SSP UI inaccessible from VDI subnet with HTTP Error 401
search cancel

SSP UI inaccessible from VDI subnet with HTTP Error 401

book

Article ID: 444559

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention VMware vDefend Firewall

Issue/Introduction

Users may find that the vDefend Security Services Platform (SSP) UI is inaccessible when accessed from specific subnets, such as VDI subnets, while remaining accessible from other network segments. This occurs even when the SSPI diagnostic pages indicate that all services are healthy and stable.

*   SSP UI fails to load with error: `The page isn't working. HTTP Error 401`.

*   Browser Developer Tools show `401 Unauthorized` when attempting to access the SSP UI page.

*   SSPI UI is accessible from the same machine where SSP UI fails.

*   SSP UI is accessible from a VM on the same subnet as the SSP appliance.

*   SSP UI is accessible from non-VDI subnets.

*   Connectivity checks (e.g., `curl`) from the SSPI CLI or Windows command prompt to the SSP instance succeed.

Environment

vDefend Security Services Platform (SSP) 5.1.1

Cause

This issue is typically caused by environmental proxy settings at either the browser or OS level within the VDI subnet. These settings can interfere with the authentication or routing required to reach the SSP UI, leading to 401 unauthorized errors.

Resolution

To resolve this issue, verify and adjust the proxy settings on the affected machine:

1.  Disable any active proxy settings in the browser (e.g., Chrome, Edge).
2.  Check for OS-level proxy configurations and disable them for testing.
3.  Test access using a portable browser that bypasses system-level proxy settings.
4.  If access is restored after disabling the proxy, work with your network or VDI administration team to add the SSP FQDN/IP to the proxy bypass list.