Configure proxy server settings
-
Ensures that the communication is secure when proxies perform SSL interception.
-
Prevents connectivity issues for telemetry uploads and Cloud Connect communication.
Points to note
-
Ensure that the proxy server is reachable from NetScaler Console over the specified IP/port.
-
If SSL interception is enabled, import in NetScaler Console, the proxy’s CA certificate to avoid connectivity failures.
-
Changes to proxy configuration might impact automated telemetry upload or Cloud Connect until the new details are added.
Proxy server configuration
-
Add
adm.cloud.comto Allow list.
-
Navigate to Settings > Administration and click Proxy Server.
-
On the Proxy Server Configuration tab, select Enable Proxy Server.
-
Specify the IP Address/Hostname of the proxy server and its listening Port.Note:
-
Starting from 14.1 release build 56.x, NetScaler Console supports using DNS host names (FQDNs) in addition to IP addresses for proxy configuration.
-
Using host names is beneficial in environments that:
-
Use DNS-based redundancy (for example, GSLB) to route traffic across multiple proxy servers.
-
Have no load balancer, but rely on DNS to manage high availability and failover.
-
Require scalable and resilient proxy configurations across data centers.
The support to use DNS host names allows NetScaler Console to dynamically resolve the most appropriate proxy endpoint, improving reliability and simplifying management. -
-
-
Provide a Username and the corresponding Password if the proxy requires credentials.Note:NetScaler Console currently supports basic authentication for proxy.
-
Click Save.

Manage CA certificate
-
Navigate to Settings > Administration and click Proxy Server.
-
Click Upload Certificate.
-
Navigate to Settings > Administration and click Proxy Server.
-
Select the certificate to be deleted.
-
Click Delete Certificate.

Proxy configuration support
-
For explicit SSL‑intercepting and transparent SSL‑intercepting proxy deployments, uploading the proxy CA certificate is mandatory. If the proxy CA certificate is not uploaded, outbound traffic from NetScaler Console fails.
-
Do not configure a proxy on NetScaler Console on‑prem when using a transparent SSL‑intercepting proxy.
No Proxy (Direct Internet Access)
-
Communication uses outbound HTTPS traffic only.
-
No proxy configuration is required on NetScaler Console on-prem.
Explicit Forward Proxy (Non‑Intercepting)
-
NetScaler Console traffic is sent through a configured forward proxy.
-
The proxy forwards HTTPS traffic without decrypting SSL/TLS.
-
Required: Proxy details must be configured on NetScaler Console on-prem.
-
Optional: Authentication is optional. Users can provide a user name and password to authenticate while providing the proxy configuration. Only basic authentication is supported.
Explicit SSL‑Intercepting proxy
-
The proxy performs SSL decryption and re‑encryption.
-
Required: Proxy configuration is required on NetScaler Console.
-
Required: The proxy CA certificate must be uploaded to NetScaler Console. For more information, see Manage CA certificate.
-
Optional: Authentication is optional. Users can provide a user name and password to authenticate while providing the proxy configuration. Only basic authentication is supported.
Transparent SSL‑intercepting proxy
-
SSL inspection occurs transparently without proxy settings on NetScaler Console.
-
Network devices redirect traffic to the proxy automatically.
-
Required: The proxy CA certificate must be uploaded to NetScaler Console for SSL validation. For more information, see Manage CA certificate.
-
No proxy configuration is required on NetScaler Console.