Netskope steering decision explainer
Paste a compact steering spec - mode, tunnel state, Fail Close, dynamic location, one flow, and the exceptions it matches - and walk the documented decision order to a verdict: steered, bypassed, blocked, or direct, with the why-ledger. Where the docs publish no rule (cross-family exception precedence), it says so instead of inventing one.
NetworkingPaste a spec, or press Example for the grammar.
API endpointGEThttps://ronutz.com/api/v1/netskope-steering-decision-explainerDocumented, not served. Opens the specification.
References
- Netskope docs: Configure a Steering Profile - the three traffic modes and their audiences; RFC1918 always bypassed by default; the Netskope-maintained cert-pinned bypass list
- Netskope docs: Creating a Steering Configuration - Fail Close behavior (domain/IP/cert-pinned exceptions applied, category exceptions blocked); the non-standard-port-accessed-by-IP pitfall and its FQDN+IP remedy
- Netskope docs: Enabling Dynamic Steering - On-Premises Detection Profiles, per-location traffic modes including None (no tunnel, exceptions not processed), per-location firewall/category exception sets
- Netskope docs: Certificate Pinned Applications - per-profile exception actions including Steer and decrypt at Netskope Cloud