Long list of public hostnames routed around the proxy
low
A PAC that lists dozens of public SaaS, identity-provider or update hostnames as DIRECT has turned into a security policy document with weak change control. Routing belongs in the PAC; bypass and inspection decisions belong on the proxy.
Why it matters
Every DIRECT entry for a public destination is uninspected, unlogged traffic, and the list must be changed through the slow PAC pipeline (edit, deploy, firewall rule for the bypass, cache expiry, client restart). Proxies and SWGs have category-based “do not inspect” rules and SNI-based tunnel lists that solve certificate pinning without MITM, with audit trails and immediate effect. The PAC should decide proxy-versus-direct for network reasons (internal ranges, local sites); it should not carry the exception list of the inspection policy. Cloud gateways without an on-premises policy engine are the exception where the PAC is the only place for such lists; even then keep it short. Draft: the public/internal heuristic needs tuning on real files.
How to fix
Move SaaS/IdP/pinned-app exceptions to the proxy (do-not-inspect categories, SNI tunnel list); keep only network routing in the PAC.
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".saas-one.example") || dnsDomainIs(host, ".saas-two.example") ||
dnsDomainIs(host, ".idp-login.example") || dnsDomainIs(host, ".push-service.example") ||
dnsDomainIs(host, ".updates.example") || dnsDomainIs(host, ".video-calls.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
// SaaS, IdP and pinned-app exceptions are configured on the proxy, not here
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- PAC file is large PAC-P006
- Many conditions and branches PAC-P007