Netskope and Cloudflare Gateway PAC files: the checks that matter

Published

Cloud proxies are strict about how a browser connects. A PAC file that would be fine for an on-premises proxy can fail completely against Netskope or Cloudflare Gateway because of one port or one keyword. Here are the checks, each based on the vendor's own documentation.

Each check links to its rule. The rule page quotes and links the vendor documentation it relies on (source: doc, as cited in our rule catalogue, October 2026). In the PAC file tester, choose the vendor under Environment to run all of them. The SSE PAC builders write files that follow them.

Netskope

  1. The right port. Cloud Explicit Proxy expects PROXY eproxy-<tenant>:8081. Explicit Proxy over Tunnel uses 163.116.128.80 / 163.116.128.81 or epot.goskope.com on port 80 (recommended) or 8080. Netskope drops other ports, so the browser waits and fails over (PAC-C021).
  2. Declare other proxies. If the PAC also sends traffic to another proxy while the Netskope Client runs, Netskope requires that proxy to be listed under “Interoperate with Proxy”. Otherwise the Client neither steers nor logs it (PAC-B013).
  3. HTTP and HTTPS only. Netskope’s template returns the proxy only for http: and https: URLs and DIRECT otherwise (PAC-C023).

Cloudflare Gateway proxy endpoints

  1. HTTPS, not PROXY. The endpoint only accepts TLS from the browser: return "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443";. PROXY to the same host never connects (PAC-C027).
  2. Port 443. Every Cloudflare example uses 443, and other ports do not answer (PAC-C028).
  3. Know your clients. According to Cloudflare’s documentation, Chromium and Firefox support the HTTPS proxy type in PAC files. Safari and iOS/iPadOS do not (source: doc, 2026-10-04). Clients without HTTPS support need another path (PAC-K006).

Both vendors

  • Local traffic first. Plain host names and private addresses cannot be reached through a cloud proxy. Send them DIRECT at the top of the function, without DNS lookups (PAC-C026, DNS in PAC files).
  • A DIRECT in the PAC is not a bypass of the agent. With the vendor’s client installed, traffic the PAC sends direct can still be intercepted by the agent. Mirror real bypasses in the agent’s own configuration (PAC-B014).
  • Write ES5. The same file is often read by Windows services through WinHTTP, which rejects let, const and arrow functions (PAC-K001).

Using Zscaler? See the Zscaler PAC file checklist.

Frequently asked questions

Which port does a Netskope PAC file use?

Netskope Cloud Explicit Proxy expects port 8081 (PROXY eproxy-<tenant>:8081). Explicit Proxy over IPsec or GRE tunnels uses 163.116.128.80/81 or epot.goskope.com on port 80 (recommended) or 8080. Other ports are dropped.

Why does my Cloudflare Gateway PAC file not work?

Usually because it returns PROXY instead of HTTPS. Cloudflare Gateway proxy endpoints only accept TLS from the browser, so the entry must be "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443". Also check that the port is 443.

How do I test a Netskope or Cloudflare PAC file?

Paste it into findproxyforurl.net/check/, open Environment and choose Netskope or Cloudflare as the security service edge vendor. The tester adds the vendor checks to the generic rules.