PAC-C024 · skyhigh-cloud-proxy-port

Skyhigh cloud proxy on a port browsers cannot use

high · Correctness

The Skyhigh Secure Web Gateway cloud proxy c<customer-id>.wgcs.skyhigh.cloud is configured with port 80 or 8080. Port 8081 is the Client Proxy Secure Channel port and is not a browser proxy port; any other port is a dead entry.

Why it matters

Skyhigh documents the proxy as c<customer_id>.wgcs.skyhigh.cloud with “port 80 or 8080”, for example c1234567890.wgcs.skyhigh.cloud:8080. Port 8081 appears in the Skyhigh Client Proxy documentation as the default Secure Channel port (TLS 1.2 between the client agent and the cloud); when Secure Channel is enabled the agent still expects the proxy to be configured with 8080. A PAC that sends browsers to 8081 or any other port produces connection failures and, with a following DIRECT, uninspected traffic.

How to fix

Return "PROXY c<customer-id>.wgcs.skyhigh.cloud:8080" (or :80).

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY c1234567890.wgcs.skyhigh.cloud:8081";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY c1234567890.wgcs.skyhigh.cloud:8080";
}
Open good example in checker

Skyhigh pack only; the customer id in the examples is synthetic.

Related rules

References