Skyhigh Security PAC builder
Builds a PAC file for the Skyhigh Secure Web Gateway cloud proxy (c<customer-id>.wgcs.skyhigh.cloud:8080) or an on-premises Secure Web Gateway, with the gateway itself excluded from proxying and DNS-free bypasses for plain hostnames, private addresses and internal domains.
Skyhigh documents the cloud proxy as c<customer-id>.wgcs.skyhigh.cloud on port 80 or 8080, and
for an on-premises Secure Web Gateway it asks that traffic to the gateway itself is never proxied,
because block pages, authentication redirects and injected files come from the appliance. Both are
built in here.
Generated proxy.pac
[{"default":"cloud","id":"mode","label":"Gateway","options":[{"label":"Skyhigh cloud proxy (c\u003ccustomer-id\u003e.wgcs.skyhigh.cloud)","value":"cloud"},{"label":"On-premises Secure Web Gateway","value":"onprem"}],"type":"select"},{"default":"1234567890","help":"Shown as the customer-specific proxy name c\u003ccustomer_id\u003e.wgcs.skyhigh.cloud in the Secure Web Gateway setup.","id":"customer_id","label":"Customer ID (10 digits, for the cloud proxy)","pattern":"^[0-9]{10}$","pattern_help":"exactly 10 digits, without the leading c","type":"text"},{"default":"8080","help":"8081 is the Client Proxy Secure Channel port, not a browser proxy port.","id":"cloud_port","label":"Cloud proxy port","options":[{"label":"8080 (documented default)","value":"8080"},{"label":"80","value":"80"}],"type":"select"},{"default":"swg.corp.example","help":"Only used for the on-premises gateway. It is returned DIRECT for the gateway's own pages and used as the proxy host.","id":"swg_host","label":"On-premises gateway host name or address","pattern":"^[a-z0-9-]+(\\.[a-z0-9-]+)*$","pattern_help":"a host name or IPv4 address","type":"text"},{"default":"9090","help":"9090 is the default HTTP proxy port of Secure Web Gateway.","id":"swg_port","label":"On-premises gateway proxy port","pattern":"^[0-9]{2,5}$","pattern_help":"a port number","type":"text"},{"default":["corp.example"],"help":"One per line, without a leading dot; the domain and all its subdomains are matched.","id":"internal_domains","item_pattern":"^[a-z0-9-]+(\\.[a-z0-9-]+)+$","label":"Internal DNS suffixes that go direct","max":50,"pattern_help":"must be a domain such as corp.example (no leading dot, no wildcard)","type":"list"},{"default":true,"help":"Uses an IP-literal test in front of isInNet, so host names never trigger a DNS lookup.","id":"bypass_private","label":"Plain hostnames and private (RFC 1918) addresses go direct","rules":["isinnet-on-hostname"],"type":"checkbox"},{"default":false,"grade_note":"Lowers the grade unless \"Accept fail-open\" is ticked in the checker settings.","id":"direct_fallback","label":"Add \"; DIRECT\" after the proxy (fail open when it is unreachable)","rules":["direct-fallback-in-proxy-list"],"type":"checkbox"}]// proxy.pac for Skyhigh Secure Web Gateway, generated by findproxyforurl.net
function FindProxyForURL(url, host) {
host = host.toLowerCase();
{{#if bypass_private}}
// plain hostnames (no dot) stay on the local network
if (isPlainHostName(host)) {
return "DIRECT";
}
// RFC 1918 and loopback addresses: literal IPs only, no DNS lookup for names
if (/^\d+\.\d+\.\d+\.\d+$/.test(host) &&
(isInNet(host, "10.0.0.0", "255.0.0.0") ||
isInNet(host, "172.16.0.0", "255.240.0.0") ||
isInNet(host, "192.168.0.0", "255.255.0.0") ||
isInNet(host, "127.0.0.0", "255.0.0.0"))) {
return "DIRECT";
}
{{/if}}
{{#if internal_domains}}
// internal domains and their subdomains go direct
if ({{#each internal_domains sep=" ||\n "}}dnsDomainIs(host, ".{{.}}"){{/each}}) {
return "DIRECT";
}
{{/if}}
{{#if mode == "onprem"}}
// the gateway serves block pages, authentication redirects and injected files itself: never proxy it
if (shExpMatch(host, "{{swg_host}}")) {
return "DIRECT";
}
// default: everything else goes to the Secure Web Gateway
return "PROXY {{swg_host}}:{{swg_port}}{{#if direct_fallback}}; DIRECT{{/if}}";
{{/if}}
{{#if mode == "cloud"}}
// default: everything else goes to the Skyhigh cloud proxy (port 80 or 8080)
return "PROXY c{{customer_id}}.wgcs.skyhigh.cloud:{{cloud_port}}{{#if direct_fallback}}; DIRECT{{/if}}";
{{/if}}
}
Deploying it
Skyhigh Client Proxy coexists with this file without changes: SCP forwards proxied requests when it
intercepts the proxy port, and traffic the PAC sends DIRECT is still redirected unless SCP bypasses
it by port, destination IP or process. In SCP explicit proxy mode the exceptions in this file are
the only bypasses. For an on-premises Secure Web Gateway, host the file on the appliance’s file
server (port 4713 HTTP / 4714 HTTPS, path /files/).
What the Skyhigh Security pack checks
The cloud proxy is
c<customer-id>.wgcs.skyhigh.cloud on port 80 or 8080; Skyhigh Client Proxy uses
8081 for its Secure Channel, which is not a browser proxy port. Skyhigh documents that systems using
PAC files can coexist with Skyhigh Client Proxy without changing the PAC: SCP forwards proxied requests
when it is configured to intercept the proxy port, and traffic the PAC sends DIRECT is still redirected
unless SCP bypasses it by port, destination IP or process. In SCP’s explicit proxy mode the bypass
lists do not apply at all and the exceptions must live in the PAC file. For an on-premises Secure Web
Gateway the PAC must return DIRECT for the gateway itself, because block pages, authentication
redirects and injected files are served from the appliance on ports such as 9090, 9094 and 9999.- Cloud proxy: c<customer-id>.wgcs.skyhigh.cloud, port 80 or 8080. The mcafee-cloud.com domain was retired on 2022-12-31; saasprotection.com is the previous name.
- Skyhigh Client Proxy and PAC files coexist; SCP intercepts the proxy port only if configured, and its domain/destination-IP bypasses do not apply to requests that arrive already proxied.
- In SCP explicit proxy mode, bypasses must be configured in the PAC file.
- On-premises Secure Web Gateway: do not proxy traffic to the gateway itself; host the PAC on the file server port (4713 HTTP / 4714 HTTPS, path /files/).
- PAC-C024Skyhigh cloud proxy on a port browsers cannot use high
- PAC-K018Legacy Skyhigh / McAfee cloud proxy domain low
- PAC-C025Secure Web Gateway itself is not returned DIRECT medium
- PAC-C026Plain hostnames or private addresses are sent to the cloud proxy medium
- PAC-B014DIRECT in the PAC does not bypass the vendor's agent info
- PAC-B015Selected vendor pack, but the PAC never routes to that vendor info
Sources
- Using Client Proxy with Existing PAC Files
- Proxy and Customer ID
- Secure the Communication Channel between Client Proxy and WGCS
- Updating IP Address Ranges and the Legacy Proxy Domain Name
- Alternate Proxy Support for Explicit Proxy Mode
- Bypass the Proxy Server (Client Proxy bypass list)
- Using Proxy Automatic Configuration with Web Gateway
- Make a .pac File Available (Secure Web Gateway on-prem)