---
title: "Configure a Symantec cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/1512862/Configure%20a%20Symantec%20cloud%20connector"
format: markdown
---
Symantec Web Security Service includes a number of advanced features including the following: Secure web gateway (SWG) Anti-virus scanning Sandboxing Web isolation Data loss prevention (DLP) Email security It enables you to enforce consistent security policies that protect your users and sensitive data as they create, access, and store it directly on the web. The Aryaka ANAP device seamlessly forwards all internet- and cloud-bound traffic directly to the Symantec cloud and the integrated solution does not require additional on-premises hardware, appliances, or software. Together, Aryaka and Symantec deliver a best-of-breed SD-WAN and security platform for enterprises accessing mission-critical internal applications and cloud-based applications. This topic describes Symantec-specific configuration settings for connecting your Aryaka ANAP device to the Symantec Cloud Security Platform using IKEv1 or IKEv2 IPSec VTI-based tunnels. The first section of this document describes the steps that must be performed in the Symantec ThreatPulse portal and the second section describes the steps that must be performed in MyAryaka. This information is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors  topic. This integration is supported for the following Aryaka ANAP topologies: Inline routed mode Edge routed mode The following table describes the configuration settings for both of these modes. Field Description Tunnel Destination Public IP of the Symantec cloud on which the tunnel terminates. To identify the closest Symantec datacenter, view  https://support.symantec.com/en_US/article.TECH242979.html  and select the corresponding IP as tunnel destination. Tunnel Source Interface The interface that is used for the tunnel. Use Interface IP for Tunnel Source  (edge routed mode only) If you select Yes, the tunnel source is the selected interface IP. If you select No, you must provide an IP from the same ISP that is associated with the interface selected in the Tunnel Source Interface field. Tunnel Settings Shared Key Enter the shared key that is configured for the IKE Gateway in Panorama. Public IP used for Tunnel Source  (inline routed mode only) Enter the public IP that is used to NAT the ANAP interface (M1/M2) IPs. Traffic Forwarding Select traffic that you want to forward to Symantec All internet traffic—Aryaka creates a default route in the  Route Controller  that routes all Internet traffic through the cloud connector tunnel. Specific traffic—You must manually create routes using the  Route Controller  to route specific traffic through the tunnel. If the ANAP supports segmentation, you must match the traffic by selecting the existing match rules on this page. If not, create a new one and reference it here. Drop Traffic to private subnet Allows or blocks private destination IPs that are routed over the tunnel. Operation on both tunnel failure Determines the behavior of the ANAP If both tunnels are down. Optionally, you can enable a secondary tunnel. The configuration is similar to that of the primary tunnel. Prerequisites Aryaka SmartServices subscription Symantec Web Security Service platform subscription Symantec configuration While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Log in to the ThreatPulse portal at  https://portal.threatpulse.com/login.jsp  using your registered account. Select the  Service  option from the top left drop-down list, then click  Add Locations . The Add Location page appears. Enter the following required information to define a location: Location Name—Enter the name of Aryaka site from which to connect. Access Method—Select the Firewall/VPN option. The following additional fields appear: Gateway IP—Enter the site’s public IP which is used to source the tunnel traffic. Preshared Key—Enter a preshared key of your choice. Estimated Users—Select the approximate numbers of users at the location. Country—Select the country for this site location. Time Zone—Local time zone of this site location. Click  Save . The location is created and is added to the Locations table. Symantec replicates the tunnel configuration to all its datacenter locations, which enables a site to connect to any of Symantec’s datacenters. MyAryaka configuration MyAryaka enables you to connect to Symantec cloud security service using a Cloud Security Connector. With an ANAP in either edge or inline routed mode, you can also control what traffic gets forwarded to Symantec. Understanding redundancy A site can have one or two tunnels to Symantec in active/standby mode and the following redundant tunnel configurations are supported. To configure the Palo Alto Networks connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right), then click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations (Add) tab page appears. In the Basic Information pane, verify that VTI is selected in the  Tunnel Type  drop-down list and that the  Enable IKEv2  field is set to No. Click  Add New  in the Tunnel Configurations section. The Tunnel Configurations tab page appears. Configure the tunnel in the Tunnel Details pane as follows: Click the  Tunnel Source Interface  drop-down list and select one of the following interface types to which the source IP is associated: M1 or M2—Both options appear if the site's ANAP has two ISPs. Only the M1 option appears if the site's ANAP has one ISP. F1 or F2—These options appear instead of M1 and M2 if the site's ANAP uses a fiber connection. Click the  Tunnel Source Type  drop-down list and select one of the following tunnel types: Use Interface IP—Select this option if you want to source the tunnel from the IP on the interface you chose in the previous step (that is, M1, M2, F1, or F2). Use Interface Aux IP—Select this option if you want to choose a different IP address that belongs to the ISP terminating on the interface. When selected, you must specify the source IP address in the Tunnel Source IP Address field that appears. Use FQDN—Select this option if you want to use an FQDN string instead of IP addresses. When selected, you must specify the fully qualified domain name in the Tunnel Source FQDN field that appears. Click the  Tunnel Destination Type  drop-down list and select one of the following: IP—Select this option if the Symantec endpoints are IPs. FQDN—Select this option if the Symantec endpoints are FQDN strings. Enter either the destination IP address or fully qualified domain name in the field that appears. If you selected IP, see  this article  to identify the closest datacenter and obtain the corresponding IP to use as the tunnel destination. Enter the shared key that you configured in the Symantec administrator portal. If ICMP keepalives are supported, configure the ICMP source and destination IPs provided by Symantec. Click  OK . The tunnel configuration is saved, and you are returned to the Tunnel Configurations (Add) tab page. Do one of the following: Click the  Save  icon to save your settings, then configure traffic forwarding as described in the next section. Click the  Submit  icon to create a change request and send it to Aryaka support for processing. To configure traffic forwarding Open the Cloud Security Connector (Add) page. It includes a Forward Traffic toggle that is disabled by default: After adding the required tunnels (as described in the previous section), click the  Forward Traffic  toggle to configure traffic match criteria that, when matched, forwards traffic to the Symantec connector. The following fields appear:  Forward Using—Drop-down list that includes the following options: Internet Policies—Select this if you want the ANAP to route those traffic to Symantec that only reaches the public interfaces after all other routing decisions have been made on the traffic. Local Policies—Select this if you want the ANAP to override all other routing decisions that could possibly make on that traffic. For example, traffic may be heading to ASN but you want to override that decision and send it to Symantec. If Forward Fails—Drop-down list that includes the following options: Blackhole—Select this if you want the ANAP to silently discard the traffic and send no response back to the sender. Prohibit—Select this if you want to send a code 13 ICMP administratively prohibited message back to the sender. Policy Name table with Add New button—Click  Add New  to define a local or internet policy (depending on your selection in the Forward Using field), then provide the following details in the Policy (Add) page that appears: Name—Enter a descriptive policy name. Zone—Select the zone where the traffic originates. Match Rules—Set the toggle to  Explicit , click  Choose  in the Match Rules Details table that appears, and then select a preconfigured mach rule from the  Name  drop-down list that matches the traffic you want to forward to Symantec. Click the  Submit  icon to create a change request and send it to Aryaka support for processing. In this topic Related topics Cloud connectors Route controller