PAC-C021 · netskope-explicit-proxy-port

Netskope explicit proxy on the wrong port

high · Correctness

Netskope's Cloud Explicit Proxy requires the browser to use port 8081; Explicit Proxy over Tunnel uses 163.116.128.80/81 or epot.goskope.com on port 80 (recommended) or 8080. Other ports are dropped, so the browser waits, fails and falls through.

Why it matters

The Cloud Explicit Proxy page states that “the user’s browser must be set up to use port 8081” and the sample PAC returns PROXY eproxy-<tenant>:8081. For Explicit Proxy over IPSec or GRE tunnels the documented destinations are the reserved addresses 163.116.128.80 and 163.116.128.81 or epot.goskope.com, on port 80 (strongly recommended) or 8080 (needs the port added under Non-Standard Ports), and “all other port traffic will be dropped”. A PAC that sends browsers to eproxy-<tenant>:8080 or to the tunnel address on 3128 therefore produces timeouts, not proxied traffic, and if a DIRECT entry follows the user is online without Netskope.

How to fix

Cloud Explicit Proxy: "PROXY eproxy-<tenant>:8081". Explicit Proxy over Tunnel: "PROXY 163.116.128.80:80" (or epot.goskope.com:80).

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY eproxy-exampletenant.goskope.com:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY eproxy-exampletenant.goskope.com:8081";
}
Open good example in checker

Netskope pack only.

Related rules

References