Web and Cloud Access feature not working when policy is applied to non Default policy target rule
search cancel

Web and Cloud Access feature not working when policy is applied to non Default policy target rule

book

Article ID: 454133

calendar_today

Updated On:

Products

Endpoint Security

Issue/Introduction

When trying to use a Policy Target Rule to apply a Web and Cloud Access Protection policy (WCAP) in Symantec Endpoint Security (SES), the agent does not switch to the desired Location or install and start using the WCAP feature.

Environment

Symantec Endpoint Security agents

  • SEP 16
  • ESA

Cause

A bug within the SES Cloud console UI allows SES admin to apply a WCAP policy to any Policy Target Rule other than Default.  When WCAP is applied to any Policy Target Rule other than Default, it will not take affect.

Resolution

When a WCAP policy is applied to a device, it installs the necessary client features to enforce the policy.  This behavior is the same with a Feature Selection Policy.  Since both of these policy types can add or remove Feature Sets from the agent, they are intended to only be applied to the Default policy target rule (also referred to as a Location) so the agent does not regularly change feature sets.

A fix is being developed for this issue which will not allow you to apply a WCAP policy to Policy Target Rules other than Default.

Solution

The Web and Cloud Access policy should be applied to the Default policy target rule.  It should also be withdrawn from any Policy Target Rule other than Default since it will not take affect. To resolve the issue first remove the WCAP policy from any non-Default policy target rule, then apply WCAP only to the Default policy target rule.

To remove the WCAP policy from any non-Default locations, follow these steps

  1. Within the SES Cloud portal, click Policies (left)
  2. Select the WCAP policy in question
  3. Click Device Groups tab (within the policy)
  4. In the Policy Target Rules column, locate any Group(s) that have the WCAP policy applied to it
  5. Click on the Group
  6. Click Remove Policy
  7. Follow the un-select workflow to remove the WCAP policy from the Group and then non-default Policy Target Rules

Apply the WCAP policy to the desired Group(s) and only Default policy target rule

  1. Within the SES Cloud portal, click Policies (left)
  2. Select the WCAP policy in question
  3. Click Apply to Device Group(s)
  4. Select the Group(s) you want to apply the WCAP policy to
  5. On the "Select Policy Target Rule for <Policy Name>" page, ONLY select Default
  6. Click Next, then Submit

 

Additional Information

CRE-24734