SAML authentication for explicit web proxy
requires Panorama and the Cloud Services plugin version 3.2.1 (and
later versions).
To simplify
configuration for SAML-based authentication for the explicit web proxy, the
firewall or Panorama automatically generates the following rules to allow the
necessary traffic. If you are using Panorama, you must select an individual
firewall to view the rules.
SWG-allow-vpc-dns-rule — Allows traffic from the zone where the
web proxy upstream interface is located to the primary and secondary DNS
server addresses for the web proxy.
The firewall also generates an anti-spyware profile,
SWG-DNS-Security-Profile, to allow the
required traffic.
The autogenerated rule
SWG-allow-vpc-dns-rule applies this
profile to the applicable traffic.
SWG-block-unsolicited-dns-rule —Blocks unauthorized traffic to the primary and secondary
DNS server addresses for the web proxy.
SWG-allow-outbound-auth-domain-rule — (Explicit proxy with SAML authentication only)
Allows traffic from the zone where the web proxy upstream interface is
located to the Cloud Services plugin.
The autogenerated rule
SWG-allow-outbound-auth-domain-rule
applies the hybrid-swg-authdomain-bypass
URL category to the applicable traffic.
The URL
category,hybrid-swg-authdomain-bypass
contains the necessary predefined entries for the required domains.