# CapaOne Agent Behind a Proxy Server

> Proxy server requirements for devices that reach CapaOne through an HTTP proxy.

Source: https://docs.capaone.com/capaone/troubleshooting/capaone-agent-behind-a-proxy-server/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

The CapaOne Agent has no proxy settings of its own. If your network sends internet traffic through
a proxy server, the agent works when the proxy meets the requirements on this page.

## Proxy server requirements

Configure your proxy server to:

- Allow HTTPS connections on port 443 to the URLs listed in
  [Windows Agent Requirements](/capaone/enrollment/windows-agent-requirements/#network-requirements).
- Exclude these URLs from TLS inspection. The agent uses HTTP/2, which doesn't work through an
  inspecting proxy.
- Keep connections open without a maximum connection lifetime.
- Use an idle timeout of at least 2 minutes.

:::note
The agent runs as the Local System account. A proxy that a user configures in Windows Settings
applies only to that user, not to the agent.
:::

## Symptoms of a proxy that doesn't meet the requirements

| Symptom | Cause |
|---------|-------|
| The device never appears as online. | The proxy blocks the URLs, or it inspects TLS traffic. |
| The device repeatedly appears offline and online. | The proxy closes the agent's connection. The agent keeps one connection to CapaOne open at all times. |
