PAC-C019 · zscaler-service-edge-port

Zscaler gateway on an undocumented port

medium · Correctness

Zscaler Public Service Edges accept browser traffic on ports 80, 443, 9400, 9443 and 9480, plus dedicated ports your organisation subscribes to. Any other port in a ${GATEWAY} entry means the browser tries, fails and falls through to the next entry.

Why it matters

Zscaler’s PAC documentation lists the ports a Public Service Edge listens on: 80 (standard), 443, 9400 (useful when something between the user and Zscaler intercepts port 80), 9443 (remote users whose HTTPS should be inspected) and 9480 (authentication exemption for known locations). Dedicated ports exist by subscription and are configured per location. A typo such as :8080 or :3128 in a ${GATEWAY} entry is a dead end: the browser waits for the connection to fail, then uses the next entry, and if that entry is DIRECT the user is online without Zscaler. Zscaler also notes that a port blocked by the local firewall (9400 is the common case) should not be in the file at all, because the retry adds latency to every connection.

How to fix

Use port 80 (or 443, 9400, 9443, 9480 as documented) on ${GATEWAY} entries; if you use a dedicated port, put the word "dedicated" in a comment on the same line.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:8080; PROXY ${SECONDARY_GATEWAY}:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checker

Zscaler pack only.

Related rules

References