Zscaler gateway on an undocumented port
medium
Zscaler Public Service Edges accept browser traffic on ports 80, 443, 9400, 9443 and 9480, plus dedicated ports your organisation subscribes to. Any other port in a ${GATEWAY} entry means the browser tries, fails and falls through to the next entry.
Why it matters
Zscaler’s PAC documentation lists the ports a Public Service Edge listens on: 80 (standard), 443,
9400 (useful when something between the user and Zscaler intercepts port 80), 9443 (remote users
whose HTTPS should be inspected) and 9480 (authentication exemption for known locations). Dedicated
ports exist by subscription and are configured per location. A typo such as :8080 or :3128 in a
${GATEWAY} entry is a dead end: the browser waits for the connection to fail, then uses the next
entry, and if that entry is DIRECT the user is online without Zscaler. Zscaler also notes that a
port blocked by the local firewall (9400 is the common case) should not be in the file at all,
because the retry adds latency to every connection.
How to fix
Use port 80 (or 443, 9400, 9443, 9480 as documented) on ${GATEWAY} entries; if you use a dedicated port, put the word "dedicated" in a comment on the same line.
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY ${GATEWAY}:8080; PROXY ${SECONDARY_GATEWAY}:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checkerRelated rules
- Proxy port out of range or not numeric PAC-E012
- Single Zscaler gateway without ${SECONDARY_GATEWAY} PAC-B012