About the CloudSOC Integration
The
Web Security Service
is an integrated platform for Content Filtering, Threat Protection, DLP, and CASB deep-controls on cloud applications. The Symantec CASB platform, CloudSOC™, provides visibility to over 24,000 cloud applications plus over 60 attributes per
application. This enables scalable policy to control Shadow IT and cloud application access.Symantec
provides two CloudSOC integration solutions:- —A full secure web gateway (CASB GateletsWSS) solution plus integration with CloudSOC. After completing the one-timeWSS-to-CloudSOC integration, you can apply a combined policy enforcement to both platforms based on their respective configurations for all enabled applicationGatelets. Configure gatelet policies in CloudSOC. An increased number of web applications are available in policy editors. The remainder of this conceptual topic discusses the CASB Gatelet solution.
- —A CASB-only solution. ConfigureCASB GatewayWSSto identify and authenticate users and steer traffic to CloudSOC. Use CloudSOC for all gatelet configuration, policy, and data analysis. Consult the CloudSOC documentation for more information about this solution.
CASB Gatelets Topography
This topography assumes that you have obtained the CASB/CloudSOC product.

1
WSS
admin links the WSS
and CloudSOC accounts through a unique Integration ID. After launching CloudSOC from the Web Security Service
portal, the Admin enables application Gatelets—for example, Yammer, Google Drive, Box. Within the Gatelets are additional options, such as domains.2
WSS
receives a list of applications subject to CASB deep control.3
WSS
processes the policy; allows or denies the content; and adds entries to the access logs. WSS
uses these access logs for report generation.4
WSS
to the CloudSOC. The WSS
forwards the access logs to the CloudSOC Audit.5
WSS
portal; from there, launches the CloudSOC portal, which opens in a separate browser tab. In CloudSOC, users can generate reports.WSS
remains in sync with the Symantec Global Intelligence Network (GIN). Updates to the database occur each day.About the Traffic Evaluation Order
The following summarizes how
WSS
and CloudSOC prioritizes and evaluates traffic according to behavior. When possible, all behaviors are applied; the order addresses conflicts.This graphic demonstrates the policy and service order when the
WSS
receives a request. There are two scenarios—A
(no CASB Gatelet) and B
(redirected CASB Gatelet).- Denial and blocking based onpolicyconfigured in theAllow/DenyrulesWSSportal or from Universal Policy Enforcement (UPE) uploaded policy rules.For security and compliance reasons, explicit denials (for Content Filtering or Threat Protection) must be applied.
- Authenticationverifies the logged-in employee credentials.

- except for exemptions configured in theSSL InterceptWSSportal.Explicit SSL exemptions (for example, traffic toHealthcarecategories) are assumed to be defined by an organization's legal compliance.
- andMalware scanningSandboxing(with Advanced license).
- DLPscanning (with license).
- (if licensed) forwarding.Web Isolation
Applications routed to CloudSOC (CASB Gateway) over ICAP service.
- AuthenticationGatelets only work forWSSconnectivity methods where the end user must authenticate. For example, if an endpoint accesses through explicit proxy with no authentication, the CASB Gatelet policy enforcement is ignored.
- SSL InterceptionWhen enabled Gatelet matches,WSSforwards the traffic to CloudSOC, regardless ofWSSSSL Interception setting.
- CloudSOC performsDLPandMalwarescanning.As CASB Gatelets include Symantec content analysis and integration to Symantec DLP, material can be exempted fromWSSprocessing of those types.
The primary use cases for CASB Gatelets and Isolation are parallel. The Web Isolation service is focused on risky/unfamiliar sites, while CASB Gatelets are by definition for sanctioned applications. The population of sanctioned applications is smaller, thus this remains lower in the order because the account has enabled CASB.
Current Limitations
- O365 Gatelet—WSSglobal O365 SSL exemption is overridden for specific destinations.
- O365 Gatelet—File Sharing Block policy is ignored for the Desktop O365 Apps (OneDrive for Business, Word, Excel, Powerpoint).For example, if the file sharing block policy is in place and a user is attempts to share the files (already synced to OneDrive) to another user/group, the files are allowed instead of blocked.
- Google Drive Gatelet—Similar to the Office 365 issue, uploads from Google Drive are allowed despite blocking policy in pace.
- If you have modified O365 settings to disable theModern-Authenticationoption, clients withWSS Agentinstalled are not able to login to Outlook. The credential dialog repeats.
Integrate CASB?
- Proceed to Integrate With CloudSOC (CASB).