This topic describes the configuration of a web proxy for communicating with the RSA Cloud service and local ThreatGrid or GFI service. The settings in the Service Configuration view > Proxy tab set up communication by web proxy, which Security Analytics Malware Analysis can use to communicate with RSA Cloud for community analysis and sandbox analysis. Once the proxy is configured:
- Malware Analysis communicates via web proxy with the RSA Cloud for community analysis.
- Malware Analysis communicates via web proxy with the configured ThreatGrid or GFI sandbox service. Using a web proxy may negatively affect performance. ThreatGrid and GFI configuration sections in the General tab have an option to ignore the web proxy and communicate directly with the sandbox to improve performance.
Configure the Web Proxy
To configure the web proxy for Security Analytics Malware Analysis:
- In the Security Analytics menu, select Administration > Services.
- Select a Malware Analysis service, and select > View > Config.
- In the Services Config view, select the Proxy tab.
- To enable the proxy, select the Enabled checkbox.
- (Optional) To automatically detect proxy settings for the Security Analytics server, select the checkbox.
The proxy host and proxy port fields are autofilled.
- If you want to use a different proxy, enter the Proxy Host and Proxy Port.
- Enter the username and password used to log on to the proxy host.
- (Optional) Select SSL, if the proxy host communicates over SSL.
- Click Apply.
The settings are saved and become effective immediately.
Note: Malware Analysis does not support NTML web proxy authentication.