Edge SWG (ProxySG) log ingestion failure in CloudSOC after SpanVA upgrade
search cancel

Edge SWG (ProxySG) log ingestion failure in CloudSOC after SpanVA upgrade

book

Article ID: 443427

calendar_today

Updated On:

Products

CASB Gateway Advanced ProxySG Software - SGOS CASB Audit

Issue/Introduction

After upgrading Symantec SpanVA to version 1.15.3.170.0 or higher, logs uploaded from Symantec Edge SWG (ProxySG) are no longer processed or visible in the CloudSOC Audit dashboard. This occurs due to new security hardening that requires an encrypted connection for all log transfers.

Environment

  • Product: Symantec SpanVA (CloudSOC Gateway)
  • Version: 1.15.3.170.0 and higher
  • Log Source: Symantec Edge SWG (ProxySG) or any FTP client

 

Cause

SpanVA version 1.15.3.170.0 introduces FTPS Enforcement. The internal vsftpd configuration is hardened to reject plain, unencrypted FTP connections and requires SSL/TLS encryption (FTPS) for both server and client communications. External FTP servers/clients that communicate with SpanVA must now support FTPS.

Resolution

To restore log ingestion, the upload client must be reconfigured to use secure protocols.

To enable FTPS on Edge SWG, refer to the online documentation for enabling SSL on FTP:

Configure an Upload Client on Edge SWG 

If the FTPS client is configured to verify peer certificates, you must import the SpanVA certificate into the Edge SWG. 

  1. Open the SpanVA UI.
  2. Navigate to Certificates > Server.
  3. Select Actions > Download Certificate.
  4. Import this certificate into the Edge SWG's Trusted CA list or SSL Client trust package.
  5. Click Apply and verify if logs are being uploaded.

For further assistance with Edge SWG configuration, please refer to Article 165325.