HTTP Proxy

Dynamic manifests

Specify a proxy for Unified VOD/LIVE for fetching the server manifest file. This is useful for dynamically updating options like DRM settings, encryption keys, enable/disable playout that are managed by your CMS.


  [CMS]   <--   [origin]  <-- client request
video.ism     IsmProxyPass


For Apache the IsmProxyPass configuration key is specified in a Directory tag.

<Directory "/var/www/video/proxy" >
    IsmProxyPass http://other-server/
</Directory >

How it works

When the IsmProxyPass configuration is present, then the webserver module requests the server manifest file from the server specified by the URL.

For example, a request for:

would normally read the server manifest file from:


but with IsmProxyPass enabled it fetches it from:


instead: all URLs with 'proxy' in the path will map to the other-server.

Please note the trailing / in the URL used for IsmProxyPass, this is mandatory.

The directive should be in the vhost config: /etc/apache2/sites-enabled/vhost.conf and not the global webserver config, /etc/apache2/apache2.conf.

The 'proxy' directory (or any other name used) should not exist on the webserver: it's a virtual path.

For example using /etc/apache2/sites-enabled/usp-evaluation.conf:

<Directory "/var/www/usp-evaluation/proxy">
  IsmProxyPass http://other-server/

So the '/var/www/usp-evaluation' directory exists but the '/var/www/usp-evaluation/proxy' directory does not and maps to http://other-server.

This applies to all examples on this page.


There is limitation on the number of TCP connections that can be open, based on the range of available ports. By default, Linux's set of outgoing ports is something like 31000 - 61000. This should be taken into consideration because when a connection is closed, ports stay reserved in TIME_WAIT status for 60 seconds by default and connections cannot be re-used by Origin. This means that the server may run out of available ports when it needs to make many outgoing requests to serve a large number of incoming requests, which is a plausible scenario when using IsmProxyPass, especially in combination with a proxy cache on the same server. This problem can be solved by distributing requests across more servers, increasing the port range (sysctl net.ipv4.ip_local_port_range), or lowering the timeout (sysctl net.ipv4.tcp_fin_timeout).

Playback content from other domains

Time for a more elaborate example. Let's say the content (an MP4 video) is hosted at: and we want to make this available in the HTTP Smooth Streaming format.

The first step is to set up IsmProxyPass since we want to create a server manifest file dynamically for any given audio/video URLs.

<Directory "/var/www/usp/ism">

The webserver module now requests the server manifest file using the given smil.php script for any URL that starts with

Say you are requesting the Smooth Streaming client manifest file for the MP4 video. The URL in this case is:

The internal URL that the webserver uses to fetch the server manifest file becomes:

The following PHP script generates a smil file with the audio/video tracks pointing to the original content:

$url = $_GET["url"];
Header('Content-Type: text/xml');
echo "<?xml version=\"1.0\" encoding=\"utf-8\"?>"
<smil xmlns="">
      <audio src="<?=htmlspecialchars($url, ENT_QUOTES, 'UTF-8')?>" systemBitrate="1"/>
      <video src="<?=htmlspecialchars($url, ENT_QUOTES, 'UTF-8')?>" systemBitrate="1"/>

Please note that the string 'CACHE_ID' in the above example is just a place holder, it can be anything (or even removed) and may be used for internal tracking (session id etc).

Re-stream content from any domain

A generic setup to re-stream any content from any domain.

This allows you to make any content available in all the playout formats, without any requirements on the webserver running on the proxied domain (i.e. it can be a plain webserver, without support for HDS, HSS or HLS playout capabilities).

The first step is to set up the IsmProxyPass to proxy any content that USP can ingest, e.g. MP4 (.mp4/.smil), HDS (.f4m) or HSS/MPEG-DASH (.ism).

<Directory "/var/www/usp/direct">
  IsmProxyPass http://

Say you are requesting the Smooth Streaming client manifest file for the MP4 video. The URL in this case is:

The webserver running at is a plain webserver and the USP origin running at uses the URL to create the manifest file.

Since USP ingests .mp4, .ism, .smil and .f4m you can ingest all these different formats from any webserver without having to run any additional media server side components on the proxied servers.

Another example would for instance be using content from S3.

For DASH playout:

or HLS: