DIRECT as fallback after a proxy
info
"PROXY proxy.corp.example:8080; DIRECT" keeps users online when the proxy is down, at the price of uninspected traffic during the outage. Make sure that trade-off is intended.
Why it matters
Browsers try the entries in order and move on when a connection to a proxy fails. A
trailing DIRECT therefore means: if the proxy is down (or blocked, or the laptop is on a
network where the proxy is unreachable), send everything directly. For a roaming laptop
that is often the intended behaviour; for a managed desktop behind a default-deny firewall
it is a policy gap that is invisible until the proxy has an incident. Browsers also
remember a failed proxy for some minutes, so a short outage turns into a longer bypass.
A second proxy as fallback keeps inspection in place.
How to fix
Prefer a second proxy ("PROXY p1:8080; PROXY p2:8080"); keep DIRECT fallback only where uninspected traffic during an outage is acceptable, and say so in a comment.
Examples
Bad
function FindProxyForURL(url, host) {
return "PROXY proxy1.corp.example:8080; DIRECT";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open good example in checkerRelated rules
- Single proxy without a fallback entry PAC-B011
- No unconditional return at the end of FindProxyForURL PAC-X001