Polaris Secure Tunnel enables teams to securely connect to internal web applications and APIs (inside a private network) for the purposes of running dynamic tests using Polaris fAST Dynamic (DAST). This document explains how to run Secure Tunnel from the Bridge CLI, establishing a secure TLS connection between Polaris and an internal target for tests run from the Polaris UI. To learn more, see Test an internal web application or API with Polaris Secure Tunnel in the Polaris Platform documentation.
Prerequisites
- The following reading is recommended before starting:
-
Consult the Polaris Secure Tunnel documentation to understand functionality and system requirements.
-
-
A Polaris access token has been created. See Make an access token for instructions
-
A secure tunnel has been created in the Polaris web UI under .
-
A DAST project has been created for an internal target (web application or API) in the Polaris UI:
- The Entry Point URL is in a private network check-box must have been selected when creating the project. For instructions, see the fAST Dynamic documentation.
- The name of the secure tunnel has been assigned to the DAST project's entry point URL in the Polaris UI.
The tunnel must be connected using the Polaris secure tunnel workflow, otherwise Bridge CLI will log an error as
Tunnel <Tunnel-name> is not connected. Shared tunnels must be started separately using the Polaris Secure Tunnel Workflow.-
Bridge CLI (version 4.3.0 or higher) is installed on a local machine (or a virtual machine or other runner that both has access to the internal DAST target and can reach the Polaris instance on port 443).
Instructions
Shared tunnels must be started separately using the Polaris Secure Tunnel Workflow"