[Original Notification] Cloud SWG: “PAC File Mode” Traffic Redirector End-of-Life

Sunday, 1 October 23 hours and 59 minutes

The maintenance is now complete. Thanks for your patience.


The scheduled maintenance is now underway. We'll keep you updated on our progress.


Effective October 1, 2023, the “PAC File Mode” traffic redirection feature in Symantec Endpoint Protection (SEP) and Symantec Endpoint Security (SES) will transition to end-of-life (EOL) status.

The PAC File Mode integration allows SEP and SES to act as limited traffic redirector agents for Cloud SWG. This technology has been replaced by our more capable Tunnel Mode technology which is available in the “Web and Cloud Access Protection” policy of SEP and SES. We strongly recommend that you begin the process of migrating PAC File mode users to Tunnel Mode to avoid loss of log data.


Effective October 1, 2023:

  • PAC File Mode will no longer be supported
  • Transaction logs generated using PAC File Mode will no longer be visible or accessible

About Tunnel Mode

Customers who use the PAC File redirection method should plan to switch to Web and Cloud Access Protection Tunnel Mode before October 1, 2023. The recommended minimum versions are 14.3 RU5 or above for Windows, and 14.3 RU6 or above for macOS.

Tunnel Mode provides better reliability, security, and value:

  • Secures data in motion by establishing a secure tunnel from the endpoint to the nearest Cloud SWG data center
  • Handles traffic redirection for all ports, all protocols, and applications, including those that are not proxy-aware
  • Provides robust single sign on capabilities including SAML authentication
  • Supports additional cloud components including Cloud Firewall and ZTNA
  • Can be remotely disabled, reconnected and blocked via the Cloud SWG admin portal
  • Tamper proof
  • Can ignore traffic generated by defined application executables
  • CASB block notifications for real-time user coaching

About PAC File Mode

  • Previously referred to as SEP “WTR” (Web Traffic Redirection)
  • First available in SEP 14.0.1 MP1
  • Supports traffic redirection for traffic on TCP ports 80/443 for proxy-aware applications only
  • Can be affected by third party software such as AD policies
  • In certain cases, transactions generated by PAC File Mode will not be logged
  • Will be removed in a future SEP / SES release, and will be excluded from subsequent releases moving forward

The security of your organization is our highest priority, which is why it is important that you adopt our most current redirector technology which provides robust protection against emerging threats and environmental changes.

If you have any questions about how to adopt Web and Cloud Access Tunnel Mode, contact technical support by visiting: https://support.broadcom.com/security.

For service status and maintenance updates visit and subscribe to Broadcom Service Status: https://status.broadcom.com

Sincerely, The Symantec Team

Began at:

Affected components
  • Cloud Secure Web Gateway
    • Point of Presence (POP) - Americas
      • Buenos Aires, Argentina (GARBA)
      • Columbia, South Carolina (GUSCO)
      • Dallas, Texas (GUSDA)
      • Des Moines, Iowa (GUSDM)
      • Las Vegas, Nevada (GUSLV)
      • Los Angeles, California (GUSLA)
      • Mexico City, Mexico (GMXMC)
      • Montreal, Canada (GCAMO)
      • Portland, Oregon (GUSPO)
      • Sao Paulo, Brazil (GBRSP)
      • Toronto, Canada (GCATO)
      • Washington, DC (GUSAS)
      • Bogota, Colombia (GCOBO)
    • Point of Presence (POP) - APAC
      • Auckland, New Zealand (GNZAU)
      • Bangkok, Thailand (GTHBA)
      • Beijing, China (ACNBJ)
      • Delhi, India (GINDE)
      • Hanoi, Vietnam (GVNHA)
      • Hong Kong (GCNHK)
      • Islamabad, Pakistan (GPKIS)
      • Jakarta, Indonesia (GIDJK)
      • Kuala Lumpur, Malaysia (GMYKL)
      • Manila, Philippines (GPHMA)
      • Melbourne, Australia (GAUME)
      • Mumbai, India (GINMU)
      • Osaka, Japan (GJPOS)
      • Seoul, South Korea (GKRSE)
      • Shanghai, China (ACNSH)
      • Singapore (GSGRS)
      • Sydney, Australia (GAUSY)
      • Taipei, Taiwan (GTWTA)
      • Tokyo, Japan (GJPTK)
    • Point of Presence (POP) - Europe And The Middle East
      • Abu Dhabi, UAE (GAEAD)
      • Amsterdam, the Netherlands (GNLAM)
      • Ankara, Turkey (GTRAN)
      • Athens, Greece (GGRAT)
      • Brussels, Belgium (GBEBR)
      • Bucharest, Romania (GROBU)
      • Copenhagen, Denmark (GDKCP)
      • Dover, England (GGBDO)
      • Dubai, UAE (GAEDX)
      • Dublin, Ireland (GIEDU)
      • Frankfurt, Germany (GDEFR)
      • Helsinki, Finland (GFIHE)
      • Lisbon, Portugal (GPTLI)
      • London, England (GGBLO)
      • Madrid, Spain (GESTO) ( Previously Madrid, Spain (GESMA))
      • Manama, Bahrain (GBHMA)
      • Milan, Italy (GITMI)
      • Milan, Italy (GITMO)
      • Nicosia, Cyprus (GCYNI)
      • Oslo, Norway (GNOOS)
      • Paris, France (GFRPA)
      • Riyadh, Saudi Arabia (GSARI)
      • Stockholm, Sweden (GSESK)
      • Tel Aviv, Israel (GILTA)
      • Valletta, Malta (GMTVA)
      • Vienna, Austria (GATVI)
      • Warsaw, Poland (GPOWA)
      • Zurich, Switzerland (GCHZU)
      • Ljubljana, Slovenia (GSILJ)
      • Zagreb, Croatia (GHRZA)
      • Belgrade, Serbia (GSRBE)
      • Tallinn, Estonia (GEETA1)
      • Vilnius, Lithuania(GLTVI)
      • Riga, Latvia (GLVRI)
      • Dammam, Saudi Arabia (GSADA)
    • Point of Presence (POP) - Africa
      • Johannesburg, South Africa GZASO (Previously Johannesburg GZAJB)
    • Portal & Reporting
      • PAC File Management System (PFMS)