Skyhigh Security PAC builder

Builds a PAC file for the Skyhigh Secure Web Gateway cloud proxy (c<customer-id>.wgcs.skyhigh.cloud:8080) or an on-premises Secure Web Gateway, with the gateway itself excluded from proxying and DNS-free bypasses for plain hostnames, private addresses and internal domains.

Skyhigh documents the cloud proxy as c<customer-id>.wgcs.skyhigh.cloud on port 80 or 8080, and for an on-premises Secure Web Gateway it asks that traffic to the gateway itself is never proxied, because block pages, authentication redirects and injected files come from the appliance. Both are built in here.

Not using a security service edge? The PAC file generator builds a file for your own proxies.

    Shown as the customer-specific proxy name c<customer_id>.wgcs.skyhigh.cloud in the Secure Web Gateway setup.

      8081 is the Client Proxy Secure Channel port, not a browser proxy port.

        Only used for the on-premises gateway. It is returned DIRECT for the gateway's own pages and used as the proxy host.

          9090 is the default HTTP proxy port of Secure Web Gateway.

            One per line, without a leading dot; the domain and all its subdomains are matched.

              Uses an IP-literal test in front of isInNet, so host names never trigger a DNS lookup. See isinnet-on-hostname.

                Lowers the grade unless "Accept fail-open" is ticked in the checker settings. See direct-fallback-in-proxy-list.

                  Generated proxy.pac

                  Deploying it

                  Skyhigh Client Proxy coexists with this file without changes: SCP forwards proxied requests when it intercepts the proxy port, and traffic the PAC sends DIRECT is still redirected unless SCP bypasses it by port, destination IP or process. In SCP explicit proxy mode the exceptions in this file are the only bypasses. For an on-premises Secure Web Gateway, host the file on the appliance’s file server (port 4713 HTTP / 4714 HTTPS, path /files/).

                  What the Skyhigh Security pack checks

                  The cloud proxy is c<customer-id>.wgcs.skyhigh.cloud on port 80 or 8080; Skyhigh Client Proxy uses 8081 for its Secure Channel, which is not a browser proxy port. Skyhigh documents that systems using PAC files can coexist with Skyhigh Client Proxy without changing the PAC: SCP forwards proxied requests when it is configured to intercept the proxy port, and traffic the PAC sends DIRECT is still redirected unless SCP bypasses it by port, destination IP or process. In SCP’s explicit proxy mode the bypass lists do not apply at all and the exceptions must live in the PAC file. For an on-premises Secure Web Gateway the PAC must return DIRECT for the gateway itself, because block pages, authentication redirects and injected files are served from the appliance on ports such as 9090, 9094 and 9999.
                  • Cloud proxy: c<customer-id>.wgcs.skyhigh.cloud, port 80 or 8080. The mcafee-cloud.com domain was retired on 2022-12-31; saasprotection.com is the previous name.
                  • Skyhigh Client Proxy and PAC files coexist; SCP intercepts the proxy port only if configured, and its domain/destination-IP bypasses do not apply to requests that arrive already proxied.
                  • In SCP explicit proxy mode, bypasses must be configured in the PAC file.
                  • On-premises Secure Web Gateway: do not proxy traffic to the gateway itself; host the PAC on the file server port (4713 HTTP / 4714 HTTPS, path /files/).

                  Sources

                  Vendor documentation the pack rests on, fetched on the date shown.