Netskope explicit proxy on the wrong port
high
Netskope's Cloud Explicit Proxy requires the browser to use port 8081; Explicit Proxy over Tunnel uses 163.116.128.80/81 or epot.goskope.com on port 80 (recommended) or 8080. Other ports are dropped, so the browser waits, fails and falls through.
Why it matters
The Cloud Explicit Proxy page states that “the user’s browser must be set up to use port 8081” and
the sample PAC returns PROXY eproxy-<tenant>:8081. For Explicit Proxy over IPSec or GRE tunnels
the documented destinations are the reserved addresses 163.116.128.80 and 163.116.128.81 or
epot.goskope.com, on port 80 (strongly recommended) or 8080 (needs the port added under
Non-Standard Ports), and “all other port traffic will be dropped”. A PAC that sends browsers to
eproxy-<tenant>:8080 or to the tunnel address on 3128 therefore produces timeouts, not proxied
traffic, and if a DIRECT entry follows the user is online without Netskope.
How to fix
Cloud Explicit Proxy: "PROXY eproxy-<tenant>:8081". Explicit Proxy over Tunnel: "PROXY 163.116.128.80:80" (or epot.goskope.com:80).
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY eproxy-exampletenant.goskope.com:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY eproxy-exampletenant.goskope.com:8081";
}
Open good example in checkerRelated rules
- Proxy port out of range or not numeric PAC-E012
- Identity provider not excluded from the SSE proxy PAC-C022