Single Zscaler gateway without ${SECONDARY_GATEWAY}
medium
Zscaler's variables come in pairs for a reason: ${GATEWAY} is the closest Public Service Edge and ${SECONDARY_GATEWAY} the next one. A return with only the primary leaves the browser without a proxy during a data-centre outage or maintenance.
Why it matters
Zscaler names a primary and a secondary gateway in every documented PAC example and states that the
pair “provides failover when one of the Public Service Edges is unavailable for any reason”. The
same applies to the country and load-balancing variants (${COUNTRY_SECONDARY_GATEWAY},
${SECONDARY_GATEWAY_F0}, ${SECONDARY_GATEWAY_FX}, _HOST forms). Zscaler Client Connector has
an extra safety net (fallback to gateway.<cloud>.net), a browser with a hosted PAC does not: if
the primary is down the browser retries, remembers the failure for a while and shows connection
errors, or takes a DIRECT fallback if one follows.
How to fix
Return the pair, same port and same variant, e.g. "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80".
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY ${GATEWAY}:80";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checkerRelated rules
- Single proxy without a fallback entry PAC-B011
- DIRECT as fallback after a proxy PAC-X014
- Zscaler gateway on an undocumented port PAC-C019