Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage PAC Files

Want to summarize with AI?

Log in

Describes Manage PAC Files in Cisco Secure Access. Cisco Secure Access provides several client configuration options to manage the web traffic and internet security for the user devices in the organization.


Cisco Secure Access provides several client configuration options to manage the web traffic and internet security for the user devices in the organization. You can integrate a proxy auto-config (PAC) file URL for the browsers that you use to reach web resources.

A PAC file is used by browsers to select the correct proxy server that can fetch a requested URL. The browser-based traffic is proxied through the Secure Access secure web gateway (SWG). After you integrate a PAC file on a user device, all traffic that is sent from the browser is redirected to the SWG. Secure Access applies DNS-layer security to browser traffic for non-web resources only, which bypasses the PAC file.

To download the Secure Access PAC file or custom PAC files to user devices, connect to Secure Access on a Registered Network or Network Tunnel. A roaming user device that has the Cisco Secure Client with the Umbrella Roaming security module deployed can also connect to Secure Access and download PAC files. For more information, see Requirements for Downloading PAC Files to User Devices.


Requirements for Downloading PAC Files to User Devices

To download the Secure Access PAC file or custom PAC files on a user device in the organization, the device must either:

  • Connect to Secure Access on a Registered Network or Network Tunnel, or
  • Deploy the Cisco Secure Client with the Umbrella Roaming Security module on the user device.

Supported Versions of the Secure Client for PAC Files

You must have a version of the Cisco Secure Client that supports the integration of PAC Files. The Secure Access PAC file and custom PAC files integrate with the Cisco Secure Client version 5.1.8.105 and newer. For information about downloading the Cisco Secure Client software packages, see Download Cisco Secure Client.


About Using the Secure Client with PAC Files

  • The Cisco Secure Client sends the username and IP of the user device for authentication to Secure Access. If authenticated, the user device can download the Secure Access PAC file or the organization's custom PAC files.
  • Secure Access PAC file—After you add bypass domains in Secure Access, you can download the Secure Access PAC file that includes the configured bypass domains. Then, when you deploy the Secure Access PAC file on the user device's browser, the browser and the Secure Client support the same bypass domains that are configured in Secure Access.
  • Custom PAC files—Unless you add bypass domains to a custom PAC file manually or create the custom PAC file from the Secure Access PAC file, the custom PAC file does not include the bypass domains that are configured in Secure Access. When you deploy a custom PAC file on the user device's browser, the browser only supports any bypass domains that you add to the custom PAC file.

For information about configuring bypass domains, see Manage Internet Security Bypass.


Managing PAC File Deployments

Integrating the Secure Access PAC file or custom PAC files on the user devices in your organization so that all browser-based traffic is proxied is straightforward. For more information, see:

Note: Microsoft has deprecated PAC file support for the file:// and ftp:// protocols in Windows 10 on Edge. Hosting the PAC file on the local machine with the Edge browser is not supported. For more information, see Windows 10 does not read a PAC file referenced by a file protocol.

We recommend that you bypass these domains in your environment for traffic with TCP on ports 80 and 443:

  • ocsp.int-x3.letsencrypt.org
  • isrg.trustid.ocsp.identrust.com
  • *.opendns.com
  • *.sse.cisco.com
  • *.umbrella.com
  • *.okta.com
  • *.oktacdn.com
  • *.pingidentity.com
  • secure.aadcdn.microsoftonline-p.com

Deploy the Secure Access PAC File for Windows

The Cisco Secure Access secure web gateway (SWG) requires that you deploy a proxy auto-config (PAC) file URL on a user device's browser to successfully reach web resources. If you are behind a firewall, you may also need to deploy the Secure Access's PAC file on the browser so that it points to the correct proxy server. A PAC file is only used with the Secure Access Internet Security.

After an organization's administrator adds bypass domains in Secure Access, the Secure Access PAC file contains the list of configured bypass domains. Web traffic to these domains is not sent to the SWG. For more information, see Manage Internet Security Bypass.

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.

