Introduction
This guide provides a comprehensive overview of how to integrate Forcepoint CASB with Forcepoint Web Security Cloud using two supported deployment models: Single‑Agent Integration and Dual‑Agent Integration. It helps you understand how each integration model works, the configuration changes required in both portals, and the prerequisites needed to ensure seamless traffic steering and consistent policy enforcement across CASB and Web Security Cloud.
- Single‑Agent Integration uses a single endpoint agent (F1E or F1A) or an agentless deployment to manage and steer both web traffic and managed cloud application traffic. In this model, all traffic flows through the Web Security Cloud proxy, which forwards CASB‑managed application traffic to CASB via inline proxy integration. This method is recommended for new users.
- Dual‑Agent Integration enables the coexistence of the SmartEdge Agent (SEA) with the F1E agent. This configuration is required when you need SEA to handle CASB‑managed application traffic while agent continues to manage broader web security cloud functions. If you are considering this model for new deployments, we recommend working with Forcepoint Technical Support or Professional Services to ensure that this approach is the right fit for your environment.
Together, these integration models offer deployment flexibility for different environments and provide unified visibility, consistent security controls, and optimized traffic handling for both web and cloud applications.