Agent network egress (relays and proxy)
Route agents on a network without Internet access through another FirstSI agent or the company proxy.
By default, an agent reaches FirstSI directly over HTTPS. On a closed network (industrial zone, subnet without Internet access), it can go through a FirstSI relay, meaning another agent on the network that does have access to the server, or through the company proxy. Only proxies without authentication (CONNECT method) are supported for now.
Encryption runs from the agent all the way to the server: the relay or proxy only sees encrypted data pass through. A relay only lets agents reach the FirstSI server, nothing else.
Set up egress
In FSI Agents, click Network egress.
- The Default rule applies to agents that are not in any of the networks declared below. For example: the whole fleet goes out through the company proxy.
- Isolated networks → Add a network: give a name and some Address ranges (
10.20.0.0/16,10.20.5.1-10.20.5.50). An agent belongs to the first network that has a range containing its local address. The screen shows how many agents are recognised in each network. - For each rule, add the Gateways (primary, then backup) in order. A FirstSI relay is defined by the relay agent, the Address seen by the agents and the port. A Corporate proxy is defined by its address and port.
- Direct access as a fallback: if no gateway answers, the agent tries to reach FirstSI directly.
- Click Save. Agents receive the setting within a minute.
The relay agent opens its own port in the Windows firewall, restricted to the declared ranges. It needs a recent version; the screen tells you if its version is too old to act as a relay.
Monitor the relays
The Relays block shows the state of each one:
| State | Meaning |
|---|---|
| Active | It sent its report for the last minute |
| Waiting for first report | It has just been designated |
| Silent | No report for 5 minutes; an alert goes out |
| Port not open | It could not listen on the chosen port |
The report shows connections per minute, the number of agents served, refusals and errors towards FirstSI.
Relay settings, which apply to all of the customer's relays: Maximum simultaneous connections (256 by default, 8 to 4,000) and Idle timeout (seconds) (330 s by default, 30 to 3,600 s).
First installation on an isolated network
A freshly installed agent has to reach FirstSI to register, before it has even received the console's setting. So you give it its gateways on the install command line:
msiexec /i FSIAgent.msi /qn SERVERURL="https://console.example.com" APIKEY="<key>" HMACSECRET="<secret>" ^
NETDIAG=true RELAIS="10.20.0.5:3129;10.20.0.6:3129" RELAISDIRECT=falseRELAIS lists the gateways, primary first. RELAISDIRECT=false forbids falling back to a direct connection. Once registered, the agent follows the console's setting.
How the agent picks its route
It first tries the gateways received from the console, in order, then those given at installation, then a direct connection if that is allowed. A gateway that doesn't answer is set aside for a minute before being tried again.
Source: · FirstSI Docs · updated 2026-10-10