PAC-B015 · sse-vendor-gateway-not-referenced

Selected vendor pack, but the PAC never routes to that vendor

info · Best practice and maintainability

The vendor packs recognise the vendor's gateway by its host name pattern or PAC variable. If the file never returns such an entry, either the wrong pack is selected or the file is an agent-only steering PAC; the pack's gateway checks then have nothing to check.

Why it matters

Each pack knows what its gateway looks like: ${GATEWAY}-family variables or a *.zscaler.net-family host for Zscaler, eproxy-<tenant> or the EPoT addresses for Netskope, c<customer-id>.wgcs.skyhigh.cloud for Skyhigh, <subdomain>.proxy.cloudflare-gateway.com for Cloudflare and <name>.proxy.prismaaccess.com for Prisma Access. Port, keyword and bypass rules are keyed on those entries. A PAC without any of them gets the generic rating only, which is correct for a Forwarding Profile PAC that returns DIRECT and ${ZAPP_LOCAL_PROXY} (that one does count as a Zscaler entry) but probably not what you meant when you picked the pack for a file that forwards to another proxy.

How to fix

Check the vendor selection, or make sure the proxy entries use the vendor's documented host name or variable.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checker

All five vendor packs; the example is rated with the Zscaler pack.

Related rules

References