PAC-X014 · direct-fallback-in-proxy-list

DIRECT as fallback after a proxy

info · Security and fail-safety

"PROXY proxy.corp.example:8080; DIRECT" keeps users online when the proxy is down, at the price of uninspected traffic during the outage. Make sure that trade-off is intended.

Why it matters

Browsers try the entries in order and move on when a connection to a proxy fails. A trailing DIRECT therefore means: if the proxy is down (or blocked, or the laptop is on a network where the proxy is unreachable), send everything directly. For a roaming laptop that is often the intended behaviour; for a managed desktop behind a default-deny firewall it is a policy gap that is invisible until the proxy has an incident. Browsers also remember a failed proxy for some minutes, so a short outage turns into a longer bypass. A second proxy as fallback keeps inspection in place.

How to fix

Prefer a second proxy ("PROXY p1:8080; PROXY p2:8080"); keep DIRECT fallback only where uninspected traffic during an outage is acceptable, and say so in a comment.

Examples

Bad

function FindProxyForURL(url, host) {
  return "PROXY proxy1.corp.example:8080; DIRECT";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open good example in checker

Related rules

References