  • To download the Secure Access PAC file or custom PAC files on a user device in the organization, the device must either:

    • Connect to Secure Access on a Registered Network or Network Tunnel, or

    • Deploy the Cisco Secure Client with the Umbrella Roaming Security module on the user device.

Supported Versions of the Secure Client for PAC Files

You must have a version of the Cisco Secure Client that supports the integration of PAC Files. For information about downloading the Cisco Secure Client software packages, see Download Cisco Secure Client.

For Windows, download and deploy the Cisco Secure Client version 5.1.8.105 (cisco-secure-client-win-5.1.8.105-predeploy-k9.msi) or newer.


Copy URL for Default PAC File or Custom PAC File

Copy the URL for the default Secure Access PAC file or a custom PAC file that you uploaded to Secure Access.


Copy URL for the the Secure Access PAC File

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. For Secure Access PAC file, click Copy to get the URL for the Secure Access PAC file.


    Copy option to obtain Secure Access PAC file URL

Copy URL for Custom PAC File

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. Click View the custom PAC files.

  3. Navigate to a custom PAC file, and then click the ellipsis (...).


    View the custom PAC files section with option to copy custom PAC file URL
  4. Click Copy, and then copy the URL for the custom PAC file.


Procedure for Deploying Secure Access PAC File URL

Note
Operating system (OS) and browser functionality can change at any time. We can not guarantee that these third-party procedures will remain accurate. For more information on deploying a PAC file URL to your browser, see your OS and browser's Help.

Deploy the Secure Access PAC File URL for Chrome and Edge Browsers

Get the URL for the Secure Access PAC file or a custom PAC file. For more information, see Copy URL for Default PAC File or Custom PAC File.

Procedure

  1. In Windows, navigate to Start > Settings > Network & internet, and click Proxy.

  2. For Automatic proxy setup, click Set up.

  3. Set Use setup script to On.

  4. For Script Address, paste the Secure Access PAC file URL.

  5. Click Save.


Deploy the Secure Access PAC File URL for Firefox

Get the URL for the Secure Access PAC file or a custom PAC file. For more information, see Copy URL for Default PAC File or Custom PAC File.

Procedure

  1. In Firefox, navigate to Settings, scroll to Network Settings, and then click Settings.


    Network Settings section with option to configure settings to deploy Secure Access PAC fileURL for Firefox
  2. Select Automatic Proxy Configuration URL and paste the Secure Access PAC file URL.

  3. Click OK.


Deploy the Secure Access PAC File for macOS

The Cisco Secure Access secure web gateway (SWG) requires that you deploy a proxy auto-config (PAC) file URL on a user device's browser to successfully reach web resources. If you are behind a firewall, you may also need to deploy the Secure Access's PAC file on the browser so that it points to the correct proxy server. A PAC file is only used with the Secure Access Internet Security.

After an organization's administrator adds bypass domains in Secure Access, the Secure Access PAC file contains the list of configured bypass domains. Web traffic to these domains is not sent to the SWG. For more information, see Manage Internet Security Bypass.

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.

  • To download the Secure Access PAC file or custom PAC files on a user device in the organization, the device must either:

    • Connect to Secure Access on a Registered Network or Network Tunnel, or

    • Deploy the Cisco Secure Client with the Umbrella Roaming Security module on the user device.

Supported Versions of the Secure Client for PAC Files

You must have a version of the Cisco Secure Client that supports the integration of PAC Files. For information about downloading the Cisco Secure Client software packages, see Download Cisco Secure Client.

For macOS, download and deploy the Cisco Secure Client version 5.1.8.105 (cisco-secure-client-macos-5.1.8.105-predeploy-k9.pkg) or newer.


Copy URL for Default PAC File or Custom PAC File

Copy the URL for the default Secure Access PAC file or a custom PAC file that you uploaded to Secure Access.


Copy URL for Secure Access PAC File

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. For Secure Access PAC file, click Copy to get Secure Access PAC file URL.


    Copy option to obtain Secure Access PAC file URL

Copy URL for Custom PAC File

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. Click View the custom PAC files.

  3. Navigate to a custom PAC file, and then click the ellipsis (...).


    View the custom PAC files section with option to copy custom PAC file URL
  4. Click Copy, and then copy the URL for the custom PAC file.


