Zscaler PAC builder

Builds a PAC file for Zscaler Internet Access with the ${GATEWAY} variable pair, the documented service-edge ports, DNS-free bypasses for plain hostnames, private addresses and your internal domains, and an optional Forwarding Profile variant for Zscaler Client Connector.

The output follows Zscaler’s own PAC guidance (variables instead of addresses, primary plus secondary gateway, FTP and internal traffic direct) and this site’s rules on top: no DNS lookup on the hot path, host lower-cased, a commented default route. Host the file on the Zscaler cloud, otherwise the ${...} variables stay literal.

Not using a security service edge? The PAC file generator builds a file for your own proxies.

The Forwarding Profile PAC must never send traffic to the cloud itself; the App Profile PAC does that.

    Only used for the hosted / App Profile role.

      Only used for the hosted / App Profile role.

        Ports documented for Public Service Edges. Only used for the hosted / App Profile role.

          One per line, without a leading dot; the generator matches the domain and all its subdomains.

            Uses an IP-literal test in front of isInNet, so host names never trigger a DNS lookup. See isinnet-on-hostname.

              The Zscaler service does not support native FTP; the default PAC files return DIRECT for ftp URLs.

                Lowers the grade unless "Accept fail-open" is ticked in the checker settings. Zscaler Client Connector has its own fallback to gateway.<cloud>.net. See direct-fallback-in-proxy-list.

                  Generated proxy.pac

                  Deploying it

                  Upload under Infrastructure > Internet & SaaS > Traffic Forwarding > Hosted PAC Files, press “Verify PAC File”, stage it for a small group first, then deploy. In Tunnel mode, remember that Zscaler Client Connector intercepts port 80/443 traffic regardless of this file; domain bypasses belong in the App Profile PAC, IP bypasses in destination exclusions or VPN gateway bypasses.

                  What the Zscaler pack checks

                  A Zscaler-hosted PAC file is a template: the PAC server replaces ${GATEWAY}, ${SECONDARY_GATEWAY} and the other documented variables with the address of the closest Public Service Edge before the browser sees the file. Zscaler Client Connector uses two PAC files with different jobs. The Forwarding Profile PAC steers system, browser and application traffic to the client (or away from it), and the App Profile PAC tells the client where in the Zscaler cloud to send what it received. In Tunnel mode the client intercepts port 80 and 443 traffic regardless of the PAC, so a DIRECT in the PAC does not bypass the client on its own.
                  • Variables only expand when the PAC file is hosted on the Zscaler cloud; in a self-hosted file they stay literal.
                  • Public Service Edges accept browser traffic on ports 80, 443, 9400, 9443 and 9480; dedicated ports exist by subscription.
                  • Primary plus secondary gateway gives failover; Zscaler Client Connector additionally falls back to gateway.<cloud>.net unless disabled.
                  • In Tunnel mode the Forwarding Profile PAC must not send traffic to the Zscaler cloud; that is the App Profile PAC's job.
                  • Domain-based bypasses live in the PAC files; IP-based bypasses for Z-Tunnel 2.0 belong in destination exclusions or VPN gateway bypasses, not in the PAC.

                  Sources

                  Vendor documentation the pack rests on, fetched on the date shown.