# Configuring Proxy and Authenticated Proxy per Web Application on Mobile Access Gateway

**Product**: Mobile Access / SSL VPN  
**Version**: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20  
**OS**: Gaia  
**Last Modified**: 2023-06-06

## Solution

**Prerequisites:**  
1. In SmartConsole, configure the Host object that represents the Proxy Server.  
2. If the proxy server listens on a non-standard port, then configure the applicable TCP service object.

**Procedure:**  
01. Back up the Security Management Server / Domain Management Server.

Refer to:  
    - [sk108902 - Best Practices - Backup on Gaia OS](https://support.checkpoint.com/results/sk/sk108902)  
    - [sk91400 - System Backup and Restore feature in Gaia](https://support.checkpoint.com/results/sk/sk91400)  
    - [sk98153 - How to take a snapshot of Endpoint Security Management Server database](https://support.checkpoint.com/results/sk/sk98153)  
02. Close **all** SmartConsole windows.

Verify by running the " _cpstat mg_" command on the Security Management Server / in the context of _each_ Domain Management Server.

03. Connect with [Database Tool (GuiDBedit Tool)](https://support.checkpoint.com/results/sk/sk13009) to the Security Management Server / Domain Management Server.

04. In the upper left pane, go to _**Table**_ \> _**Other**_ \> _**network_applications**_.

05. In the upper right pane, select the applicable Web Application object (Class Name "`connectra_web_application`).

06. Press CTRL+F (or go to _**Search**_ menu \> _**Find**_) \> paste _**proxy_server**_ \> click _**Find Next**_.

07. In the lower pane, below the attribute _**proxy_server**_, configure the applicable values in the nested attributes:

**Notes:**  
    - To edit an attribute value:  
      1. Right-click the attribute \> select _**Edit**_  
      2. Enter or select the applicable value  
      3. Click _**OK**_  
    - Available attributes when configuring an Authenticated HTTP / HTTPS Proxy per Web Application:

| Attribute | Description |
      | --- | --- |
      | `use_the_gw_general_proxy_settings` | Specifies whether this Web Application uses the proxy settings on the Mobile Access Gateway (this is the main "on-off" switch):<br>      - Value " _**true**_" specifies to ignore all other nested attributes in the attribute **_proxy_server_**.<br>      - Value " _**false**_" specifies to use the configured proxy server settings. |
      | `http_proxy_credentials` | Configures the Proxy Server Credentials.<br>**Important** - If below the attribute _**http_proxy_credentials**_, there are **no** nested attributes _**password**_ and _**username**_, then:<br>      1. Right-click the attribute _**http_proxy_credentials**_ \> select _**Edit**_<br>      2. Do not edit the default value<br>      3. Just click _**OK**_<br>Notes:<br>      - To use credentials for an HTTP Proxy, you must configure the value _**true**_ for the attribute _**use_credentials_for_http_proxy**_.<br>      - To use credentials for an HTTPS Proxy, you must configure the value _**true**_ for the attribute _**use_credentials_for_https_proxy**_.<br>      - To configure the password in **plain-text**:<br>        1. Right-click the attribute _**password**_ \> select _**Edit**_<br>        2. Enter the applicable password<br>        3. Click _**OK**_<br>      - To configure the password as an **obfuscated** string:<br>        1. Connect to the command line on the Mobile Access Gateway / each Mobile Access cluster member.<br>        2. Log in to the Expert mode.<br>        3. Get the obfuscated string for your password:<br>           <br>           `$CVPNDIR/bin/obfuscate_password <Proxy Server Password in plain-text>`<br>        4. Right-click the attribute _**password**_ \> select _**Edit**_<br>        5. Enter the applicable password as an obfuscated string<br>        6. Click _**OK**_<br>      - To configure the username:<br>        1. Right-click the attribute _**username**_ \> select _**Edit**_<br>        2. Enter the applicable username<br>        3. Click _**OK**_ |
      | `use_http_proxy` | Specifies whether this Web Application uses the configured HTTP proxy:<br>      - Value " _**true**_" specifies to use the configured HTTP proxy.<br>      - Value " _**false**_" specifies **not** to use the configured HTTP proxy, even if it is configured on the Mobile Access Gateway. |
      | `use_https_proxy` | Specifies whether this Web Application uses the configured HTTPS proxy:<br>      - Value " _**true**_" specifies to use the configured HTTPS proxy.<br>      - Value " _**false**_" specifies **not** to use the configured HTTPS proxy, even if it is configured on the Mobile Access Gateway. |
      | `http_proxy_host` | Specifies the HTTP Proxy Server.<br>      1. In the _**Table**_ field, select _**network_objects**_.<br>         <br>      2. In the _**Object**_ field, select the applicable host object (you created earlier in SmartConsole) that represents this HTTP Proxy Server.<br>         <br>         Note: If the field is empty, then enter the host object name exactly as it appears in SmartConsole. |
      | `https_proxy_host` | Specifies the HTTPS Proxy Server.<br>      1. In the _**Table**_ field, select _**network_objects**_.<br>         <br>      2. In the _**Object**_ field, select the applicable host object (you created earlier in SmartConsole) that represents this HTTPS Proxy Server.<br>         <br>         Note: If the field is empty, then enter the host object name exactly as it appears in SmartConsole. |
      | `http_proxy_service` | Specify the port on the HTTP Proxy Server.<br>      1. In the _**Table**_ field, select _**services**_.<br>         <br>      2. In the _**Object**_ field, select the applicable service object.<br>         <br>         Note: If the field is empty, then enter the service object name exactly as it appears in SmartConsole. |
      | `https_proxy_service` | Specify the port on the HTTPS Proxy Server.<br>      1. In the _**Table**_ field, select _**services**_.<br>         <br>      2. In the _**Object**_ field, select the applicable service object.<br>         <br>         Note: If the field is empty, then enter the service object name exactly as it appears in SmartConsole. |
      | `use_credentials_for_http_proxy` | Specifies whether to use login credentials for the configured HTTP Proxy Server:<br>      - Value " _**true**_" specifies to use the login credentials.<br>      - Value " _**false**_" specifies **not** to use the login credentials. |
      | `use_credentials_for_https_proxy` | Specifies whether to use login credentials for the configured HTTPS Proxy Server:<br>      - Value " _**true**_" specifies to use the login credentials.<br>      - Value " _**false**_" specifies **not** to use the login credentials. |
08. Save the changes: go to the _**File**_ menu \> click _**Save All**_.

09. Close the Database Tool (GuiDBedit Tool).

10. Connect with SmartConsole to the Security Management Server / Domain Management Server.

11. Install the Access Control Policy onto the applicable Mobile Access Gateway / Cluster object.

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level**: General  
**Status**: Approved by TAC  
**Date Created**: 2008-04-16  
**Last Modified**: 2023-06-06
