3.6 3.5 3.4
3.6 3.5 3.4

On-Prem: Enable HTTPS Proxy Server

HTTPS proxies encrypt and secure communication traffic during scans. When direct network access to scanning targets is not possible, an HTTPS proxy can be leveraged to scan the external target’s assets.

In order to enable HTTPS Proxy server support, perform the following steps to update the scheduler service on each backend and scan node:

  1. Open $agilesec_install_dir/config_envs/scheduler for editing.

  2. Add the variable HTTPS_PROXY and set with your proxy information.

    1. HTTPS_PROXY="<proxy url>:<proxy port>"

  3. Add the variable NO_PROXY and list each node’s internal address to ensure internal traffic does not route through the proxy:

    1. NO_PROXY=<node hostname 1>.<analytics_internal_domain>,<node hostname 2>.<analytics_internal_domain>,...

    2. 3-Node example: NO_PROXY="frontend-1.kf-agilesec.internal,backend-1.kf-agilesec.internal,backend-2.kf-agilesec.internal"

  4. Configured changes will be used next time a scan is executed.