Documentation Videos View Site

# Using a Windows as a Proxy Server between CMDB360 Base Station and Satellites

The CMDB360 design incorporates secure model that allows direct outbound only connections from the Satellites to the Base Station. However, if a proxy server is required, one may be placed between the Satellite and Base Station. This document discusses setting up NGINX as a forward proxy on a Windows server. Other configurations should be possible also.

# Install NGINX

Visit the official Nginx website to download the latest version of Nginx for Windows: Nginx Download.

Once the download is complete, extract the contents of the archive to a directory of your choice.

For this example we have downloaded version 1.27.4 and are extracting it to C:\nginx-1.27.4

# Configure NGINX HTTPS stream

Once your have extracted the zip file, a conf directory will have been created under the directory you extracted to. Edit the nginx.conf file in that directory.

Add the following section to the nginx.conf

stream {
    resolver 8.8.8.8;
    server {
        listen 443;
        ssl_preread on;
        proxy_connect_timeout 5s;
        proxy_pass $ssl_preread_server_name:$server_port;
    }
}

Additionally, comment out or remove any other http server section that uses https or port 443.

This example shows a full nginx.conf file that only handles the CMDB forward proxy (all other sections removed) using a port other than HTTPS (443), in this case 12001. The port is then translated to 443 externally. It also enables logging of the transactions at c:\nginx-1.27.5\logs\access.log and error.log

worker_processes  1;

error_log  logs/error.log;
error_log  logs/error.log  notice;
error_log  logs/error.log  info;

pid        logs/nginx.pid;

events {    worker_connections  1024; }

stream {
    resolver 8.8.8.8;
    server {
        log_format basic '$remote_addr [$time_local] $protocol $status $bytes_sent'
                         '$bytes_received   $session_time';
        access_log logs/access.log basic;
        error_log  logs/error.log debug;
        
        include /etc/nginx/stream.conf.d/*.conf;
        
        listen 12001;
        ssl_preread on;
        proxy_connect_timeout 5s;
        proxy_pass $ssl_preread_server_name:443;
    }
}

# Add entry to /etc/hosts on Satellite

On the satellite, edit the /etc/hosts file and create an entry for the CMDB Base station and Control server that has the proxy server address. For example, if your Windows proxy server has a local address of 10.0.1.10 and the CMDB Base Station is at mythics-test.cmdb360.com, the following would need to be added to the satellite’s /etc/hosts file.

10.0.1.10 mythics-test.cmdb360.com control.cmdb360.com

# Installing the Satellite

On the satellite, run the Satellite Installation Tool with root privileges. You must use the hostnames for your CMDB Base Station and CMDB Control Center (as put into the /etc/hosts and that can be resolved by the resolver in the NGINX config) and not IP addresses. If you are using a port other than the standard HTTPS (443) to the proxy server, be sure to add that to the end of the Repository Host and CMDB Host entries.

# Open Network Traffic

Be sure to allow INBOUND traffic on port 443/tcp on the Proxy Server. Outbound traffic from the satellite is required to reach the Proxy Server. Also, if you are setting up this proxy on OCI, ensure the Network rules on the OCI subnet allow for this traffic between the satellite and the proxy server.

# Starting and Stopping NGINX

Once everything is configured you can start NGINX with the following command

C:\nginx-1.27.4>start nginx.exe

NGINX can be gracefully stopped using

C:\nginx-1.27.4>nginx.exe -s stop

By default, Nginx does not run as a Windows service, which means it will not automatically start when your computer boots. It is suggested that you use Windows Task Scheduler to set it up to automatically run on boot or failure. Or you can use a third-party tool like NSSM to create a Windows service.

# Using Task Scheduler

Here is an example of settings up a task on Windows Server 2022 using Task Scheduler. Start the Task Scheduler application and click the “Create Task…” button on the right. Fill in the task name and select “Run whether user is logged in or not” from the Security options section and Configure for: Windows Server 2022

Next add an Action to start the nginx server. Click the Action tab and click the New button. Select “Start a program” from the Action dropdown. Then Browse and select the nginx.exe executable that you installed. Also add the directory where nginx is installed to the Start In field. Then click OK

Add a trigger to start nginx when the system is booted by clicking on the Triggers tab and clicking the New button. Select “At Startup” from the “Begin the task:” dropdown and click OK.

Modify the settings for the task by clicking the Settings tab. Click the “If task fails, restart every” check box and enter the time frame to restart and number of retry attempts. Unclick the “Stop the task if it runs longer than:” checkbox. And Click OK

The task is now scheduled to start at the next boot, however it is not currently running. To start the task manually Click on the Task Schedule Library and select the nginx task you just created. On the right hand side click the Run button to start the task. You should then see the Status of Running in the main windows next to the nginx task. You can also end the nginx task here by clicking the End button.