HTTPS proxies encrypt and secure communication traffic during scans. When direct network access to scanning targets is not possible, an HTTPS proxy can be leveraged to scan the external target’s assets.
In order to enable HTTPS Proxy server support, perform the following steps to update the scheduler service on each backend and scan node:
-
Open
$agilesec_install_dir/config_envs/schedulerfor editing. -
Add the variable
HTTPS_PROXYand set with your proxy information.-
HTTPS_PROXY="<proxy url>:<proxy port>"
-
-
Add the variable
NO_PROXYand list each node’s internal address to ensure internal traffic does not route through the proxy:-
NO_PROXY=<node hostname 1>.<analytics_internal_domain>,<node hostname 2>.<analytics_internal_domain>,... -
3-Node example:
NO_PROXY="frontend-1.kf-agilesec.internal,backend-1.kf-agilesec.internal,backend-2.kf-agilesec.internal"
-
-
Configured changes will be used next time a scan is executed.