cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
142
Views
0
Helpful
1
Replies

SIG - Web Policy Issue?

We experience inconsistent user experience when using the internal network or on-network, there are times that we can access the site or not and no logs are captured. We are using AD users' identities only that shared information with roaming client. Roaming is working when off-network and hits the policy and has logs. All users are domain-joined. When in on-network we have tunnels going to umbrella. What could be the possible solution in on-network that should hit the same policy as when off-network? We also tried using DNS forwarder but the status is unable to resolve. Could the routing to the tunnels be the issue?

1 Reply 1

nbogdaje
Cisco Employee
Cisco Employee

Check your SWG backoff settings in the roaming computer settings. If you are backing off your roaming users SWG then you will need to use SAML to get the AD user info when going over the tunnels for web traffic.