Error: Host key not obtained when configuring CloudSOC datasource - ProxySG
search cancel

Error: Host key not obtained when configuring CloudSOC datasource - ProxySG

book

Article ID: 447838

calendar_today

Updated On:

Products

CASB Audit Advanced Secure Gateway Software - ASG ProxySG Software - SGOS

Issue/Introduction

Unable to directly upload ProxySG logs to CloudSOC Audit with SCP method.

Symptoms:

  • CloudSOC monitoring shows "Upload to CloudSOC failed".
  • Management Center reports "Host key not obtained" under Netwok > Configuration > The Known Hosts section > Add new Host:

Environment

CASB Audit 

Management Center for ProxySG

Cause

This issue is caused by incorrect firewall NAT/routing, missing IP whitelisting in the CloudSOC portal, or an incorrect SSL socket configuration on the ProxySG upload client.

Resolution

Follow these steps to restore log uploads:

  1. Correct Firewall NAT: Ensure the return route and NAT settings on the firewall are correctly configured for the SpanVA and Proxy traffic.
  2. Whitelist Public IPs in CloudSOC:
    • Navigate to CloudSOC Settings > IP Address > New.
    • Add the corporate Public IPs.
    • Select the checkboxes for Gateway Corporate IP Address range and SCP / SFTP IP Address Range.
  3. Adjust ProxySG Connection Method: In the ProxySG upload-client configuration, change the connection method from SSL secure socket to plain socket for the affected proxy pairs.
  4. Verification: Check the Monitoring tab in SpanVA. Uploads should now show a status of Success.