Use NGINX as a reverse proxy

NGINX can act as a reverse proxy that sits between internal applications and external clients, forwarding client requests to the appropriate application. Using NGINX as a reverse proxy in front of the engine enables you to provide network segmentation where the proxy can be put on a public subnet (DMZ) while the engine can be on a private subnet, only accepting traffic from the proxy. Additionally, NGINX provides a number of advanced load balancing and acceleration features that you can utilize.

If you want to use an engine (d1) through the reverse proxy, you need to modify EngineURLs in the d1.conf file to point to the host and port the NGINX server is listening on. In addition to supporting engine upgrades from the UI, edit the /usr/local/demisto/upgrade.conf file to add the SERVER_URLS setting. SERVER_URLS should be set to the proxy’s network address (host and port). For example: SERVER_URLS="10.0.0.30:1234". For SERVER_URLS, include only the IP/hostname and, optionally, a port. Do not include https:// or any path at the end.

Install NGINX

You can install NGINX on the Red Hat/Amazon (yum) and Ubuntu Linux distributions. For full instructions and available distributions, see NGINX documentation.

  1. On the engine, run one of the following commands according to your Linux system:
    • RedHat/Amazon: sudo yum install nginx
    • Ubuntu: sudo apt-get install nginx
  2. (Optional) Verify the NGINX installation by running the following command:

    sudo nginx -v

Generate a certificate for NGINX

You should not use self-signed certificates for production systems. It is recommended to use a properly signed certificate for production systems. These instructions are intended only for non-production setups.

  1. To use OpenSSL to generate a self-signed certificate, on the engine machine, run the following command:

    sudo openssl req -x509 -nodes -days 3650 -newkey rsa:2048 -keyout /etc/nginx/cert.key -out /etc/nginx/cert.crt

  2. When prompted, complete the on-screen instructions to complete the required fields.

Configure NGINX

  1. Open the following NGINX configuration file with your preferred editor:

    /etc/nginx/conf.d/demisto.conf

  2. Use the following configuration template:

    Replace DEMISTO_ENGINE with the appropriate hostname.

    # Replace DEMISTO_ENGINE with the appropriate hostname. If needed, change port 443 to the port on which the engine is listening.
    
    upstream demisto {
        server DEMISTO_ENGINE:443;
    }
    
    # Uncomment to redirect http to https (optional)
    # server {
    #     listen 80;
    #     return 301 https://$host$request_uri;
    # }
    
    server {
       # Change the port if you want NGINX to listen on a different port
        listen 443;
            
        ssl_certificate           /etc/nginx/cert.crt;
        ssl_certificate_key       /etc/nginx/cert.key;
    
        ssl on;
        ssl_session_cache  builtin:1000  shared:SSL:10m;
        ssl_protocols  TLSv1 TLSv1.1 TLSv1.2;
        ssl_ciphers HIGH:!aNULL:!eNULL:!EXPORT:!CAMELLIA:!DES:!MD5:!PSK:!RC4;
        ssl_prefer_server_ciphers on;
    
        access_log            /var/log/nginx/demisto.access.log;
    
        location / {
    
          proxy_set_header        Host $host;
          proxy_set_header        X-Real-IP $remote_addr;
          proxy_set_header        X-Forwarded-For $proxy_add_x_forwarded_for;
          proxy_set_header        X-Forwarded-Proto $scheme;
    
          proxy_pass          https://demisto;
          proxy_read_timeout  90;
        }
    
        location ~ ^/(websocket|d1ws|d2ws) {
            proxy_pass https://demisto;
            proxy_http_version 1.1;
            proxy_set_header Upgrade $http_upgrade;
            proxy_set_header Connection "upgrade";
            proxy_set_header Host $host;
            proxy_set_header Origin "";
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    

    For multi-tenant deployments, replace location ~ ^/(websocket|d1ws|d2ws) { with location ~ ^/(acc_\S+/)?(websocket|d1ws|d2ws)

  3. Restart the NGINX server by typing the following command:

    sudo service nginx restart

  4. Verify you can access the engine by browsing to the NGINX server host.