PAC builders for SSE vendors

Pick your security service edge, answer a few questions and download a PAC file that follows the vendor's own documentation and this site's rules. Each builder links to the checker with its vendor pack preselected.

These builders cover the common cases: forward web traffic to the vendor’s gateway, keep plain hostnames, private addresses and your internal domains direct, bypass what the vendor says must be bypassed (identity providers, authentication services, FTP), and document the default route. They do not try to encode bypass policy for SaaS or streaming destinations; that belongs on the proxy or in the agent’s configuration.

With an agent installed (Zscaler Client Connector, Netskope Client, Skyhigh Client Proxy, GlobalProtect), the PAC is evaluated first by the browser or OS and the agent intercepts afterwards at the network layer. A DIRECT in the PAC therefore means “not through this proxy”, not “not through the agent”. The vendor packs in the checker report exactly that interaction.

You run your own proxies? The PAC file generator builds a file for them, with a comment on every entry.