Using CASB Inline with Hybrid Policies

Hybrid customers can enable CASB Inline to secure managed cloud application traffic for roaming users.

When enabled, traffic matching a managed cloud app is forwarded from the Cloud Security Gateway (CSG) proxy to the CASB Inline data plane for inspection and policy enforcement.

Note: Previously, CASB Inline was available only for cloud-only (Web Direct) policies.

Enabling CASB Inline for a hybrid policy

  1. Navigate to Web Security > Policies and select your hybrid policy.
  2. On the Cloud Apps tab, enable the CASB Inline toggle.
Note: Only one CASB mode can be active per policy. If CASB coexistence (PAC file sharing) is enabled, disable it before enabling CASB Inline.

Figure: CASB Inline toggle on the Cloud Apps tab


Screenshot showing the CASB Inline toggle on the Cloud Apps tab for a hybrid policy

Policy precedence

  • FSM policy rules take precedence. If a managed app is blocked by an FSM category or rule, traffic is blocked by the proxy and not forwarded to CASB Inline.
  • For all other managed app requests, the Hybrid Policy Engine forwards traffic to CASB Inline.
  • Category-based blocking, file-type blocking, and cloud-based DLP are skipped by the proxy for managed app traffic — CASB Inline handles these.

Limitations

  • Roaming users only — on-premises locations behind a Web Content Gateway (WCG) are not supported in this release.
  • Sanctioned apps only — unsanctioned CASB (Cloud App Filters for blocking/allowing by risk level) is not supported in hybrid mode.
  • A PCEP endpoint (F1E/F1A) is required on the user's device.