This article outlines the standard configuration guidelines for routing outbound application traffic to Symantec Validation and ID Protection (VIP) APIs via an outbound/forward proxy infrastructure. It clarifies responsibilities regarding network access control lists (ACLs) and endpoint path configuration.
Applications requiring multi-factor authentication (MFA) or identity services communicate with Symantec VIP API endpoints hosted by Broadcom. When an enterprise initiative dictates that all external vendor or SaaS calls must be funneled through a centralized proxy infrastructure (such as Netskope, Squid, or any corporate forward proxy), proper configuration on both the application side and the proxy side is essential to maintain service continuity.
Target Destination: https://services-auth.vip.symantec.com
Protocols/Ports: HTTPS (Outbound Port 443)
VIP Service
To seamlessly route traffic through the corporate proxy to Symantec VIP cloud endpoints, observe the following implementation parameters:
Action Required: You do not need to request Broadcom to allow or whitelist your proxy's new egress IP addresses. The Symantec VIP cloud endpoints are publicly available to receive validated API requests over the internet.
Endpoint Maintenance: Internal applications should continue to direct their calls natively to the target URL: https://services-auth.vip.symantec.com. Do not modify the API path; ensure the application environment variables or network configurations (HTTP_PROXY / HTTPS_PROXY) are handling the routing rule.
SSL/TLS Considerations: Ensure that security profiles on the proxy allow proper pass-through or appropriate certificate trust validation for Broadcom’s VIP cloud platform.
For full architectural details, official prerequisites, and detailed documentation on Symantec VIP validation services, please consult the official Broadcom TechDocs documentation: