- Log in to the IWSVA administration console.
- Go to Administration > Deployment Wizard.
Note: The Deployment Wizard launches automatically when an administrator logs in for the first time. - Click Start on the Welcome page.
- On the Deployment Mode page, click the Reverse Proxy Mode radio button and then click Next.
- On the Proxy Settings page, type the internal/private IP address of the SSFE server in the Protected serverfield.
- Click Next.
- In the Network Interface page, select the appropriate Internet-facing NIC and then type the public IP address of the IWSVA server as shown below.
- Configure other settings as required and then click Next.
- Complete the remaining steps of the Deployment Wizard then save all the changes done.
- Log in to the IWSVA Linux shell.
- Edit the /etc/iscan/intscan.ini file using any text editor such vi.
- Look for the ProxyPreserveHost parameter and set it to "yes".
This ensures successful login to the SSFE GUI because SSFE will not work well with requests that have the IP address in the hostname header. It will process only requests addressed to its FQDN, so requests proxied by IWSVA should always use FQDN on the request header. - Restart the proxy daemon by running these commands:
- ./S99ISproxy stop
- ./S99ISproxy start
- Update the DNS records to make the FQDN of the SSFE server point to the IWSVA public IP address.