Earlier this year we started using CDA for authentication mappings to our Ironport. Apparently the surrogate type we were using was not supported, and CDA was the solution for this.
Every so often I have noticed that if I search for a webpage (say a Cisco support topic) and I navigate to that 443 page it does not load. If I go back and click on some port 80 type page and immediately go back to the 443 page it will load.
It seems as if there is some sort of issue with the authentications/re-authentications for CDA getting passed to the WSA.
Any ideas of how to correct this behavior. Being that this is so random I'm not sure how to isolate it.