IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: How to Set Up a Reverse Proxy

App Control: How to Set Up a Reverse Proxy

Environment

  • App Control Server (formerly CB Protection): All Supported Versions

Objective

How to set up a reverse proxy in App Control?
 

Resolution

  1. Make sure forwarding the port not terminate it. The default port is 41002.
  2. Verify the port configuration under the System Configuration – General tab.
  3. NAT the internal IP of the App Control Server to the DMZ and create a 1:1 firewall rule to allow only the external reverse proxy via the port
  4. Setup the reverse proxy from the Internet IP and port to forward to the NAT address in the DMZ.
  5. Make sure the traffic is all pass through, and not tampering/intercepting SSL
  6. Ensure there is no kind of TCP/IP connection sharing occurring for the agent-server communications.

 


Additional Notes

  • This solution is best effort
  • Support does not get involved in setting up a reverse proxy for customers as it's not a supported configuration and we do not test/QA in house with a reverse proxy
  • If assistance is needed with a reverse proxy setup, configuration or troubleshooting, please engage Professional Services or ask on the User eXchange
  • To summarize, it's HTTP over SSL over TCP, on ports 443 and 41002
  • SSL termination is not officially supported

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-12-2020
Views:
1377
Contributors