PAC-C025 · skyhigh-web-gateway-not-excluded

Secure Web Gateway itself is not returned DIRECT

medium · Correctness

An on-premises Skyhigh Secure Web Gateway talks to the browser directly for block pages, coaching pages, authentication redirects (port 9094) and injected files (port 9999). If the PAC proxies requests to the gateway's own host name or address, those pages break.

Why it matters

Skyhigh’s PAC guidance for Web Gateway says the appliance “performs many security functions using a single session from the client to the server” (page redirection, session injection, JavaScript insertion) and that “it’s important that traffic to Web Gateway is not proxied”. The documented remedy is an explicit DIRECT for the gateway’s address or name before the proxy statement, for example if (shExpMatch(host, "10.1.0.222")) { return "DIRECT"; }. The rule looks for any proxy host in this file that is not a Skyhigh cloud proxy and checks whether some DIRECT branch matches that host (equality, shExpMatch, dnsDomainIs, localHostOrDomainIs or isInNet for an address). The same advice applies to any explicit proxy that serves its own pages; Skyhigh documents it, so the rule lives in the Skyhigh pack.

How to fix

Add a DIRECT rule for the gateway host or address before the PROXY return, e.g. if (shExpMatch(host, "swg.corp.example") || shExpMatch(host, "10.1.0.222")) return "DIRECT";

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY swg.lab.example:9090";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  if (shExpMatch(host, "swg.lab.example")) {
    return "DIRECT";
  }
  return "PROXY swg.lab.example:9090";
}
Open good example in checker

Skyhigh pack only.

Related rules

References