Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Traffic Steering
    Steering Configuration

    Steering Configuration

    Steering Configurations control what kind of traffic gets steered to Netskope for real-time deep analysis and what kind of traffic gets bypassed. Moreover admins can configure a set of firewall apps to bypass processing using the Exceptions feature. It’s for endpoints using the Netskope Client and directs traffic from end users to the Netskope Cloud. A Netskope account steers thousands of apps by default, but to ensure the correct type of traffic is steered, you can modify the default steering configuration or create a new steering configuration. You can assign these configurations to either user groups or Organizational Units (OUs) for granular steering within your organization. Steering configurations apply to all platforms, but OU and Group settings are applied to the Netskope Client only.

    When enabling Dynamic Steering on a Steering Configuration, the behavior of the “On-Premise” steering changes depending on the enablement of the “Flexible Dynamic Steering” backend option, starting from R112.
    If Flexible Dynamic steering is enabled, Customers can configure the Steering Configuration to send “All Traffic” when the Netskope Client is “On-Premise”.
    If Flexible Dynamic Steering is not enabled, Customers are not able to send “All Traffic” when the Netskope Client in “On Premise”. If the option to send “All Traffic” on the “On-Premise” Steering Configuration section is unavailable please contact support@netskope.com.

    The Netskope Client offers comprehensive coverage when installed on managed devices and provides visibility and policy enforcement for devices that are both on- and off-premises (remote). The Netskope Client:

    • Performs posture checks to classify devices as managed or unmanaged based on admin-defined configurations.
    • Detects if a user is on-premises or remote and applies different steering configurations based on the location.
    • Provisions certificates to help with user identification when used with other traffic steering methods, such as GRE or IPSec.
    • Detects the presence of other traffic steering methods.
    • Generates user-facing notifications for security policy violations.

    General Guidelines

    When the Steering Configuration that applies to the Netskope Client is configured to steer “All Traffic”, the Netskope Client will be configured to steer the following traffic:

    • Port TCP 80 and 443, which will be sent directly to the Netskope Proxy
    • Any non-standard TCP port configured on the Steering Configuration under the “Non-Standard Ports” section for Web Traffic, which will be sent directly to the Netskope Proxy (remember that the traffic destined to those ports will not be inspected by Netskope Cloud Firewall, so ensure that the traffic sent to those ports is indeed web or proxied traffic, more info on /en/creating-a-steering-configuration/)
    • Any TCP and UDP port with the exception of default DNS and mDNS traffic (TCP/UDP 53 and UDP 5353). In order to steer and inspect DNS traffic a valid license for Netskope DNS Security, and a separate Steering Configuration option must be enabled, which goes beyond the scope of this document

    When creating or editing steering configurations, consider the following:

    • When creating a custom steering configuration, you can enable Dynamic Steering, and the default exceptions are populated in both on- and off-premise steering configurations.
    • When editing the default steering configuration (i.e., Default tenant config), there is no restore defaults functionality, so you must create or remove exceptions in on- or off-premises mode based on where you left off before enabling Dynamic Steering.
    • If you’re editing a configuration that steers All Traffic, note the following:
      • When you enable Dynamic Steering, the off-premises configuration, which steers All Traffic by default, inherits the exceptions.
      • When you enable Dynamic Steering, the on-premises configuration, which steers Cloud Apps Only by default, doesn’t inherit the exceptions. Netskope assumes you create exceptions differently when a user is on-premises.
      • When you disable Dynamic Steering, Netskope preserves the steering configuration based on the traffic type.
    • If you’re editing a configuration that steers Cloud Apps Only, note the following:
      • When you enable Dynamic Steering, the on-premises configuration, which steers Cloud Apps Only by default, inherits the exceptions.
      • When you enable Dynamic Steering, the off-premises configuration, which is All Traffic by default, doesn’t inherit the exceptions. Netskope assumes you create exceptions differently when a user is off-premises.
      • When you disable Dynamic Steering, Netskope preserves the steering configuration based on the traffic type.
    If Dynamic Steering is enabled on an existing Steering Configuration, all default exceptions are reinstated automatically. You need to reconfigure the exceptions according to your requirements after enabling Dynamic Steering.

