Secure Web Gateway itself is not returned DIRECT
medium
An on-premises Skyhigh Secure Web Gateway talks to the browser directly for block pages, coaching pages, authentication redirects (port 9094) and injected files (port 9999). If the PAC proxies requests to the gateway's own host name or address, those pages break.
Why it matters
Skyhigh’s PAC guidance for Web Gateway says the appliance “performs many security functions using a
single session from the client to the server” (page redirection, session injection, JavaScript
insertion) and that “it’s important that traffic to Web Gateway is not proxied”. The documented
remedy is an explicit DIRECT for the gateway’s address or name before the proxy statement, for
example if (shExpMatch(host, "10.1.0.222")) { return "DIRECT"; }. The rule looks for any proxy
host in this file that is not a Skyhigh cloud proxy and checks whether some DIRECT branch matches
that host (equality, shExpMatch, dnsDomainIs, localHostOrDomainIs or isInNet for an address). The
same advice applies to any explicit proxy that serves its own pages; Skyhigh documents it, so the
rule lives in the Skyhigh pack.
How to fix
Add a DIRECT rule for the gateway host or address before the PROXY return, e.g. if (shExpMatch(host, "swg.corp.example") || shExpMatch(host, "10.1.0.222")) return "DIRECT";
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY swg.lab.example:9090";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
if (shExpMatch(host, "swg.lab.example")) {
return "DIRECT";
}
return "PROXY swg.lab.example:9090";
}
Open good example in checkerRelated rules
- Plain hostnames or private addresses are sent to the cloud proxy PAC-C026
- DIRECT in the PAC does not bypass the vendor's agent PAC-B014