IPv6 address in a PROXY statement for Prisma Access
high
Palo Alto Networks' PAC file guidelines state that only IPv4 addresses are supported in PROXY statements. An IPv6 literal does not reach the Explicit Proxy.
Why it matters
The guidelines list the constraints for Explicit Proxy PAC files: ASCII text only, at most 256 KB,
“Only IPv4 addresses are supported in PROXY statements. Do not use IPv6 addresses”, and at least one
Explicit Proxy URL (a configured domain or a valid IPv4 address) in a return statement. Explicit
Proxy itself has no IPv6 support outside the GlobalProtect agent proxy mode. A bracketed IPv6
literal in a PROXY entry is therefore an entry that cannot work for this service, whatever the
browser does with it.
How to fix
Use the Explicit Proxy domain name, e.g. "PROXY <name>.proxy.prismaaccess.com:8080".
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY [2001:db8::10]:8080; PROXY example.proxy.prismaaccess.com:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY example.proxy.prismaaccess.com:8080";
}
Open good example in checkerRelated rules
- IPv4 loopback/private ranges handled, IPv6 equivalents not PAC-C012
- Prisma Access Explicit Proxy on a port other than 8080 PAC-C029