PAC-C030 · prisma-service-domains-not-bypassed

Prisma Access service domains not returned DIRECT

info · Correctness

Palo Alto Networks requires the PAC to bypass the Authentication Cache Service (*.acs.prismaaccess.com) and, when GlobalProtect is used alongside Explicit Proxy, *.prismaaccess.com and *.gpcloudservice.com. Sending that traffic to the proxy breaks authentication or the agent connection.

Why it matters

The PAC file guidelines’ sample bypasses *.acs.prismaaccess.com (“Bypass ACS”) and the best practices say to “bypass all SAML, CIE, and Authentication Cache Service (ACS) URLs” when setting up the PAC. The GlobalProtect coexistence pages add *.prismaaccess.com, *.gpcloudservice.com, the portal and gateway names and, in Tunnel and Proxy mode, *.rbi.io. The ACS bypass is rated high: the SAML flow redirects the browser to the ACS, and if that request is proxied to the authenticating proxy the user never completes the login. The GlobalProtect domains are rated low because they only matter when the agent is deployed; add them anyway if it is.

How to fix

Before the proxy return add if (shExpMatch(host, "*.acs.prismaaccess.com") || shExpMatch(host, "*.gpcloudservice.com")) return "DIRECT";

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY example.proxy.prismaaccess.com:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  if (shExpMatch(host, "*.acs.prismaaccess.com") || shExpMatch(host, "*.gpcloudservice.com")) {
    return "DIRECT";
  }
  return "PROXY example.proxy.prismaaccess.com:8080";
}
Open good example in checker

Prisma Access pack only.

Related rules

References