Software Secure Workload
Activity Configure

Configuring IP traffic for Agent Communications

A typical configuration for most will be to have a perimeter firewall and possibly a proxy between the agents (workflows) and Secure Workload SaaS.

Each customer (tenant) is assigned to a particular SaaS cluster. You can find the IP addresses of that cluster under Manage > Service Settings > IP Addresses > Service IPs..

You should allow the following IPs while configuring your firewall or proxy.

  • Allow outbound port 443 over TLS/HTTPS.

  • If a decrypting proxy is being used; configure proxy bypass and SSL/TLS bypass for those IPs.

  • If a transparent proxy is being used; you must route the specific SaaS IP addresses and configure the bypass rules. Agents cannot do automatic HTTPS redirection.


 

Ensure that the outbound firewall rules allow traffic to flow to the destination metadata collector IPs.


 

You can now edit the outbound gateway IP addresses on the user interface. This functionality allows the allowed metadata traffic originating from your workloads to their destination.