    Steering Exceptions

    It is very important to understand that once the non-web traffic is steered to the Netskope Cloud and it reaches the Netskope Cloud Firewall, the latter ignores any Steering Exception defined in any Steering Configuration, with the exception of 2 Steering Exceptions types defined on the Default Steering Configuration (and only on the Default Steering Configuration):

    • Destination Locations – If the destination IP of the non-web traffic matches a Destination Location steering exception, the traffic is “bypassed” by the Netskope Cloud Firewall, so it will be egressing the Netskope Cloud bypassing any Policy evaluation
    • Application – If the non-web traffic matches a Custom Firewall Application defined as Application Steering Bypass (see /en/creating-a-firewall-app-definition-449298/), the traffic is “bypassed” by the Netskope Cloud Firewall, so it will be egressing the Netskope Cloud bypassing any Policy evaluation
    It is possible to log the non-web traffic that is “bypassed” in the Cloud, please refer to Configuring Cloud Firewall Steering Exceptions.

    About the Steering Configuration Page

    On the Steering Configuration page (Settings > Security Cloud Platform > Steering Configuration), you can:

    1. Choose whether all traffic steering configurations must apply to Organizational Units (OUs) or user groups. When configuring OUs and user groups, consider the following:

      • If a user is a member of multiple groups, the order placement of User Group steering configurations determines what’s used to resolve conflicts. The first group determines which group steering configuration Netskope uses when there is a group conflict. Conflict resolution is only applicable to User Groups.

      • In a multi-user deployment mode, if the logged in users belong to different OUs or user groups, the Netskope Client applies the steering configuration corresponding to the first logged in user. Ensure all the users belong to a single OU or User Group for a multi-user machine.

      • For users in OUs or user groups that aren’t included in a custom steering configuration, Netskope applies the default steering configuration (i.e., Default tenant config). If you want to steer different types of traffic for different OUs or User Groups, create multiple custom steering configurations.

      The Steering Configuration Apply To window

    2. Choose whether you want to log bypassed traffic (i.e., steering exceptions) in Skope IT Events. This setting applies to all steering configurations.

      – If you enabled dynamic steering and Netskope detects that the user is off-premises, Netskope client bypasses the traffic and doesn’t log it.
      – If you bypassed traffic locally on the device, then the traffic won’t be sent to Netskope and logged in Skope IT events. You can only see logs for traffic bypassed in Netskope Cloud.

      The steering configuration Log Bypassed Traffic window

    3. Manage how certain errors that Netskope observes in HTTP/HTTPS traffic are handled by blocking or bypassing them. To learn more: Managing Error Settings.

    4. Choose the action taken when Netskope adds new predefined certificate pinned apps or updates to existing ones. To learn more: Configuring the Steering Preferences.

    5. Search the steering configurations by a name, OU, or user group.

    6. Create a new steering configuration.

    7. View a list of steering configurations. For each configuration, you can see the OU or user group and the steering settings.

    8. Click The Netskope Drag icon. to move the steering configuration. The steering configuration placed at the top takes priority over all other configurations.

    9. Click The More icon. to choose one of the following options:

      • View Steered Items: Click to go to the Steered Traffic tab where you can add applications and steer their traffic to Netskope for deep analysis via Real-time Protection policies. To learn more: Adding Steered Items.

      • View Exceptions: Click to go to the Exceptions tab where you can add exceptions for the steering configuration and bypass the traffic from Netskope.

      • Edit Configuration: Modify the steering configuration and its settings. To learn more: Creating a Steering Configuration.

      • Clone: Create a copy of the steering configuration.

      • Disable/Enable: Enable or disable the steering configuration. You can’t disable the Default tenant config.

      • Delete: Delete the steering configuration. You can’t delete the Default tenant config.

      The Steering Configuration page.

    Audit Logs for Steering Configuration

    Navigate to Audit Logs under Settings > Administration to check logs for all intentional or accidental changes such as create, modify, or delete performed in Steering Configuration.

    On the Audit Log page, click the View Details option and it displays Audit Log Details.

    A few examples:

    • If you edit a few details in Steering Configuration, the Audit Log Details window displays:

    • When you create a new Steering Configuration:

    • When you delete an existing Steering Configuration:

    In this Topic
    • Steering Configuration