Procedure

Note
Operating system (OS) and browser functionality can change at any time. We can not guarantee that these third-party procedures will remain accurate. For more information on deploying a PAC file URL to your browser, see your OS and browser's Help.

Deploy the Secure Access PAC File URL to Chrome

Get the URL for the Secure Access PAC file or a custom PAC file. For more information, see Copy URL for Default PAC File or Custom PAC File.

Procedure

  1. In your Chrome browser, navigate to chrome://settings/system and click Open your computer's proxy settings.


    Configuration of proxy settings in Chrome browser
  2. Enable Automatic proxy configuration and paste the Secure Access PAC file URL.


    Enable Automatic proxy configuration option to deploy Secure Access PAC file URL
  3. Click OK and then Apply.


Deploy the Secure Access PAC File URL to Firefox

Get the URL for the Secure Access PAC file or a custom PAC file. For more information, see Copy URL for Default PAC File or Custom PAC File.

Procedure

  1. Open your Firefox browser, navigate to Firefox > Preferences, scroll to Network Settings, and click Settings.


    Network Settings section with option to configure proxy settings in Firefox browser
  2. Check Automatic Proxy Configuration URL and paste the Secure Access PAC file URL.

  3. Click OK.


Deploy the Secure Access PAC File URL to Safari

Get the URL for the Secure Access PAC file or a custom PAC file. For more information, see Copy URL for Default PAC File or Custom PAC File.

Procedure

  1. Open your Safari browser, navigate to Safari > Settings > Advanced, and then click Change Settings.


    Advanced Settings section with option to configure proxy settings in Safari browser
  2. Enable Automatic proxy configuration and paste the Secure Access PAC file URL.


    Enable Automatic proxy configuration to deploy Secure Access PAC file URL
  3. Click OK and then Apply.


Customize the Secure Access PAC File

You can create custom PAC files to use with the browsers on the user devices in the organization.

To bypass domains, add domains in Secure Access where the web traffic on these domains will bypass the secure web gateway (SWG). Secure Access includes the configured bypass domains in the Secure Access PAC file. For information about bypass domains, see Manage Internet Security Bypass.

After you download the Secure Access PAC file from Secure Access, you can edit the file and add more domains. Then, upload the custom PAC file to Secure Access or host this PAC file in your environment. Secure Access does not modify a custom PAC file. Secure Access only modifies the Secure Access PAC file with the bypass domains that you add in Secure Access.

Note: Secure Access supports IP-based domains. You must enter the IP in the browser's address bar as the domain portion of the URL. For example, https://1.2.3.4/URLpath/. The PAC file does not resolve a domain to IP before matching an IP-based domain for bypass.

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.
  • To download the Secure Access PAC file or custom PAC files on a user device in the organization, the device must either:
    • Connect to Secure Access on a Registered Network or Network Tunnel, or
    • Deploy the Cisco Secure Client with the Umbrella Roaming Security module on the user device.

For more information, see Manage PAC Files.


Procedure for Customizing the Secure Access PAC File

Copy the Secure Access PAC File URL. Then, enter the PAC file URL in your browser and download the PAC file. Open the Secure Access PAC file in an editor and update the file.


Copy the Secure Access PAC File

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. For Secure Access PAC File, click Copy to get the PAC file URL.


    Copy option to obtain Secure Access PAC file URL

Download the Secure Access PAC File

Procedure

Paste the copied PAC URL into a browser's address bar and then press Enter or Return to download the PAC file.

Browser address bar showing Secure Access PAC File URL

Edit the PAC File

Procedure

  1. Open the downloaded PAC file with a text editor.

  2. Add the internal domains that the web proxy will bypass to the PAC file, and then save the file.

    Note
    Provide a comma-delimited list of domain names and surround each domain name in the list with quotation marks. The wildcard character asterisk * is supported and treated as any value of any length. Use caution when using wildcards as well as periods. For example, *.example.com bypasses www.example.com, mail.example.com, and c.23.example.com. *example.com bypasses www.example.com as well as phishingexample.com.
  3. Save the PAC file.

