# Netskope and Cloudflare Gateway PAC files: the checks that matter

Source: https://findproxyforurl.net/articles/netskope-cloudflare-pac-checklist/ · updated 2026-10-06

Cloud proxies are strict about how a browser connects. A PAC file that would be fine for an on-premises proxy can fail completely against Netskope or Cloudflare Gateway because of one port or one keyword. Here are the checks, each based on the vendor's own documentation.

Each check links to its rule. The rule page quotes and links the vendor documentation it relies on
(source: doc, as cited in our rule catalogue, October 2026). In the [PAC file tester](https://findproxyforurl.net/check/),
choose the vendor under **Environment** to run all of them. The [SSE PAC builders](https://findproxyforurl.net/generate/sse/)
write files that follow them.

## Netskope

1. **The right port.** Cloud Explicit Proxy expects `PROXY eproxy-<tenant>:8081`. Explicit Proxy over
   Tunnel uses `163.116.128.80` / `163.116.128.81` or `epot.goskope.com` on port 80 (recommended) or
   8080. Netskope drops other ports, so the browser waits and fails over
   ([PAC-C021](https://findproxyforurl.net/rules/netskope-explicit-proxy-port/)).
2. **Declare other proxies.** If the PAC also sends traffic to another proxy while the Netskope
   Client runs, Netskope requires that proxy to be listed under "Interoperate with Proxy". Otherwise
   the Client neither steers nor logs it ([PAC-B013](https://findproxyforurl.net/rules/netskope-undeclared-third-party-proxy/)).
3. **HTTP and HTTPS only.** Netskope's template returns the proxy only for `http:` and `https:` URLs
   and `DIRECT` otherwise ([PAC-C023](https://findproxyforurl.net/rules/sse-proxy-for-non-http-schemes/)).

## Cloudflare Gateway proxy endpoints

1. **`HTTPS`, not `PROXY`.** The endpoint only accepts TLS from the browser:
   `return "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443";`. `PROXY` to the same host never
   connects ([PAC-C027](https://findproxyforurl.net/rules/cloudflare-gateway-endpoint-needs-https-keyword/)).
2. **Port 443.** Every Cloudflare example uses 443, and other ports do not answer
   ([PAC-C028](https://findproxyforurl.net/rules/cloudflare-gateway-endpoint-port/)).
3. **Know your clients.** According to Cloudflare's documentation, Chromium and Firefox support the
   `HTTPS` proxy type in PAC files. Safari and iOS/iPadOS do not (source: doc, 2026-10-04). Clients
   without `HTTPS` support need another path ([PAC-K006](https://findproxyforurl.net/rules/https-proxy-keyword-without-fallback/)).

## Both vendors

- **Local traffic first.** Plain host names and private addresses cannot be reached through a cloud
  proxy. Send them `DIRECT` at the top of the function, without DNS lookups
  ([PAC-C026](https://findproxyforurl.net/rules/sse-local-traffic-not-bypassed/), [DNS in PAC files](https://findproxyforurl.net/articles/dns-in-pac-files/)).
- **A DIRECT in the PAC is not a bypass of the agent.** With the vendor's client installed, traffic
  the PAC sends direct can still be intercepted by the agent. Mirror real bypasses in the agent's
  own configuration ([PAC-B014](https://findproxyforurl.net/rules/agent-intercepts-pac-direct-traffic/)).
- **Write ES5.** The same file is often read by Windows services through WinHTTP, which rejects
  `let`, `const` and arrow functions ([PAC-K001](https://findproxyforurl.net/rules/es2015-syntax/)).

Using Zscaler? See the [Zscaler PAC file checklist](https://findproxyforurl.net/articles/zscaler-pac-file-checklist/).


## Frequently asked questions

### Which port does a Netskope PAC file use?

Netskope Cloud Explicit Proxy expects port 8081 (PROXY eproxy-<tenant>:8081). Explicit Proxy over IPsec or GRE tunnels uses 163.116.128.80/81 or epot.goskope.com on port 80 (recommended) or 8080. Other ports are dropped.

### Why does my Cloudflare Gateway PAC file not work?

Usually because it returns PROXY instead of HTTPS. Cloudflare Gateway proxy endpoints only accept TLS from the browser, so the entry must be "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443". Also check that the port is 443.

### How do I test a Netskope or Cloudflare PAC file?

Paste it into findproxyforurl.net/check/, open Environment and choose Netskope or Cloudflare as the security service edge vendor. The tester adds the vendor checks to the generic rules.

