Cloud SWG POP Optimization Announcement: Shanghai (ACNSH1, ACNSH2) and Beijing (ACNBJ1, ACNBJ2)

Monday, 10 April 23 hours and 59 minutes
Complete
Complete

The maintenance is now complete. Thanks for your patience.

Underway

The scheduled maintenance is now underway. We'll keep you updated on our progress.

Scheduled

The Symantec Cloud SWG team is pleased to announce an optimization of our points-of-presence in Shanghai and Beijing to improve connectivity to certain web destinations. As a result, Symantec will decommission the current Shanghai and Beijing designations and IP ranges which will be replaced by new designations and IP ranges, as detailed below. Both old and new POPs are located in the same facilities, so there is no geographic change. We apologize for any inconvenience this may cause.

Carefully review the information below to avoid disruption of service.

New POPs

  • Designations: ACNSH2, ACNBJ2
  • General Availability Date: April 10, 2023

POPs Being Decommissioned

  • Designations: ACNSH1, ACNBJ1
  • Shutdown Date: April 28, 2023

New POP Ingress IP Addresses (all Access Methods):

  • 40.72.119.208 - NEW - April 10, 2023 (Shanghai, ACNSH2)
  • 52.131.103.144 - NEW - April 10, 2023 (Beijing, ACNBJ2)

Egress IP Addresses:

NEW - April 10, 2023 (ACNSH2)

  • 40.72.119.208/28
  • 40.72.119.224/28
  • 52.130.200.0/28
  • 52.130.200.128/28
  • 52.130.200.144/28
  • 52.130.200.16/28
  • 52.130.200.176/28
  • 52.130.200.192/28
  • 52.130.200.208/28
  • 52.130.200.224/28
  • 52.130.200.240/28
  • 52.130.200.48/28
  • 52.130.200.64/28
  • 52.130.200.96/28

NEW - April 10, 2023 (ACNBJ2)

  • 52.131.103.144/28
  • 52.131.113.128/28
  • 52.131.113.144/28
  • 52.131.113.176/28
  • 52.131.113.192/28
  • 52.131.113.208/28
  • 52.131.113.224/28
  • 52.131.113.240/28
  • 52.131.113.48/28
  • 52.131.113.80/28
  • 52.131.114.0/28
  • 52.131.114.16/28
  • 52.131.114.32/28
  • 52.131.114.48/28

TO BE RETIRED AFTER April 28, 2023:

  • 163.228.65.32/28 - TO BE RETIRED - After April 28,2023 (ACNSH1)
  • 163.228.65.48/28 - TO BE RETIRED - After April 28,2023 (ACNSH1)
  • 163.228.65.64/28 - TO BE RETIRED - After April 28,2023 (ACNSH1)
  • 163.228.65.80/28 - TO BE RETIRED - After April 28,2023 (ACNSH1)
  • 163.228.65.96/28 - TO BE RETIRED - After April 28,2023 (ACNSH1)
  • 159.27.94.48/28 - TO BE RETIRED - After April 28,2023 (ACNBJ1)
  • 159.27.94.64/28 - TO BE RETIRED - After April 28,2023 (ACNBJ1)
  • 159.27.94.80/28 - TO BE RETIRED - After April 28,2023 (ACNBJ1)
  • 159.27.94.96/28 - TO BE RETIRED - After April 28,2023 (ACNBJ1)
  • 159.27.124.16/28 - TO BE RETIRED - After April 28,2023 (ACNBJ1)

Required Action

Prior to April 10, 2023:

  • Firewall rules regulating connectivity to/from your network to Cloud SWG should be adjusted to allow traffic to pass to the new IP networks listed above.
  • Third party applications that regulate connections by source IP address should be updated to accept connections from the new egress IP networks listed above to ensure traffic proxied through Cloud SWG can reach the applications.
  • Auth Connector must be able to communicate with all egress ranges listed above on TCP 443, where applicable.

Failure to make these changes could prevent users from connecting to Cloud SWG, accessing third party web applications, or authenticating against the service using the Auth Connector (where applicable).

  • IPsec: Customers must update their tunnel configurations to point to the new ingress IP address before April 28, 2022. This change can be made after April 10, 2023.
  • WSS Agent, SEP Agent: Agent traffic will be automatically redirected to the new POP. No customer action is required.
  • Explicit proxy and proxy forwarding: Customers explicitly directing traffic to proxy.wss.broadcom.cn will be automatically redirected to the nearest new POP on April 21, 2023. No customer action is required.
  • Regardless of the connection method, any configuration pointing to a specific POP hostname or IP address (not recommended) must be manually switched to the new POP prior to the decommissioning date to avoid an outage.

Please visit these KB articles for a full list of IP networks used by Cloud SWG:

Questions?

If you have further questions regarding this announcement, contact Technical Support. Support information is located at: https://support.broadcom.com/security

For real time updates and status visit and subscribe to Broadcom Service Status: https://status.broadcom.com

Began at:

Affected components