Netskope and Cloudflare Gateway PAC files: the checks that matter
Cloud proxies are strict about how a browser connects. A PAC file that would be fine for an on-premises proxy can fail completely against Netskope or Cloudflare Gateway because of one port or one keyword. Here are the checks, each based on the vendor's own documentation.
Each check links to its rule. The rule page quotes and links the vendor documentation it relies on (source: doc, as cited in our rule catalogue, October 2026). In the PAC file tester, choose the vendor under Environment to run all of them. The SSE PAC builders write files that follow them.
Netskope
- The right port. Cloud Explicit Proxy expects
PROXY eproxy-<tenant>:8081. Explicit Proxy over Tunnel uses163.116.128.80/163.116.128.81orepot.goskope.comon port 80 (recommended) or 8080. Netskope drops other ports, so the browser waits and fails over (PAC-C021). - Declare other proxies. If the PAC also sends traffic to another proxy while the Netskope Client runs, Netskope requires that proxy to be listed under “Interoperate with Proxy”. Otherwise the Client neither steers nor logs it (PAC-B013).
- HTTP and HTTPS only. Netskope’s template returns the proxy only for
http:andhttps:URLs andDIRECTotherwise (PAC-C023).
Cloudflare Gateway proxy endpoints
HTTPS, notPROXY. The endpoint only accepts TLS from the browser:return "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443";.PROXYto the same host never connects (PAC-C027).- Port 443. Every Cloudflare example uses 443, and other ports do not answer (PAC-C028).
- Know your clients. According to Cloudflare’s documentation, Chromium and Firefox support the
HTTPSproxy type in PAC files. Safari and iOS/iPadOS do not (source: doc, 2026-10-04). Clients withoutHTTPSsupport need another path (PAC-K006).
Both vendors
- Local traffic first. Plain host names and private addresses cannot be reached through a cloud
proxy. Send them
DIRECTat the top of the function, without DNS lookups (PAC-C026, DNS in PAC files). - A DIRECT in the PAC is not a bypass of the agent. With the vendor’s client installed, traffic the PAC sends direct can still be intercepted by the agent. Mirror real bypasses in the agent’s own configuration (PAC-B014).
- Write ES5. The same file is often read by Windows services through WinHTTP, which rejects
let,constand arrow functions (PAC-K001).
Using Zscaler? See the Zscaler PAC file checklist.
Frequently asked questions
Which port does a Netskope PAC file use?
Netskope Cloud Explicit Proxy expects port 8081 (PROXY eproxy-<tenant>:8081). Explicit Proxy over IPsec or GRE tunnels uses 163.116.128.80/81 or epot.goskope.com on port 80 (recommended) or 8080. Other ports are dropped.
Why does my Cloudflare Gateway PAC file not work?
Usually because it returns PROXY instead of HTTPS. Cloudflare Gateway proxy endpoints only accept TLS from the browser, so the entry must be "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443". Also check that the port is 443.
How do I test a Netskope or Cloudflare PAC file?
Paste it into findproxyforurl.net/check/, open Environment and choose Netskope or Cloudflare as the security service edge vendor. The tester adds the vendor checks to the generic rules.