What to do next

function FindProxyForURL(url, host) {

        //------------------------Customer Section------------------------
        //Add your internal domains within quotations marks like "wwwin.acme.com"
        //after the right parenthesis below. Please remove the two examples
        //below and add your own internal domains.

        var dont_proxy_customer_list = \["121.12.11.11","*.121.12.11.11","aaa","*.aaa","abc.com","*.abc.com","addingboth.com","*.addingboth.com","alibaba.com","*.alibaba.com","capfix.com","*.capfix.com","capissuefix.com","*.capissuefix.com","ci.com","*.ci.com","example.com","*.example.com","flipkart.com","*.flipkart.com","google.com","*.google.com","internal.com","*.internal.com","internaldomain.com","*.internaldomain.com","nnn.com","*.nnn.com","qeqfqgeag.com","*.qeqfqgeag.com","resolvewithdns.com","*.resolvewithdns.com","something.com","*.something.com","ss.com","*.ss.com","test1.com","*.test1.com","testing.com","*.testing.com","testing2.com","*.testing2.com","testing3.com","*.testing3.com","testnew.com","*.testnew.com","bypassproxy.com","*.bypassproxy.com","external.com","*.external.com","externalexample.com","*.externalexample.com","test.com","*.test.com"\];

        //Warning to Administrators: Touching any section after this point might
        //affect your users browsing experience and lead to considerable number
        //of issues and loading your customer support.
        //---------------------End Customer Section-----------------------

        for(var iter = 0; iter < dont_proxy_customer_list.length; ++iter) {
            if(shExpMatch(host, dont_proxy_customer_list\[iter\])) {
                return "DIRECT";
            }
        }

Upload Custom PAC Files to Secure Access

You can create custom PAC files to manage web traffic on browsers. To bypass domains on the secure web gateway (SWG), add the bypass domains to the custom PAC files manually, and then upload the custom PAC files to Secure Access. Once uploaded, the custom PAC files are available on Secure Access for you to use in the organization's environment.

Secure Access supports IP-based domains. However, you must enter the IP in the browser's address bar as the domain portion of the URL. For example, https://1.2.3.4/URLpath/. The PAC file does not resolve a domain to IP before matching an IP-based domain for bypass.

Before you begin

Uploading custom PAC files to Secure Access requires the following.

  • Full Admin user role. For more information, see Manage Accounts.
  • PAC files uploaded to Secure Access must meet the following requirements:
    • Each custom PAC file size is 500KB or less.
    • Filenames are unique.
    • Filenames are case sensitive.
    • Filenames can include alphanumeric characters, hyphens, and underscores.
    • Files have the .pac extension.
Note
No more than ten custom PAC files can be uploaded in Secure Access.

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security, then click View custom PAC files.

    View custom PAC files option to display list of custom PAC files
  2. Under Custom PAC Files, click Add custom PAC file.

  3. Drag and drop your custom PAC file or click the text area to select a custom PAC file from your local system.

    Add cusstom PAC file page with option to upload custom PAC file
  4. After you upload your custom PAC file, click Add.

    Note

    Uploading a PAC file with an invalid file name will result in an error. For more information, see the Prerequisites above.

    Add custom PAC file page showing invalid custom PAC file name error

    Clicking Add without first uploading a file will result in an error.

    Add custom PAC file page showing error message when attempting to add custom PAC file without successful file upload

Manage Uploaded Custom PAC Files

View uploaded custom PAC files, get the URL for a custom PAC file, replace the contents of the custom PAC file, or rename the custom PAC file in Secure Access.

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. Click View the custom PAC files.

    The Custom PAC File View Table interface.

    The table of PAC files shows the following information:

    • # (pound sign)— The number of the custom PAC file.

    • PAC File Name—The filename of the custom PAC file.

    • Link—The link to the URL for the custom PAC file.

  3. To copy a PAC file URL, replace a PAC file with a new uploaded file, or rename a custom PAC file, navigate to the PAC file in the table, click the ellipsis (…), then click Copy, Replace, or Rename.

    The Custom PAC File Copy Replace Rename interface.