As configured, your TMWS on-premises gateway can submit sample files to the Cloud Virtual Analyzer for further analysis, and can utilize the suspicious objects generated by the Cloud Virtual Analyzer and synchronized from Apex Central for threat detection. In addition, you can configure to integrate your on-premises gateway with Deep Discovery™ Analyzer (DDAn) deployed within your organization to defend against custom-defense APT attacks from malicious programs through HTTP/HTTPS traffic.
For each on-premises gateway, you can choose to use the Cloud Virtual Analyzer or integrate with DDAn to submit sample files. Once Custom Defense is enabled and configured, your on-premises gateway will submit sample files to the integrated DDAn, regardless of the Cloud Virtual Analyzer settings in the matched cloud access rules.
The suspicious objects generated by DDAn are only sent to each on-premises gateway that DDAn integrates with. The on-premises gateway will not upload these suspicious objects to other on-premises gateways deployed within your organization or to the TMWS cloud.
For the same suspicious object, its information is subject to the sources that come with the following priorities from high to low: Apex Central, Cloud Virtual Analyzer, DDAn.