Legacy Skyhigh / McAfee cloud proxy domain
low
The cloud proxy moved from mcafee-cloud.com (retired at the end of 2022) and saasprotection.com to wgcs.skyhigh.cloud. A PAC that still names the retired domain has no proxy; one that names the previous domain works today but should be migrated.
Why it matters
Skyhigh retired the mcafee-cloud.com legacy proxy domain on 31 December 2022 and asks customers to
update the proxy domain in their products and policies to the wgcs.skyhigh.cloud syntax. The
Client Proxy documentation still recognises c*.saasprotection.com as a cloud proxy next to
c*.wgcs.skyhigh.cloud, so that name is legacy rather than retired. A retired name in a PAC is a
hard failure (the browser falls through or fails), which is why that instance is rated high; the
legacy name is a migration reminder.
How to fix
Replace the host with c<customer-id>.wgcs.skyhigh.cloud (port 80 or 8080) and redeploy the PAC.
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY c1234567890.saasprotection.com:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY c1234567890.wgcs.skyhigh.cloud:8080";
}
Open good example in checkerRelated rules
References
- https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(Cloud)/Secure_Web_Gateway_Concepts/Updating_IP_Address_Ranges_and_the_Legacy_Proxy_Domain
- https://success.skyhighsecurity.com/Skyhigh_Client_Proxy/Configure_a_Client_Proxy_Policy/06_Secure_the_Communication_Channel_between_Client_Proxy_and_WGCS
- https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(Cloud)/Secure_Web_Gateway_Concepts/Proxy_and_Customer_ID