Netskope explicit proxy PAC builder

Builds a PAC file for Netskope Cloud Explicit Proxy (eproxy-<tenant>:8081) or Explicit Proxy over IPSec/GRE tunnels, with the identity-provider exception Netskope requires, DNS-free local bypasses and an http/https-only proxy rule.

Netskope’s sample template normalises the URL and host, sends plain hostnames direct, leaves a commented block for IdP and other exceptions and returns PROXY eproxy-<tenant>:8081 for http and https URLs. This builder fills in the exception blocks and keeps the rest.

Not using a security service edge? The PAC file generator builds a file for your own proxies.

    Exactly as shown under Settings > Security Cloud Platform > Explicit Proxy > Tenant Name; the sample PAC uses eproxy-<Tenant Name>.

      Netskope relies on the IdP for the user identity and requires IdP traffic to go directly to the IdP.

        One per line; the domain and all its subdomains are matched.

          One per line, without a leading dot. With the Netskope Client installed, add the same domains as steering exceptions.

            Uses an IP-literal test in front of isInNet, so host names never trigger a DNS lookup. See isinnet-on-hostname.

              The explicit proxy accepts HTTP and HTTPS only and drops other protocols.

                Netskope describes this as fail-through when the upstream proxy or tunnel is down. It lowers the grade unless "Accept fail-open" is ticked in the checker settings. See direct-fallback-in-proxy-list.

                  Generated proxy.pac

                  Deploying it

                  Host the file on-premises or on a web server your devices can reach, distribute the URL by GPO, MDM or WPAD. If the Netskope Client is installed too, remember that it steers at the TCP level: a DIRECT here bypasses the explicit proxy, not the Client, and any other proxy this file returns must be declared under Interoperate with Proxy.

                  What the Netskope pack checks

                  Netskope ships a PAC template for its Cloud Explicit Proxy that returns PROXY eproxy-<tenant>:8081 for http and https URLs, bypasses plain hostnames and leaves a commented block for identity-provider and other exceptions. The explicit proxy accepts HTTP and HTTPS only and relies on the IdP for user identity, so IdP traffic must go DIRECT. When the Netskope Client is installed as well, it steers at the TCP level and watches HTTP CONNECT requests to on-premises proxies: a DIRECT in the PAC bypasses your proxy, not the Client, and any other proxy the PAC returns must be declared under “Interoperate with Proxy” so that the Client can analyse those requests.
                  • Cloud Explicit Proxy: the browser must use port 8081; only HTTP and HTTPS belong on it.
                  • Explicit Proxy over Tunnel: 163.116.128.80/81 or epot.goskope.com on port 80 (recommended) or 8080; other protocols and ports are dropped.
                  • IdP requests must not be sent to Netskope; add the IdP to the PAC exceptions.
                  • A DIRECT statement at the end of the proxy list is described by Netskope as fail-through when the upstream proxy or tunnel is down; this site caps such files at B unless fail-open is accepted in the settings.
                  • Netskope Client: proxies the PAC returns, other than Netskope's, must be declared under Interoperate with Proxy.

                  Sources

                  Vendor documentation the pack rests on, fetched on the date shown.