/login process.
- This script should automatically launch a background browser session to trigger SAML authentication.
- This guarantees that authentication is completed at logon without requiring manual user action, maintaining compliance and reducing helpdesk tickets.
Feedback
thumb_up
Yes
thumb_down
No