A macOS user experienced persistent rendering issues on specific websites, including LinkedIn.com and business.reddit.com, despite having configured Traffic Steering and Split Tunneling to bypass these sites outside of Cisco Secure Client. The affected websites displayed incorrectly formatted pages with broken functionality, even after the domains were added to the exception list for bypass.
Cisco Secure Access (formerly Umbrella)
Cisco Secure Client
macOS client device
Affected websites: LinkedIn.com and business.reddit.com
The resolution involved multiple steps to address both the client version compatibility and the CDN blocking issues:
Upgrade the Cisco Secure Client from version to latest to ensure compatibility and resolve known issues.
This step resolved the issues with LinkedIn.com but did not address the problems with business.reddit.com.
Add the required CDN domains to the Do Not Decrypt (DND) list within the security profile to prevent JavaScript injection that interferes with page loading:
Navigate to the security profile configuration and add these domains to the DND list:
cdn.prod.website-files.com
cdn.intellimize.co
cdn.cookielaw.org
cdn.segment.com
Ensure that JavaScript files are not being blocked by file type controls within the "Internet Security Profile ACA Normal" security profile. Verify that "js" file types are not restricted, as this can interfere with proper website functionality.
Create specific rules to include Reddit and Box applications as destinations rather than relying solely on domain-based exceptions. This approach provides more comprehensive coverage for applications that utilize multiple CDN services.
Configure application-based rules to handle the complex CDN requirements of modern web applications more effectively than individual domain exceptions.
The issue was caused by two primary factors:
First, the outdated Cisco Secure Client version 5.1.9 had compatibility issues that were resolved in version 5.1.14, which addressed the LinkedIn.com rendering problems.
Second, modern websites like business.reddit.com depend on multiple CDN services to deliver content, scripts, and functionality. While the main domain (business.reddit.com) was properly configured for bypass through Traffic Steering and Split Tunneling, the associated CDN domains were still being processed through Cisco Secure Access. This caused JavaScript injection and potential blocking of essential CDN resources, resulting in incomplete page rendering and broken functionality. The decrypt and inspect functionality of the security profile was interfering with the JavaScript delivery from these CDN sources, preventing proper page assembly.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
20-Jul-2026
|
Initial Release |