When the Endpoint Security Agent (ESA) is installed on a remote system and accessed via a Remote Desktop Protocol (RDP) session, the Web Security component displays a "Tunnel failed" status. This occurs because the component defaults to expecting a physical user login, whereas RDP creates a virtual desktop session.
The Web Security component is configured to identify traffic based on the console user. In an RDP session, the system identifies the session as a virtual desktop, causing the tunnel initialization to fail under default settings.
To resolve the "Tunnel failed" message and allow Web Security to connect during RDP sessions, update the system policy in the CBX console:
1. Log into the CBX console.
2. Navigate to Agent Management > Policies > System Policy - Default > Web Security Settings.
3. Change the Identify traffic from setting from Based on the console user to Based on the running process.
4. Click Save and Apply to device groups.
5. Relaunch the Endpoint Security Agent on the remote system.
Web Security now displays as connected.
For further assistance, refer to the Broadcom Support Portal