RFC 1918 range with the wrong mask
medium
172.16.0.0 with mask 255.255.0.0 covers only 172.16.x.x. The private block is 172.16.0.0/12 (mask 255.240.0.0), i.e. 172.16.0.0 to 172.31.255.255; the /16 misses fifteen sixteenths of it.
Why it matters
RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The middle block is
the one that gets written wrong: /16 instead of /12. With mask 255.255.0.0 the host
172.20.0.5 is outside the match and takes the default route (lab, 2026-05-20). The
symptom is a subset of internal addresses going to the proxy, which may not route to them.
A mask narrower than the canonical one with the canonical base address is almost always a
mistake; a deliberately narrower internal range normally starts at a different base.
How to fix
Use 255.240.0.0 for 172.16.0.0, 255.0.0.0 for 10.0.0.0 and 255.255.0.0 for 192.168.0.0.
Examples
Bad
function FindProxyForURL(url, host) {
if (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "172.16.0.0", "255.255.0.0")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "172.16.0.0", "255.240.0.0")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- isInNet called with an invalid address, mask or argument count PAC-E010
- IP range matched as a text prefix PAC-X006
- Only 127.0.0.1 excluded instead of 127.0.0.0/8 PAC-C008