Selected vendor pack, but the PAC never routes to that vendor
info
The vendor packs recognise the vendor's gateway by its host name pattern or PAC variable. If the file never returns such an entry, either the wrong pack is selected or the file is an agent-only steering PAC; the pack's gateway checks then have nothing to check.
Why it matters
Each pack knows what its gateway looks like: ${GATEWAY}-family variables or a *.zscaler.net-family
host for Zscaler, eproxy-<tenant> or the EPoT addresses for Netskope, c<customer-id>.wgcs.skyhigh.cloud
for Skyhigh, <subdomain>.proxy.cloudflare-gateway.com for Cloudflare and <name>.proxy.prismaaccess.com
for Prisma Access. Port, keyword and bypass rules are keyed on those entries. A PAC without any of them
gets the generic rating only, which is correct for a Forwarding Profile PAC that returns DIRECT and
${ZAPP_LOCAL_PROXY} (that one does count as a Zscaler entry) but probably not what you meant when
you picked the pack for a file that forwards to another proxy.
How to fix
Check the vendor selection, or make sure the proxy entries use the vendor's documented host name or variable.
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checkerRelated rules
- PAC sends traffic to a proxy the Netskope Client may not know PAC-B013
- DIRECT in the PAC does not bypass the vendor's agent PAC-B014
References
- https://help.zscaler.com/zia/writing-pac-file
- https://docs.netskope.com/en/explicit-proxy
- https://success.skyhighsecurity.com/Skyhigh_Secure_Web_Gateway_(Cloud)/Secure_Web_Gateway_Concepts/Proxy_and_Customer_ID
- https://developers.cloudflare.com/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/set-up-explicit-proxy