Views:

The issue happens because the DSA fails to load the plug-in through the proxy connection.

To resolve the issue, a DSR must be placed in the AWS Cloud Zone. This DSR should be kept within its own Relay Group and should be configured with the appropriate proxy settings. Any DSA in AWS Cloud Zone must then be configured using this DSR in place.

  1. Enable the Relay for DSA.
    1. From the Deep Security Manager console, select a DSA which is installed on AWS VM.
    2. Open the machine's context window and go to Overview > Actions > Software.
    3. Click Enable Relay for this machine and wait for the update process to finish.
  2. Create Relay Groups.
    1. Navigate to Administration > Update > Relay Groups.
    2. Click New and follow the Relay Groups Wizard.
    3. Name your Relay Group and select the Relay members for this group.
    4. Configure your primary Relay Group by selecting Primary Security Update Source under the Download Updates From section. This setting will download updates from the Update Source URL configured in the Relay section of Updates tab.
    5. Repeat steps 2-3 to create more Relay Groups.
    6. You may opt to create Relay Group heirarchy by selecting an existing Relay Group as the source of your new Relay Group under the Download Updates From section.
  3. Assign Agents or Appliance to the Relay Groups.
    1. On the Computers page, right-click the selected machine and click Actions.
      If you want to assign a Relay Group to multiple computers, press SHIFT or CTRL and click the selected machines on the list.
       
      When selecting multiple computers, the Assign Relay Group option will only be available if this action is applicable to all the computers you selected.
    2. Click Assign Relay Group and choose the Relay Group to be used by doing any of the following:
      • Select the Relay Group from the drop-down list.
      • From the Computer Details windows, select the Relay Group from the Download Updates From section.
  4. Review all the Relay Group assignments. Note that the agents and appliances with no specific Relay Group assignment are automatically assigned to the "Default Relay Group".
    1. Navigate to Administration > System Settings > Updates.
    2. Click the View Relay Groups button.
    3. Right-click a Relay Group and select Properties.
    4. Click Assigned tab to review the list of agents and appliances assigned to this Relay Group.
    5. To quickly change the assignment for an agent or appliance, click the Assigned to link to open the Computer Details page where you can select another Relay Group assignment.
  5. Configure a Relay Group to use a proxy server.
     
    Each Relay Group (except the Default Relay Group) can be configured to use a separate proxy server to connect to Trend Micro for retrieving Security Updates. The Default Relay Group uses the same proxy to connect to the internet as Deep Security.
    1. From the Deep Security Manager console, go to Administration > Updates > Relay Groups.
    2. Double-click a Relay Group to show its Properties window.
    3. Click Proxies tab and select the proxy server from the Primary Security Update Proxy drop-down list. The list of available proxy servers is maintained on Administration > System Settings > Proxies tab.
    4. Click OK.