Connectivity and performance issues between VeloCloud Edge and Cloud SWG
search cancel

Connectivity and performance issues between VeloCloud Edge and Cloud SWG

book

Article ID: 441477

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Introduction 

Intermittent latency, brief disconnections, or delays in web browsing can occur when routing traffic from VeloCloud Edge devices through Cloud Secure Web Gateway (Cloud SWG) PoPs (e.g., GGRAT, GDEFR). This article provides troubleshooting steps to identify root causes related to firewall policies and data pod connectivity.

 

Environment

Environment

  • Product: Cloud Secure Web Gateway (Cloud SWG)
  • Access Method: VeloCloud IPsec Tunnel
  • Component: VeloCloud Edge
  • PoPs: GGRAT, GDEFR

 

Cause

A known issue with the Common Criteria Firewall policy on VeloCloud Edge devices can block inbound traffic, such as TCP SYN-ACKs, even when IPsec tunnels are active.

Resolution

  1. Verify Firewall Configuration: Check the VeloCloud Edge configuration for the Common Criteria Firewall policy. Disable this policy to determine if connectivity is restored.
  2. Verify Service Status: Review the Cloud SWG Status Page for active maintenance or regional alerts.
  3. Validate Data Pod Routing: Review access logs to identify the specific data pod being accessed. If routing is incorrect (e.g., European users hitting US pods), use Location Management APIs to manually set the country and time zone for the Edge tunnel.
  4. Collect Diagnostic Data: If the issue persists, collect the following during an active incident:

For further assistance, see Contact Support.

 

Additional Information