Loading...
Loading...
This article explains how to configure an HTTP proxy for Veeam Service Provider Console 9.3 and later, which introduced a dedicated proxy configuration mechanism that is disabled by default and does not use the WinHTTP, Internet Options, or environment variable proxy settings described in KB4875. If a proxy is required to reach the internet and this mechanism is not configured, product update, license auto-update, and single sign-on features fail. Typical entries appear in Server.log: VeeamAutoLk>>AutoLkClient: Failed to get data from the AutoLk service ... A connection attempt failed ... (vac.butler.veeam.com:443) Saml2IdentityProvider: Failed to retrieve data from 'https://login.microsoftonline.com/...' due network error. Exception: System.Net.WebException: The operation has timed out. In versions prior to Veeam Service Provider Console 9.3, the software had no dedicated proxy setting and always used the .NET defaults: the HTTPS_PROXY/HTTP_PROXY environment variables first, then the Internet Options (WinINET) proxy of the service account, as described in KB4875.
Summary Veeam Service Provider Console 9.3 introduced a central HttpClient configuration section. All HTTP clients created by the Veeam Service Provider Console Server, Web UI, REST API, and Management Agent read from it, and the default value of HttpClient_UseProxy is False. Until this key is set to True, every outbound connection is sent directly, regardless of OS-level proxy settings.
What This Affects Once enabled, HttpClient_UseProxy covers: Server: AutoLK/Butler license and update checks, license auto-update, plugin package downloads, support-bundle API calls, SAML 2.0 SSO metadata retrieval, and REST calls to managed Veeam Backup & Replication, Veeam Backup for Microsoft 365, and Veeam ONE servers. Web UI and REST API: the same HTTP client traffic as the Server, since the Web UI reads the Server's configuration file. Management Agent: REST calls to the managed products it monitors. Keep those products in the bypass list if the agent must also reach the internet, or their traffic is sent to the proxy too. A few flows are not covered by HttpClient_UseProxy and continue to use the .NET defaults, that is, the OS proxy via environment variables or Internet Options as described in KB4875, regardless of this setting: Download of Veeam Backup & Replication and Veeam ONE deployment answer files. Upload of the support bundle to the pre-signed storage URL. Time synchronization for TOTP multi-factor authentication. Google OAuth client-secret validation for Veeam Plug-In for Google Cloud credentials in the Web UI. Webhook alarm actions.
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.