Agent Proxies

In complex network environments, not all monitored hosts may be directly reachable from the NetXMS server. The agent proxy feature allows one agent to act as a relay, forwarding requests from the server to agents and devices in isolated network segments.

Agent Proxy Overview

An agent proxy is a NetXMS agent that forwards communication between the server and agents that the server cannot reach directly. This is commonly used when:

  • Monitored hosts are in DMZ or isolated network segments

  • Network segmentation prevents the server from reaching all agents

  • Remote sites are connected via a single gateway host

The server connects to the proxy agent, which opens a connection to the target agent and relays the traffic — data collection, action execution, and file transfers all pass through the proxy. A single proxy hop is supported: the server connects directly to the proxy, and the proxy connects directly to the target.

Proxy Configuration

Enabling the Proxy Agent

On the agent that will act as a proxy, enable the proxy feature:

EnableProxy = yes

The NetXMS server’s address must be listed in the proxy agent’s MasterServers — proxy requests from other server levels are rejected.

The target agents behind the proxy must accept connections from the proxy agent’s address — list it in Servers, ControlServers, or MasterServers (the level determines what the server can do through the proxy):

# On target agents behind the proxy
MasterServers = 10.0.1.10

Where 10.0.1.10 is the proxy agent.

Configuring Nodes to Use the Proxy

On the NetXMS server, configure nodes to communicate through the proxy:

  1. Open the node properties in the management client

  2. Go to Communication > Agent

  3. In the Proxy field, select the node running the proxy agent

  4. Save the changes

In zoned setups, per-node proxy settings are usually unnecessary: any per-node proxy left unset falls back to the zone’s proxy nodes (see Zones and Subnets).

Proxy Types

Agent-side proxying is enabled per protocol in the proxy agent’s configuration file:

Agent Parameter Enables

EnableProxy

Agent-to-agent relay (agent proxy)

EnableSNMPProxy

SNMP requests to devices

EnableSNMPTrapProxy

Forwarding SNMP traps to the server

EnableSyslogProxy

Forwarding syslog messages to the server

EnableWebServiceProxy

Web service (HTTP) requests

EnableModbusProxy

Modbus-TCP requests

EnableEtherNetIPProxy

EtherNet/IP requests

EnableTCPProxy

Generic TCP port forwarding

EnableTFTPProxy

TFTP transfers

On the server side, the proxy node is selected per protocol on the corresponding property page of the target node, all under the Communication group: Agent, SNMP, ICMP, EtherNet/IP, Modbus, MQTT, SSH, VNC, and Web Services pages each have a Proxy field. Any proxy left at default falls back to the zone proxy when zoning is enabled.

SNMP Proxy

With EnableSNMPProxy = yes on the proxy agent, the server can collect SNMP data from devices it cannot reach directly: the proxy agent sends SNMP requests to the target device and relays responses back. Select the proxy in the Proxy field on the Communication > SNMP page of the target node.

ICMP Proxy

ICMP polls through a proxy are executed as Icmp.Ping metric requests on the proxy agent, which requires the PING subagent to be loaded on the proxy:

SubAgent = ping.nsm

Select the proxy in the Proxy field on the Communication > ICMP page of the target node. The same requirement applies to proxied active discovery scans, which use the Icmp.ScanRange metric.

Proxy with Tunnels

Agent proxy works with agent tunnels. A common deployment pattern for remote sites:

  1. One agent at the remote site establishes a tunnel to the central server

  2. That agent also acts as a proxy for other agents at the same site

  3. Target agents connect directly to the proxy agent (local network)

# Gateway agent at remote site
ServerConnection = central-server.example.com
MasterServers = central-server.example.com
EnableProxy = yes
EnableSNMPProxy = yes

This approach requires only one outbound connection from the remote site, while still monitoring all hosts at that site.

Performance Considerations

  • Each proxied connection adds latency compared to direct communication

  • The proxy agent handles all data traffic for its downstream agents; ensure it has adequate resources (CPU, memory, network bandwidth)

  • Monitor the proxy agent’s performance metrics to detect bottlenecks

  • For large numbers of proxied nodes, use zones — zone proxies support multiple proxy agents with automatic load balancing and failover (see Zones and Subnets); node-level proxy assignment is static

Troubleshooting

Proxied Agent Not Responding

  1. Verify the NetXMS server’s address is in the proxy agent’s MasterServers list — without it, proxy requests are rejected with an access denied error

  2. Verify the proxy agent itself is reachable from the server

  3. From the proxy host, test connectivity to the target agent: nxget <target-ip> System.PlatformName

  4. Verify the proxy agent’s address is accepted by the target agent (Servers, ControlServers, or MasterServers)

  5. Check that EnableProxy = yes is set in the proxy agent’s configuration

  6. Enable debug logging on the proxy agent and look for forwarding errors

Slow Data Collection Through Proxy

  1. Check network latency between proxy and target agents

  2. Monitor the proxy agent’s CPU and thread pool utilization

  3. Consider reducing the number of nodes routed through a single proxy

  4. If using tunnel + proxy, check the tunnel connection stability