Configuring IP traffic for Agent Communications
A typical configuration for most will be to have a perimeter firewall and possibly a proxy between the agents (workflows) and Secure Workload SaaS.
Each customer (tenant) is assigned to a particular SaaS cluster. You can find the IP addresses of that cluster under
.You should allow the following IPs while configuring your firewall or proxy.
-
Allow outbound port 443 over TLS/HTTPS.
-
If a decrypting proxy is being used; configure proxy bypass and SSL/TLS bypass for those IPs.
-
If a transparent proxy is being used; you must route the specific SaaS IP addresses and configure the bypass rules. Agents cannot do automatic HTTPS redirection.
|
Ensure that the outbound firewall rules allow traffic to flow to the destination metadata collector IPs. |
|
You can now edit the outbound gateway IP addresses on the user interface. This functionality allows the allowed metadata traffic originating from your workloads to their destination. |