A proxy server acts as an intermediary gateway between a local network client or endpoint and another server, such as the Internet. It makes service requests on behalf of a local client and allows the client to make network connections to network services outside its own network.
If your enterprise uses an HTTPS proxy server to allow endpoints on your network to access the Endpoint Security (HX) server or the Internet, you must configure your proxy server to allow communication between the agent and the Endpoint Security (HX) server. Your proxy server will also allow the Trellix DTI cloud to download malware and antivirus content updates and software updates to your agent.
This section describes how to use the Agent Policy Service to configure a proxy policy for host sets in your environment.
Note
The Endpoint Security Agent (HX) requires an Internet connection to download malware definitions and other agent updates.
Direct HTTPS proxy support for Internet access is supported in Endpoint Security Agent (HX) version 25 or later.
If an agent tries to communicate with the Endpoint Security (HX) server through a proxy where SSL inspection is enabled, then the proxy provides a different SSL certificate than the Endpoint Security (HX) server, and the agent cannot communicate with the server. In these circumstances, you receive a 1235, MX_API_SSL_EVERIFY, "SSL verify error" error message in the agent logs. When SSL inspection is enabled on the proxy, agents can still communicate with the server as long as they don't use the proxy to do so. If SSL inspection is not enabled on the proxy, then agents can communicate through the proxy without errors.
Proxy server types
The Agent Policy Service allows you to select from three configuration types when setting up an HTTPS proxy server for the agents on your host endpoints: none, system, and manual.
Type Value | Description |
|---|---|
| No proxy server. Proxy switch is disabled. |
| Configure your local system as a proxy server. NoteWeb traffic is not blocked for contained Windows endpoints that have a proxy. Host containment works only at the IP protocol layer. If your host endpoints use a proxy server that has been added to the containment whitelist, a contained host will still be able to send and receive Web traffic and other traffic. If you are using an agent proxy and you want to be able to contain compromised hosts, you must set up the proxy server with a separate IP address that can only be used to reach the Endpoint Security (HX) server. Use the Endpoint Security (HX) Web UI to add the proxy server IP address to the Allowed IP Addresses on the Containment Settings page. See the Endpoint Security User Guide for more information. |
| Manually configure a remote system as your proxy server. NoteWhen the proxy |
Using the Web UI or the API, you can set up a direct HTTPS proxy server that allows the agents on your host endpoints to access the Endpoint Security (HX) server and the Internet. Set up your proxy server using your Windows, OS X, and Linux operating system proxy settings or manually enter your proxy server settings.
Trellix recommends using your system proxy settings to avoid breaking the provisioning between your Endpoint Security (HX) server and agent. Use care when manually supplying proxy settings. If your proxy settings are not correct and your agent and Endpoint Security (HX) server are on different networks, you may disrupt or break the communication between your Endpoint Security (HX) server and agent.
Note
You must configure your HTTPS proxy server through the Web UI before installing or upgrading the Endpoint Security Agent (HX) on your host endpoints.
Proxy server settings and default values
By default, HTTPS proxy support is disabled. The table below defines the proxy settings and default values. Use these settings to configure your proxy server.
Proxy Setting | Description | Default Value |
|---|---|---|
| Enable or disable the agent web proxy. Valid values include true (enable) and false (disable). |
|
| Enable or disable local and simple host exclusions from the agent web proxy support. |
|
| A list of hosts that should be excluded from proxy support. |
|
| The user password required to authenticate access to the proxy server. The proxy password must have a minimum of six alphanumeric characters. | |
| The HTTPS proxy server port number (optional setting). |
|
| If the proxy server connection fails, the agent will wait for this specified time period (in seconds) before attempting to reconnect with the proxy server. The default value is 1200 seconds. |
|
| The HTTPS proxy host or IP address. NoteWhen the proxy | --- |
| The type of HTTPS proxy server configuration setting used by your host endpoint. Options include |
|
| The username required to authenticate access to the proxy server. |
Admin access to the Endpoint Security (HX) server or the endpoints
Endpoint Security Agent (HX) software version 25 or later (Downloaded from the Endpoint Security (HX) server and transferred to the endpoint)
Note
You must download the Endpoint Security Agent (HX) software package from your Endpoint Security (HX) server to ensure the installation package obtains the agent configuration file and certificates required to provision your server with the agent.
This section covers the following topics: