PAC-C029 · prisma-explicit-proxy-port

Prisma Access Explicit Proxy on a port other than 8080

high · Correctness

The Explicit Proxy URL is <name>.proxy.prismaaccess.com on port 8080; the PAC file guidelines and every Palo Alto Networks example return "PROXY <name>.proxy.prismaaccess.com:8080". Another port is a dead entry.

Why it matters

Palo Alto Networks documents the proxy as proxyname.proxy.prismaaccess.com “and uses port 8080”, and the GlobalProtect proxy-mode guidance adds that “port 8080 must be specified in the PAC file”. The sample PAC ends with return "PROXY foo.proxy.prismaaccess.com:8080";. A browser sent to port 443 or 3128 on that host waits for a connection that is not answered and then falls through, so a DIRECT fallback would silently remove Prisma Access from the path.

How to fix

Return "PROXY <name>.proxy.prismaaccess.com:8080".

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY example.proxy.prismaaccess.com:443";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY example.proxy.prismaaccess.com:8080";
}
Open good example in checker

Prisma Access pack only.

Related rules

References