Configuring a custom proxy for dynamic analysis

Route dynamic analysis (DAST) scan traffic to internal or private web applications through a designated forward proxy server as an alternative to an AppScan Presence.

Before you begin

Before you configure a custom proxy, confirm the following prerequisites:
  • The forward proxy server can reach the target application URL.
  • You have the fully qualified domain name (FQDN) or IP address and the listening port of your proxy server.
  • If the proxy server requires authentication, obtain the authorized username and password.

About this task

Custom proxy routing enables scan engines to test web applications hosted on private corporate networks or private cloud infrastructure without installing an AppScan Presence.

Important:
  • Mutual exclusivity: A scan configuration supports either an AppScan Presence or a custom proxy, but not both. Selecting a custom proxy disables the AppScan Presence selection for that scan.
  • Pre-scan validation bypass: When you enter proxy authentication credentials (username and password), AppScan on Cloud automatically bypasses automated pre-scan URL reachability validation to allow authentication handshakes during scan execution.

Procedure

  1. Go to Scans and select an existing DAST scan configuration, or select Create scan > Dynamic analysis.
  2. In the scan configuration wizard, go to the Environment or Connection tab.
  3. Under private network routing options, select Custom Proxy.
  4. In the Proxy Host / IP box, enter the FQDN or IP address of the forward proxy server.
  5. In the Port box, enter the listening port of the proxy server.
  6. (Optional) If the proxy requires authentication, enter the credentials in the Username and Password boxes.
  7. Select Save to store the configuration, or select Scan to start the scan.

Results

AppScan on Cloud routes scan traffic through the configured forward proxy server to analyze the target private web application.

What to do next

If the scan fails to establish a connection, see AppScan Presence troubleshooting or verify that the proxy host accepts incoming requests from the AppScan on Cloud scanner IP range.