This document describes the steps to bypass traffic in Secure Web Appliance (SWA).
Cisco recommends that you have knowledge of these topics:
Cisco recommends that you have these tools installed:
This document is not restricted to specific software and hardware versions.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
In SWA, there are three different concepts of bypassing a traffic from reaching the SWA which depends on your Proxy deployment (Explicit or Transparent Deployment), or from being analyzed and scanned by the SWA. Here are a brief over view of these three concepts:
Image - Comparison Chart
Bypass procedures vary depending on your proxy deployment model. Here is a brief overview of each type:
To Bypass the Traffic in the Explicit Deployment, you must configure the Client to not forward the web request for the desired URLs to the SWA. As shown in this network diagram, some of the traffic are directly going to the Firewall or the Default Gateway to bypass the SWA (Path number 2).
Image - Bypass the Traffic in Explicit Deployment
Depends on your explicit proxy deployment, you can exempt some URLs to redirected to the SWA.
| Explicit Proxy Configuration |
Steps to exclude URLs from reaching the SWA |
PAC File Configuration |
Depends on how you configured your PAC file, you can define the exception list and set the action to DIRECT. Here are some samples to bypass the private IP address from reaching the SWA This is an Example to Bypass the traffic to www.cisco.com from redirecting the SWA This example is to bypass all the sub-domains of cisco.com from redirecting the SWA |
Browser Configuration ( Microsoft Edge, Internet Explorer, Google Chrome) |
Step 1. In the Start Menu, type Internet Options and press Enter. Step 2. Navigate to Connections tab and click LAN Settings Step 3. Click on the Advanced Step 4. Define your desired URLs in the Exceptions section.
|
Browser Configuration (Mozila FireFox) |
Step 1. On the top right corner, click on the three bar menu and select Settings. Step 2. In the search bar, type proxy. Step 3. Define your desired URLs in the No Proxy for section.
|
Browser Configuration (Apple Safari) |
Step 1. On the top-left corner, click on the Apple icon and choose System Settings. Step 2. From the left panel navigate to Network and select the Network Interface you are using to access the Internet. Step 3. Click on the Details. Step 4. From the left panel, select Proxies. Step 5. Define your desired URLs in the Bypass Proxy Settings section.
|
Group Policy Configuration |
Depends on how you configured the Group Policy to push the proxy settings, you can define the exception list. |
You can bypass traffic in a transparent deployment using either the WCCP router or SWA Bypass settings. SWA Bypass acts at Layer 3, routing traffic to the default gateway and bypassing the appliance entirely, which prevents processing and the creation of separate sessions.
Image - Bypass the Traffic in Transparent Deployment
| Bypassing traffic Transparent Proxy Deployment |
Steps to bypass the traffic from reaching the SWA |
SWA Bypass Setting |
Step 1. From GUI, Choose Web Security Manager. Step 2. Select Bypass Settings. Step 3. Click Edit Proxy Bypass Settings. Step 4. You can enter the URL, IP address or adding a Custom URL Category to the list. Step 5. Submit and Commit the changes.
|
Redirect the Traffic From WCCP/PBR Router |
You can configure source or destination IP address in your WCCP or Policy Based Router (PBR) to not redirect some traffics to the SWA. |
If the traffic is hitting the SWA and in order to reduce the load on the SWA to due to the privacy concerns you do not want the traffic for some URLs being inspected by the SWA, use these steps.
| Steps |
Steps |
| Step 1. Create a Custom URL Category for the URLs. |
1.1. From GUI, Choose Web Security Manager and then click Custom and External URL Categories. 1.5. From List Order, choose the first category to position on top. 1.6. From Category Type drop-down list, choose Local Custom Category. 1.7. Add desired URLs in the Sites Section. 1.8. Submit.
|
| Step 2. Create an Identification Profile to exempt traffic from Authentication. |
2.1. From GUI, Choose Web Security Manager and then click Identification Profiles. 2.7. In the User Identification Method section, choose Exempt from authentication/ identification. 2.8. In the Define Members by Subnet, leave this field blank to include all Client IP address unless you would like to Pass Through the traffic for a certain IP addresses. 2.9. From Advanced section, choose Custom URL Categories.
2.10. Add the Custom URL Category that was created on Step 1. 2.11. Click Done. 2.12. Submit. |
| Step 3. Create a Decryption Policy to pass through traffic. |
3.1. From GUI, Choose Web Security Manager and then click Decryption Policy. 3.2. Click Add Policy to add a Decryption Policy. 3.3. Use the Enable Policy check box to enable this policy. 3.7. From the Identification Profiles and Users, choose the Identification Profile that you created in Step 2. 3.8. Submit.
3.9. In the Decryption Policies page, under URL Filtering, click on the link associated with this new Decryption Policy.
3.10. Select Pass Through as the action for the URL Category created on Step 1.
3.11. Submit. |
| Step 4. Create an Access Policy to allow Microsoft Updates traffic. |
4.1. From GUI, Choose Web Security Manager and then click Access Policy. 4.2. Click Add Policy to add an Access Policy. 4.3. Use the Enable Policy check box to enable this policy. 4.7. From the Identification Profiles and Users, choose the Identification Profile that you created in Step 2. 4.8. Submit.
4.9. On the Access Policies page, under URL Filtering, click on the link associated with this new Access Policy.
4.10. Select Allow as the action for the Custom URL category created for the URL Category created on Step 1.
4.11. Submit. 4.12. Commit changes. |
| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
30-Jul-2026
|
Recertification |
1.0 |
24-Apr-2026
|
Initial Release |