PAC-K019 · prisma-ipv6-proxy-address

IPv6 address in a PROXY statement for Prisma Access

high · Compatibility across engines

Palo Alto Networks' PAC file guidelines state that only IPv4 addresses are supported in PROXY statements. An IPv6 literal does not reach the Explicit Proxy.

Why it matters

The guidelines list the constraints for Explicit Proxy PAC files: ASCII text only, at most 256 KB, “Only IPv4 addresses are supported in PROXY statements. Do not use IPv6 addresses”, and at least one Explicit Proxy URL (a configured domain or a valid IPv4 address) in a return statement. Explicit Proxy itself has no IPv6 support outside the GlobalProtect agent proxy mode. A bracketed IPv6 literal in a PROXY entry is therefore an entry that cannot work for this service, whatever the browser does with it.

How to fix

Use the Explicit Proxy domain name, e.g. "PROXY <name>.proxy.prismaaccess.com:8080".

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY [2001:db8::10]:8080; PROXY example.proxy.prismaaccess.com:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY example.proxy.prismaaccess.com:8080";
}
Open good example in checker

Prisma Access pack only.

Related rules

References