Web Security Service Announcement Chennai (GINCH) Maintenance

1 day and 12 hours
Complete
Complete

The scheduled maintenance has been completed.

Underway

Scheduled maintenance is currently in progress. We will provide updates as necessary.

Scheduled

The Chennai (GINCH) WSS site will undergo maintenance beginning on March 2, 2021 at 13:30 UTC for a duration of up to 36 hours.

• IP address changes will occur so it is imperative to adjust access control lists appropriately. • Carefully review the information below to avoid disruption of service.

Ingress IP Addresses The IP addresses you forward traffic to for filtering. The IP address must match the connection method. For example, do not connect IPsec tunnels to the IP addresses for WSS Agent.

IPsec / Proxy-forwarding / Explicit / SEP Agent:

• 148.64.6.164 - NO CHANGE

WSS Agent / Unified Agent :

• 148.64.7.164 - NO CHANGE • 168.149.169.164 - NO CHANGE • 34.93.130.164 - CAN BE RETIRED AFTER MAINTENANCE • 34.93.96.164 - CAN BE RETIRED AFTER MAINTENANCE • 34.93.163.164 - CAN BE RETIRED AFTER MAINTENANCE

Egress IP Addresses The IP addresses WSS will use to access content on your behalf and to deliver filtered content to your users. If you use application or firewall access control lists, add new IP ranges prior to the maintenance:

• 148.64.22.0/24 - NO CHANGE • 168.149.169.0/24 - NO CHANGE • 168.149.172.0/24 - NO CHANGE • 168.149.173.0/24 - NO CHANGE • 148.64.7.0/24 - NO CHANGE • 168.149.166.0/24 - NEW • 168.149.167.0/24 - NEW • 168.149.168.0/24 - NEW • 34.93.96.0/24 - CAN BE RETIRED AFTER MAINTENANCE • 34.93.163.0/24 - CAN BE RETIRED AFTER MAINTENANCE • 34.93.130.0/24- CAN BE RETIRED AFTER MAINTENANCE

Impact No impact to WSS traffic is expected during the maintenance window. However, it is important to make sure that your connection method aligns to the correct ingress IP address to avoid loss of connectivity. For example, following this maintenance IPsec connections will no longer be allowed to connect to IP addresses designated for WSS Agent (see ingress IP address detail above).

Required Action Failure to make these changes could prevent users from connecting to WSS, accessing third party web applications, or authenticating against the service using the Auth Connector (where applicable). • Firewall rules regulating connectivity to/from your network to WSS should be adjusted to allow traffic to pass to the IP networks listed above. • Third party applications that regulate connections by source IP address should be updated to accept connections from the egress IP networks listed above to ensure traffic proxied through WSS can reach the application. • Auth Connector must be able to communicate with all egress ranges listed above on TCP 443, where applicable.

Guidance for specific connection methods: • IPsec: No action is needed unless your tunnel is connecting to the incorrect ingress IP address (see Impact section above). • WSS Agent and Unified Agent: Update firewall rules to allow access to the new ingress IP address prior to the maintenance. User traffic will be automatically redirected by the service to the nearest alternate site during the maintenance window. • SEP Agent: User traffic will be automatically redirected by the service to the nearest alternate site during the maintenance window. • Explicit proxy and proxy forwarding: Customers directing traffic to proxy.threatpulse.net will be automatically redirected by the service to the nearest alternate site during the maintenance window.

WARNING: Any customer, regardless of connection method, with a configuration pointing to a specific site or IP address must manually failover to a secondary site during the migration window to avoid an outage. Explicit redirection should never point to an IP address. Only IPsec connections should be directed to IP addresses.

Support Questions? Contact technical support by visiting: https://support.broadcom.com/security.

For service status and maintenance updates visit and subscribe to Broadcom Service Status: https://wss.status.broadcom.com.

Began at: