Prisma Access Explicit Proxy on a port other than 8080
high
The Explicit Proxy URL is <name>.proxy.prismaaccess.com on port 8080; the PAC file guidelines and every Palo Alto Networks example return "PROXY <name>.proxy.prismaaccess.com:8080". Another port is a dead entry.
Why it matters
Palo Alto Networks documents the proxy as proxyname.proxy.prismaaccess.com “and uses port 8080”,
and the GlobalProtect proxy-mode guidance adds that “port 8080 must be specified in the PAC file”.
The sample PAC ends with return "PROXY foo.proxy.prismaaccess.com:8080";. A browser sent to port
443 or 3128 on that host waits for a connection that is not answered and then falls through, so a
DIRECT fallback would silently remove Prisma Access from the path.
How to fix
Return "PROXY <name>.proxy.prismaaccess.com:8080".
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY example.proxy.prismaaccess.com:443";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY example.proxy.prismaaccess.com:8080";
}
Open good example in checkerRelated rules
- Proxy port out of range or not numeric PAC-E012
- Prisma Access service domains not returned DIRECT PAC-C030
References
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/set-up-explicit-proxy
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/pac-file-guidelines
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode