Use these settings when the Link Agent runs in a network that sends outgoing traffic through a forward proxy. This article covers the proxy options, proxy modes, and proxy exclusions, which you can set on the command line, in a Link Agent configuration file, or in the installers. For the endpoints and ports your proxy must allow, see Link Agent requirements.
- How the Link Agent connects through a proxy
- Using the host's proxy configuration
- Proxy configurations
- Proxy modes
- Proxy exclusions
How the Link Agent connects through a proxy
The Link Agent reaches the mabl cloud over one of two protocols. QUIC, over UDP port 443, is the faster one, but it can't pass through an HTTP proxy. When the Link Agent's traffic to mabl goes through a proxy, the agent connects over secure WebSocket (WSS) on TCP port 443, to the WSS endpoint listed in Link Agent requirements instead. Make sure your proxy allows that endpoint and api.mabl.com. See Link Agent requirements.
Proxies that inspect TLS traffic by re-signing it with your organization's certificate are supported for the tunnel connection. Every connection through the tunnel is also encrypted end to end between mabl and the Link Agent, so the proxy can't read the test traffic inside it.
Using the host's proxy configuration
If you give the Link Agent no proxy settings at all, it follows the proxy configuration of its host operating system: the Windows proxy settings, the macOS network proxy settings, or the http_proxy environment variables on Linux. That includes a PAC script, if the host uses one. The Link Agent sends all of its traffic the way the host configuration says, which is the same way a browser on that machine would.
- If the host's proxy needs a user name and password, add them with
--proxy-authorproxyAuthin the configuration file. No operating system's proxy configuration carries credentials. - If the host has a proxy configured that the Link Agent should not use, set the proxy mode to
none.
Proxy auto-configuration (PAC) files
To use a PAC script other than the host's, pass --pac-url {url} on the command line, or add PAC settings to a Link Agent configuration file. The configuration file also supports credentials for each proxy the PAC script names.
Proxy configurations
Use the following command-line options to configure a proxy explicitly:
| Option | Description |
|---|---|
--http-proxy or -h
|
The proxy server host address and port, in the following format: --http-proxy host:port
|
--pac-url |
The URL of a PAC script, as an alternative to --http-proxy
|
--proxy-auth or -i
|
Optional - if the proxy server requires authentication, a username and password in the following format: --proxy-auth username:password
|
--proxy-mode or -y
|
Optional - which traffic uses the proxy. See proxy modes for more details. |
--proxy-exclude |
Optional - IP addresses, CIDR ranges, hosts, or domains that outgoing Link traffic reaches directly. See proxy exclusions for more details. |
The same settings are available in a Link Agent configuration file. The Windows installer and the Linux and macOS installer also ask for them while they install.
Proxy modes
Use the --proxy-mode or -y option, or proxyMode in the configuration file, to choose which traffic uses the proxy:
| Proxy mode | Description |
|---|---|
mabl |
Connections to mabl, to api.mabl.com and the Link tunnel endpoint, use the proxy. All other connections, such as those to the system under test, are made without it. The default when you name a proxy with --http-proxy. |
all |
All connections are made through the proxy. The default when you use a PAC script. |
upstream |
Only connections to upstream hosts, such as the system under test, use the proxy. Connections to mabl are made without it, so the Link Agent can use QUIC. |
none |
No connections use a proxy, even if the host has one configured. |
auto |
Follow the host operating system's proxy configuration for every connection. The default when you give no proxy settings. It can't be combined with other proxy options except --proxy-auth. |
The following diagrams illustrate how the all, mabl, none, and upstream modes work.
mabl Link with proxy mode set to "All".
mabl Link with proxy mode set to "mabl".
mabl Link with proxy mode set to "none".
mabl Link with proxy mode set to "upstream".
Proxy exclusions
If a proxy is required to reach certain hosts but not others, list proxy exclusions separated by commas. Spaces after the commas are fine. A proxy exclusion can be one of the following types:
- A single IP address, for example:
192.168.10.50 - A CIDR range, for example:
10.0.0.0/8 - A host or domain, for example:
example.com
If you exclude a host or domain, the address is treated as a suffix. For example, an exclusion of example.com also matches www.example.com, api.example.com, and host1.subdomain1.example.com.
A complete example might look like this:
--proxy-exclude "localhost,127.0.0.1,192.168.10.50,10.0.0.0/8,example.com"
When the Link Agent follows the Windows proxy configuration, it also honors the Windows <local> bypass entry, which sends host names without a dot directly.