Web Security displays "Tunnel failed" in Endpoint Security Agent over RDP
search cancel

Web Security displays "Tunnel failed" in Endpoint Security Agent over RDP

book

Article ID: 450245

calendar_today

Updated On:

Products

CBX Complete CBX Essentials Cloud Secure Web Gateway

Issue/Introduction

When the Endpoint Security Agent (ESA) is installed on a remote system and accessed via a Remote Desktop Protocol (RDP) session, the Web Security component displays a "Tunnel failed" status. This occurs because the component defaults to expecting a physical user login, whereas RDP creates a virtual desktop session.

Environment

  • CBX console (Complete/Essentials)
  • Endpoint Security Agent (ESA)

Cause

The Web Security component is configured to identify traffic based on the console user. In an RDP session, the system identifies the session as a virtual desktop, causing the tunnel initialization to fail under default settings.

Resolution

To resolve the "Tunnel failed" message and allow Web Security to connect during RDP sessions, update the system policy in the CBX console:

1. Log into the CBX console.

2. Navigate to Agent Management > Policies > System Policy - Default > Web Security Settings.

3. Change the Identify traffic from setting from Based on the console user to Based on the running process.

4. Click Save and Apply to device groups.

5. Relaunch the Endpoint Security Agent on the remote system.

Web Security now displays as connected.

Additional Information

For further assistance, refer to the Broadcom Support Portal