PAC-B012 · zscaler-no-secondary-gateway

Single Zscaler gateway without ${SECONDARY_GATEWAY}

medium · Best practice and maintainability

Zscaler's variables come in pairs for a reason: ${GATEWAY} is the closest Public Service Edge and ${SECONDARY_GATEWAY} the next one. A return with only the primary leaves the browser without a proxy during a data-centre outage or maintenance.

Why it matters

Zscaler names a primary and a secondary gateway in every documented PAC example and states that the pair “provides failover when one of the Public Service Edges is unavailable for any reason”. The same applies to the country and load-balancing variants (${COUNTRY_SECONDARY_GATEWAY}, ${SECONDARY_GATEWAY_F0}, ${SECONDARY_GATEWAY_FX}, _HOST forms). Zscaler Client Connector has an extra safety net (fallback to gateway.<cloud>.net), a browser with a hosted PAC does not: if the primary is down the browser retries, remembers the failure for a while and shows connection errors, or takes a DIRECT fallback if one follows.

How to fix

Return the pair, same port and same variant, e.g. "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80".

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checker

Zscaler pack only; replaces the generic PAC-B011 note for this vendor.

Related rules

References