Routing Outbound Symantec VIP API Requests Through Forward Proxies
search cancel

Routing Outbound Symantec VIP API Requests Through Forward Proxies

book

Article ID: 447158

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

This article outlines the standard configuration guidelines for routing outbound application traffic to Symantec Validation and ID Protection (VIP) APIs via an outbound/forward proxy infrastructure. It clarifies responsibilities regarding network access control lists (ACLs) and endpoint path configuration.

Scenario Overview

Applications requiring multi-factor authentication (MFA) or identity services communicate with Symantec VIP API endpoints hosted by Broadcom. When an enterprise initiative dictates that all external vendor or SaaS calls must be funneled through a centralized proxy infrastructure (such as Netskope, Squid, or any corporate forward proxy), proper configuration on both the application side and the proxy side is essential to maintain service continuity.

  • Target Destination: https://services-auth.vip.symantec.com

  • Protocols/Ports: HTTPS (Outbound Port 443)

Environment

VIP Service

Resolution

To seamlessly route traffic through the corporate proxy to Symantec VIP cloud endpoints, observe the following implementation parameters:

  1. Broadcom / Symantec Endpoints IP Whitelisting Policy
    No Destination IP Whitelisting Required: Broadcom does not perform IP whitelisting or enforce source IP restrictions on their inbound cloud endpoints for VIP services.

Action Required: You do not need to request Broadcom to allow or whitelist your proxy's new egress IP addresses. The Symantec VIP cloud endpoints are publicly available to receive validated API requests over the internet.

  1. Application-Side Configuration
    Proxy Awareness: Local applications calling the Symantec VIP APIs must be configured to utilize the internal corporate proxy as their forward gateway.

Endpoint Maintenance: Internal applications should continue to direct their calls natively to the target URL: https://services-auth.vip.symantec.com. Do not modify the API path; ensure the application environment variables or network configurations (HTTP_PROXY / HTTPS_PROXY) are handling the routing rule.

  1. Proxy-Side Configuration
    Route to VIP Endpoints: The forward proxy must be explicitly permitted to reach the fully qualified domain name (FQDN) services-auth.vip.symantec.com over outbound port 443.

SSL/TLS Considerations: Ensure that security profiles on the proxy allow proper pass-through or appropriate certificate trust validation for Broadcom’s VIP cloud platform.

For full architectural details, official prerequisites, and detailed documentation on Symantec VIP validation services, please consult the official Broadcom TechDocs documentation: