Knowledge base

RC-Scanner Behind a Web Proxy

Last updated: 2026-09-08



Purpose

This article explains how RC-Scanner works in proxy-controlled networks. It outlines supported proxy deployment models, requirements for transparent proxies, and available options when an explicit proxy is required.

Introduction

RC-Scanner requires outbound internet access for installing dependencies, bootstrapping the cluster, container image pulls, license validation and vulnerability updates. Where that traffic must pass through a web proxy, support depends on how the proxy is deployed

Summary

Proxy deployment

Support status

No proxy (direct egress, or firewall allowlist)

Supported

Transparent (intercepting) proxy, without TLS inspection

Supported

Transparent (intercepting) proxy, with TLS inspection

Not currently supported

Non-transparent (explicit) proxy

Not currently supported

TLS inspection is unsupported regardless of whether the proxy is deployed transparently or non-transparently.

Transparent Proxy without TLS Inspection

A transparent proxy redirects outbound traffic at the network layer. The client is unaware the proxy exists and requires no configuration to use it.

RC Scanner operates normally in these environments. No proxy settings are needed on the appliance, and the proxy retains full visibility, logging, and policy enforcement over the appliance’s outbound traffic.

For example, the appliance is placed on a network segment whose gateway redirects HTTP and HTTPS traffic to the proxy.

Requirements

  • DNS resolution. The appliance must be able to resolve public DNS names. In a transparent deployment the appliance connects to destination addresses directly, so it performs its own name resolution rather than relying on the proxy to do so.

  • Correct interface MTU (Maximum Transmission Unit). The appliance’s network interface must be configured with the maximum packet size its network segment supports. This is usually the standard 1500 bytes, but is lower on networks that use tunnels, VPNs, or virtualised overlay networking.

If the MTU is set too high, the appliance appears to have working connectivity while larger transfers fail — the management interface loads and small requests succeed, but updates or downloads stall partway through and time out.

Proxies Performing TLS Inspection (not supported)

A proxy that performs TLS inspection — also called SSL interception, TLS decryption, or break-and-inspect — decrypts HTTPS traffic in order to examine its contents. It presents each client with a certificate that it generates and signs using an internal certificate authority, rather than the true certificate belonging to the destination server. Clients that do not trust that certificate authority reject the connection.

RC Scanner does not currently provide any mechanism for trusting an additional certificate authority. Outbound connections made by the appliance therefore fail when they pass through an inspecting proxy.

This applies to both transparent and non-transparent proxy deployments.

Resolution

Configure the proxy to exempt the appliance from TLS inspection. Most web gateways support inspection bypass rules based on source address, destination, or both.

Non-Transparent Proxy (not supported)

A non-transparent (explicit) proxy must be configured on each client. Software that is unaware of the proxy cannot use it — traffic sent directly to the destination is blocked, since no route to the internet exists other than through the proxy.

RC Scanner does not currently provide any mechanism for configuring proxy settings. Outbound connections therefore cannot be directed through an explicit proxy.

This applies regardless of whether the proxy requires authentication.

Options for Environments with an Explicit Proxy

Place the Appliance behind a Transparent Proxy Path

Position the appliance on a network segment where outbound traffic is redirected to the proxy at the network layer, rather than requiring client configuration.

This is the recommended option. Most commercial web gateways support both non-transparent and transparent deployment. Note that transparent proxies cannot require user authentication, so per-user attribution is not available for this host.

Firewall Allowlist Bypass

Permit the appliance direct outbound access to the destinations RC Scanner requires, bypassing the proxy.