Enable Proxy Configuration

If the appliance is behind a Proxy server, you need to enable a Proxy configuration using the ENABLE PROXY menu option. Provide details in the Proxy user and password fields to authenticate to your proxy server.

The Network Passive Sensor uses the Secure Sockets Layer (SSL) protocol (HTTPS and WebSocket) to secure its connection to the Qualys web application, similar to how a web browser does to a secure web server. If the Qualys connection must pass through a Proxy server, then you must enable the Proxy option on the appliance. This configuration redirects Qualys outbound connections through the Proxy server.

Your Proxy server must be configured to tunnel or pass through the SSL session (HTTPS and WebSocket) to the Qualys Cloud Platform. This ensures a secured end-to-end connection. SSL bridging or tunnel termination must not be configured in your Proxy server when supporting the Network Passive Sensor.

Perform the following steps to configure the appliance with Proxy support:

  1. Go to SETUP NETWORK menu option.
  2. Press the Down arrow until the ENABLE PROXY menu option appears. Then press ENTER to continue.
  3. When the CONFIG PROXY PARAMETERS prompt appears, press ENTER to continue or press the Up arrow two times to quit this procedure and return to the SETUP NETWORK menu option.

Enter Parameters

Enter Proxy parameters using the Up and Down arrows to scroll through characters.

  1. When the PROXY HOST prompt appears, enter the Proxy server’s FQDN/IP address. The gateway IP address appears in the screen by default. Use the LCD interface to enter an FQDN/IP address, and then press ENTER to continue.

    IP addresses are allowed in dotted decimal format, for example: 176.34.20.5

    Supported characters for FQDN: Uppercase letters, numbers, dot (.) and hyphen (-).

  2. When the PROXY PORT prompt appears, enter the port number assigned to the Proxy server. Port '0443' appears by default. Confirm that the port number shown is correct or enter a different one, if necessary. When the correct port number appears, press ENTER to continue.

    Supported Characters: numbers only

  3. When the PROXY USER prompt appears, enter the username for Proxy authentication. If authentication is not enabled at the Proxy level, leave the entry field blank. Press ENTER to continue.

    Supported Characters: Lowercase letters, uppercase letters, numbers, and these special characters: _-\@.

  4. When the PROXY PASS prompt appears, enter the password for Proxy authentication. If authentication is not enabled at the Proxy level, leave the entry field blank. Press ENTER to continue.

    Supported Characters: Lowercase letters, uppercase letters, numbers, and these special characters: _-\/|~!?@#$%^&*+=(){}[]<>:;"`,. (including dot).

  5. When the REALLY ENABLE PROXY? prompt appears, press ENTER to continue. Or press the Up arrow two times to quit this procedure and return to the SETUP NETWORK menu option.

  6. Review the confirmation messages. The ENABLING PROXY SUPPORT message appears followed by other messages while the Network Passive Sensor attempts to make a connection to the Qualys Cloud Platform using the new configuration.

Upon success the APPLIANCE NAME–IP ADDRESS message appears and the configured proxy is now confirmed working and being used.

Interface - Enable Proxy

The LCD interface to enable Proxy support is shown below.

InterfaceEnableProxy.

Update Proxy Settings

Once a Proxy configuration is enabled, the Proxy settings are stored on the appliance. You can change or disable these settings at any time.

Perform the following steps to change Proxy parameters:

  1. Go to SETUP NETWORK menu option.
  2. Press the Down arrow until the CHANGE PROXY PARAMS menu option appears. Then press ENTER to continue.
  3. Follow the prompts and messages in the LCD interface to change the existing Proxy parameters. Existing parameters are displayed on each screen. Change and confirm each parameter. If a parameter has not changed, press ENTER to view the next parameter.
  4. When the REALLY ENABLE PROXY? prompt appears, press ENTER to continue. Or press the Up arrow two times to quit this procedure and return to the SETUP NETWORK menu option.
  5. Review the confirmation messages. The ENABLING PROXY SUPPORT message appears followed by others. 

Disable Proxy Parameters

Perform the following steps to disable Proxy parameters:

  1. Go to SETUP NETWORK menu option.
  2. Press the Down arrow until the DISABLE PROXY menu option appears. Then press ENTER to continue.
  3. When the REALLY DISABLE PROXY? prompt appears, press ENTER to continue. Or press the Up arrow two times to quit this procedure and return to the SETUP NETWORK menu option.
  4. Review the confirmation messages.

Interface - Change Proxy Parameters

InterfaceEnableProxy

Confirm Configuration

The message APPLIANCE NAME–IP ADDRESS appears if the Network Passive Sensor successfully connected to the Qualys Cloud Platform using the new configuration.

The USER LOGIN prompt appears if the Network Passive Sensor successfully connects to the Qualys Cloud Platform. However, the appliance has not been activated. See Step 1 in the Get Started section and follow the instructions to activate the appliance.

An appliance configuration error appears if the Network Passive Sensor fails to connect to the Qualys Cloud Platform. An error may occur because the Proxy parameters you entered are incorrect, or they do not match the Proxy configuration on your network. Refer to the Troubleshooting section for resolving this issue.

Related Topic

Troubleshooting