Prerequisites
- The device is enrolled and shows managed routing as Active.
- The organization inspection CA is trusted on the device.
- The Resource uses an exact DNS hostname and a supported protocol.
- The Resource is enabled, assigned to an online Resource Gateway, and has Automatic routing enabled.
- The Gateway can resolve and reach the destination and verify its certificate.
- The authenticated user or service account resolves to exactly one compatible destination credential.
Enable automatic routing
- Open the Resource and assign the Resource Gateway that can reach it.
- Add and test a destination credential.
- Turn on Automatic routing and save.
- Confirm the intended device has received the current managed-routing configuration.
- Use the Resource’s original client command.
Verify the route
Perform one harmless operation, then open Live → Resources and filter by the Resource. Confirm the expected user, device and process when available, originating product when recognized, protocol operation, outcome, and responsible policy. For a policy test, begin with a narrow monitor rule, then enforce a harmless block such as one test HTTP path or database command in non-production. The client should receive the policy identifier and configured message; the Live row should show the same outcome.Troubleshoot
Automatic routing cannot govern only one SQL command on an otherwise direct
database connection. The entire connection must first follow the Forge route;
the Gateway then evaluates each supported command on that connection.
See Forge for devices for enrollment and routing
health, and Protocols for protocol limits.