How do I chain WebMarshal to an upstream proxy server?


This article applies to:

  • WebMarshal
  • Third party proxy servers

Question:

How do I chain WebMarshal to an upstream proxy server?

Procedure:

This article explains the steps required to chain WebMarshal to an upstream proxy server. For details of configuration of other proxy servers, refer to the proxy server's documentation.

The upstream proxy server can be running on any platform. If the upstream proxy is a Windows application, WebMarshal can sometimes be installed on the same physical server (depending on load and other prerequisites).

The following steps are required when chaining WebMarshal to an upstream proxy server:

  1. Chain WebMarshal to the upstream proxy server.
  2. Restrict access on the upstream proxy server so that only WebMarshal has permission to connect directly to the proxy server.
  3. Ensure WebMarshal can authenticate to the upstream proxy.

These steps are described in greater detail below.

Chain WebMarshal to the upstream proxy server

  1. Open the WebMarshal Console.
  2. From the Tools menu, click Global Settings and select the Internet Connection item.
  3. Select Forward the request to a specified upstream proxy server, and fill in the server name and proxy port of the upstream proxy server.
  4. Check the box, Use the following account, and enter the details of the user account. Be sure to use the correct syntax, e.g. domain\username.
  5. Click OK or Apply.
  6. Commit configuration.

    Note: The account that you specify in the WebMarshal Proxy Wizard must have the appropriate permission on the upstream proxy server.

Restrict access on the upstream proxy server

Typically when chaining WebMarshal to an upstream proxy server, you will want to restrict who can connect directly to the upstream proxy server. If you do not apply any restrictions, users can change the settings in their Internet browser and bypass the WebMarshal server, resulting in unrestricted access to the Internet.

Enable basic authentication on the upstream proxy server

If you configure WebMarshal to authenticate with an upstream proxy server using a specified user account, WebMarshal uses basic authentication to authenticate with the upstream proxy server. 

If the other proxy server is using Windows system calls for authentication (as WebMarshal does), you must enable Basic Authentication on the server.

Changing the port that the proxy server listens on

If WebMarshal is installed on the same physical server as another proxy server then you must ensure that they are listening on different ports. By default, WebMarshal listens on port 8080. This can be changed either during the installation of the WebMarshal Proxy or at a later date.

  • WebMarshal Proxy
To change the port that WebMarshal listens on: 
  1. Open the WebMarshal Console.
  2. From the Tools menu, select Global Settings and click the Ports and Authentication item.
  3. Edit the port/method you need to change, and change the port number to the desired port.
  4. Click OK, then commit configuration.

This article was previously published as:
NETIQKB28938
Marshal KB208

 


Last Modified 4/1/2020.
https://support.trustwave.com/kb/KnowledgebaseArticle10246.aspx