Unexpected Error (200) accessing ZTNA Portal
search cancel

Unexpected Error (200) accessing ZTNA Portal

book

Article ID: 450748

calendar_today

Updated On:

Products

Symantec ZTNA

Issue/Introduction

ZTNA Administrator initially reporting "Unexpected error (200)" message below while adding a user/entity id to an existing policy.
 
 
Further tests showed that any changes to the ZTNA configuration via the Portal were not possible.
Confirmed that the user making the change had the appropriate admin rules.
Audit logs did not report any errors or configuration update requests at the time.
 
 
 
 
 

Environment

ZTNA.

Cloud SWG.

Administration Console.

DLP.

Cause

Cloud SWG DLP policy blocking access to uploaded ZTNA configuration.

Resolution

Change DLP policy to allow uploaded requests to the ZTNA Portal.

Additional Information

ZTNA admin made changes earlier in the day from the office, but the changes that gave the error were from the admin's home network.

Looking at the HAR file at the time of the issue showed the PUT (HTTP method used to push updates to ZTNA) request to update the policy (policy ID masked out below for security reasons) returned an error in the payload that indicated a DLP block (data_leak_detected).

Data leak messages are usually returned from a DLP policy when going through Cloud SWG.

Confirmed that the ZTNA admin was indeed sending traffic via Cloud SWG using the WSS Agent (active for all users outside of the office).

Logging into their Cloud SWG tenant, we confirmed that all HTTP requests using the PUT method were blocked with the data_leak_detected verdict.

Modifying the DLP policy to allow these requests through addressed the issue.