Prisma Access Explicit Proxy PAC builder

Builds a PAC file for Prisma Access Explicit Proxy (<name>.proxy.prismaaccess.com:8080) with the Authentication Cache Service, identity-provider, FTP and private-address bypasses the PAC file guidelines require, plus the GlobalProtect domains when the agent runs alongside.

Palo Alto Networks’ sample PAC bypasses localhost and private addresses, FTP, the SAML provider and the Authentication Cache Service, then forwards to the proxy on port 8080. This builder keeps that order, resolves private ranges without a DNS lookup per request and adds the GlobalProtect domains when you select a coexistence mode.

Not using a security service edge? The PAC file generator builds a file for your own proxies.

The subdomain you specified for the Explicit Proxy URL; the proxy listens on port 8080.

    The best practices say to bypass all SAML, Cloud Identity Engine and Authentication Cache Service URLs.

      One per line; the domain and all its subdomains are matched.

        The portal and gateway names live under gpcloudservice.com; add your own portal name under internal domains if it is elsewhere.

          One per line, without a leading dot; the domain and all its subdomains are matched. Private apps reached through GlobalProtect belong here.

            Uses an IP-literal test in front of isInNet, so host names never trigger a DNS lookup. See isinnet-on-hostname.

              Explicit Proxy supports HTTP and HTTPS only; the sample PAC bypasses FTP.

                Lowers the grade unless "Accept fail-open" is ticked in the checker settings. The Prisma Access sample has no DIRECT fallback. See direct-fallback-in-proxy-list.

                  Generated proxy.pac

                  Deploying it

                  Upload the file through a Forwarding Profile (Prisma Access hosts it) or on your own server. ASCII only, 256 KB at most, IPv4 or domain names in PROXY statements. In GlobalProtect Tunnel and Proxy mode, traffic this file returns DIRECT is still subject to the split-tunnel rules.

                  What the Prisma Access pack checks

                  Explicit Proxy listens on <name>.proxy.prismaaccess.com:8080 and accepts HTTP and HTTPS only. The PAC file (256 KB, ASCII, IPv4 or domain names in PROXY statements) must bypass the Authentication Cache Service (*.acs.prismaaccess.com), the SAML identity provider, private addresses and FTP, otherwise authentication loops or the traffic is dropped. With GlobalProtect in Proxy mode the app pushes the PAC to the endpoint; in Tunnel and Proxy mode internet traffic follows the PAC while everything the PAC returns DIRECT is still subject to the split-tunnel rules, and *.prismaaccess.com, *.gpcloudservice.com and the portal and gateway names must be excluded from the proxy.
                  • Port 8080; only IPv4 addresses or domain names in PROXY statements; ASCII; 256 KB maximum.
                  • Bypass SAML, Cloud Identity Engine and Authentication Cache Service URLs in the PAC.
                  • GlobalProtect coexistence: bypass *.prismaaccess.com, *.gpcloudservice.com (portal and gateways) and, in Tunnel and Proxy mode, *.rbi.io.
                  • URL filtering actions continue and override are not supported with Explicit Proxy.

                  Sources

                  Vendor documentation the pack rests on, fetched on the date shown.