Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Integrations
    IPSec and GRE
    Netskope Forward Proxy over IPSec/GRE with Azure AD SAML Auth
    Bypass SAML Forward Proxy Authentication Methods

    Bypass SAML Forward Proxy Authentication Methods

    There are use cases where SAML Auth will need to be bypassed for traffic steered via the IPSec or GRE tunnel.

    Netskope has three methods of bypass:

    • Domain Bypass: Like www.<finance website>.com and www.<finance website>.com. Wildcards (like *.tld) are not valid.
    • Web Category Bypass: Like Finance/Accounting.
    • Source IP Address – User IP / Egress IP: Like Guest Wi-Fi, Server Subnets

    The three options can be configured from the tenant under Settings > Security Cloud Platform > Forward Proxy > SAML.

    In this Topic
    • Bypass SAML Forward Proxy Authentication Methods