Support for HTTP(s) Proxy in the Cloud Extension

IT managers may choose to divert HTTP(S) traffic through an HTTP(S) proxy for reasons of security and network monitoring.

Communication from the Velostrata Manager and edge node on-prem supports a proxy configuration for telemetry and support center.  Velostrata CloudExtension also supports the option to communication with the Velostrata proactive support service through an HTTPS Proxy.

Note that you can define cloud extension communication through the proxy to include either control only, or also include data-plane communication. The latter option may have performance implications for the proxy and is not recommended.

When implementing such configuration, the following steps may be required:

  • Define the proxy during Velostrata Cloud Extension creation process.
  • If you apply URL whitelisting, you will need to whitelist the following URLs:
GCP Proxy whitelist
  • telemetry-eu-1.prod.velostrata.com (Europe only)
  • telemetry1.prod.velostrata.com (US only) 
  • accounts.google.com
  • cloudresourcemanager.googleapis.com
  • www.googleapis.com
  • iam.googleapis.com
  • storage.googleapis.com
AWS Proxy whitelist

telemetry1.prod.velostrata.com

qt1.velostrata.com

velostelemetryweb-780103999.us-east-1.elb.amazonaws.com / dns resolved from qt1.velostrata.com

iam.amazonaws.com

ec2.us-east-1.amazonaws.com


In addition add the s3, ec2 and kms service endpoint of the respective region you utilizing.

For example, see below the end points for eu-west-1 region:


s3.eu-west-1.amazonaws.com

ec2.eu-west-1.amazonaws.com

kms.eu-west-1.amazonaws.com


* You can find the relevant region endpoint here.




Azure Proxy whitelist

 telemetry1.prod.velostrata.com

qt1.velostrata.com

velostelemetryweb-780103999.us-east-1.elb.amazonaws.com / dns resolved from qt1.velostrata.com

.blob.core.windows.net

login.microsoftonline.com

management.azure.com

 

  • If you would like to inspect the SSL traffic by the proxy, the proxy’s SSL certificate needs to be configured in the Velostrata Cloud Extension.  Contact support@velostrata.com for help with this process.