Prisma Access service domains not returned DIRECT
info
Palo Alto Networks requires the PAC to bypass the Authentication Cache Service (*.acs.prismaaccess.com) and, when GlobalProtect is used alongside Explicit Proxy, *.prismaaccess.com and *.gpcloudservice.com. Sending that traffic to the proxy breaks authentication or the agent connection.
Why it matters
The PAC file guidelines’ sample bypasses *.acs.prismaaccess.com (“Bypass ACS”) and the best
practices say to “bypass all SAML, CIE, and Authentication Cache Service (ACS) URLs” when setting up
the PAC. The GlobalProtect coexistence pages add *.prismaaccess.com, *.gpcloudservice.com, the
portal and gateway names and, in Tunnel and Proxy mode, *.rbi.io. The ACS bypass is rated high:
the SAML flow redirects the browser to the ACS, and if that request is proxied to the authenticating
proxy the user never completes the login. The GlobalProtect domains are rated low because they only
matter when the agent is deployed; add them anyway if it is.
How to fix
Before the proxy return add if (shExpMatch(host, "*.acs.prismaaccess.com") || shExpMatch(host, "*.gpcloudservice.com")) return "DIRECT";
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY example.proxy.prismaaccess.com:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
if (shExpMatch(host, "*.acs.prismaaccess.com") || shExpMatch(host, "*.gpcloudservice.com")) {
return "DIRECT";
}
return "PROXY example.proxy.prismaaccess.com:8080";
}
Open good example in checkerRelated rules
- Identity provider not excluded from the SSE proxy PAC-C022
- Prisma Access Explicit Proxy on a port other than 8080 PAC-C029
References
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/pac-file-guidelines
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/explicit-proxy-best-practices
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/use-explicit-proxy-with-globalprotect-or-a-third-party-vpn/explicit-proxy-and-globalprotect-set-it-up