Error: 403 Forbidden when accessing specific sites via Cloud SWG
search cancel

Error: 403 Forbidden when accessing specific sites via Cloud SWG

book

Article ID: 445618

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Users receive an HTTP 403 Forbidden error when attempting to access specific websites (e.g., Atlassian, Jira, or internal corporate resources) while connected via Cloud Secure Web Gateway (Cloud SWG) and WSS Agent. This typically occurs when the destination site or its Web Application Firewall (WAF) blocks the egress IP addresses used by Cloud SWG.

  • Browser displays 403 Forbidden.
  • Cloud SWG logs show an ALLOWED verdict but the Origin Content Server (OCS) returns the 403 status code.
  • Issue may occur specifically when a client VPN is active.

Environment

Cloud Secure Web Gateway (Cloud SWG)
WSS Agent
3rd Party VPN

Cause

The destination web server or its security infrastructure (WAF/ACLs) is blocking the Cloud SWG egress IP range. This often happens if the destination requires traffic to originate from a specific corporate VPN range rather than the Cloud SWG egress ranges.

Some websites do not allow access when a proxy like service, such as Cloud SWG perform SSL inspection.

Resolution

Follow these steps to isolate and resolve the error:

  1. Isolate the WSS Agent:
    • Disable the WSS Agent on the affected machine.
    • Attempt to access the site again.
    • If the 403 Forbidden error persists with the agent disabled, the issue is environmental or related to 3rd party network restrictions (e.g., your VPN configuration). Contact your internal network or the 3rd party site administrator.

  2. Configure a Traffic Bypass:
    • If the site works with the agent disabled, configure an Agent Traffic Manager (ATM) bypass for the specific domain.
    • In the Cloud SWG portal, navigate to Connectivity > Agent Traffic Manager > Traffic Bypass Rules.
    • Add the affected domain to a bypass rule.
    • Activate the changes.
    • Reconnect the WSS Agent and verify access.

  3. Coordinate with Site Administrator:
    • Configuring a Traffic Bypass rule is not an option then request the destination site administrator to whitelist the Cloud SWG egress IP ranges for your region.

  4. Configure a SSL/TLS inspection bypass rule