Agent Proxies
In complex network environments, not all monitored hosts may be directly reachable from the NetXMS server. The agent proxy feature allows one agent to act as a relay, forwarding requests from the server to agents and devices in isolated network segments.
Agent Proxy Overview
An agent proxy is a NetXMS agent that forwards communication between the server and agents that the server cannot reach directly. This is commonly used when:
-
Monitored hosts are in DMZ or isolated network segments
-
Network segmentation prevents the server from reaching all agents
-
Remote sites are connected via a single gateway host
The server connects to the proxy agent, which opens a connection to the target agent and relays the traffic — data collection, action execution, and file transfers all pass through the proxy. A single proxy hop is supported: the server connects directly to the proxy, and the proxy connects directly to the target.
Proxy Configuration
Enabling the Proxy Agent
On the agent that will act as a proxy, enable the proxy feature:
EnableProxy = yes
The NetXMS server’s address must be listed in the proxy agent’s MasterServers — proxy requests from other server levels are rejected.
The target agents behind the proxy must accept connections from the proxy agent’s address — list it in Servers, ControlServers, or MasterServers (the level determines what the server can do through the proxy):
# On target agents behind the proxy
MasterServers = 10.0.1.10
Where 10.0.1.10 is the proxy agent.
Configuring Nodes to Use the Proxy
On the NetXMS server, configure nodes to communicate through the proxy:
-
Open the node properties in the management client
-
Go to Communication > Agent
-
In the Proxy field, select the node running the proxy agent
-
Save the changes
In zoned setups, per-node proxy settings are usually unnecessary: any per-node proxy left unset falls back to the zone’s proxy nodes (see Zones and Subnets).
Proxy Types
Agent-side proxying is enabled per protocol in the proxy agent’s configuration file:
| Agent Parameter | Enables |
|---|---|
|
Agent-to-agent relay (agent proxy) |
|
SNMP requests to devices |
|
Forwarding SNMP traps to the server |
|
Forwarding syslog messages to the server |
|
Web service (HTTP) requests |
|
Modbus-TCP requests |
|
EtherNet/IP requests |
|
Generic TCP port forwarding |
|
TFTP transfers |
On the server side, the proxy node is selected per protocol on the corresponding property page of the target node, all under the Communication group: Agent, SNMP, ICMP, EtherNet/IP, Modbus, MQTT, SSH, VNC, and Web Services pages each have a Proxy field. Any proxy left at default falls back to the zone proxy when zoning is enabled.
SNMP Proxy
With EnableSNMPProxy = yes on the proxy agent, the server can collect SNMP data from devices it cannot reach directly: the proxy agent sends SNMP requests to the target device and relays responses back.
Select the proxy in the Proxy field on the Communication > SNMP page of the target node.
ICMP Proxy
ICMP polls through a proxy are executed as Icmp.Ping metric requests on the proxy agent, which requires the PING subagent to be loaded on the proxy:
SubAgent = ping.nsm
Select the proxy in the Proxy field on the Communication > ICMP page of the target node.
The same requirement applies to proxied active discovery scans, which use the Icmp.ScanRange metric.
Proxy with Tunnels
Agent proxy works with agent tunnels. A common deployment pattern for remote sites:
-
One agent at the remote site establishes a tunnel to the central server
-
That agent also acts as a proxy for other agents at the same site
-
Target agents connect directly to the proxy agent (local network)
# Gateway agent at remote site
ServerConnection = central-server.example.com
MasterServers = central-server.example.com
EnableProxy = yes
EnableSNMPProxy = yes
This approach requires only one outbound connection from the remote site, while still monitoring all hosts at that site.
Performance Considerations
-
Each proxied connection adds latency compared to direct communication
-
The proxy agent handles all data traffic for its downstream agents; ensure it has adequate resources (CPU, memory, network bandwidth)
-
Monitor the proxy agent’s performance metrics to detect bottlenecks
-
For large numbers of proxied nodes, use zones — zone proxies support multiple proxy agents with automatic load balancing and failover (see Zones and Subnets); node-level proxy assignment is static
Troubleshooting
Proxied Agent Not Responding
-
Verify the NetXMS server’s address is in the proxy agent’s
MasterServerslist — without it, proxy requests are rejected with an access denied error -
Verify the proxy agent itself is reachable from the server
-
From the proxy host, test connectivity to the target agent:
nxget <target-ip> System.PlatformName -
Verify the proxy agent’s address is accepted by the target agent (
Servers,ControlServers, orMasterServers) -
Check that
EnableProxy = yesis set in the proxy agent’s configuration -
Enable debug logging on the proxy agent and look for forwarding errors