Netskope Agent - pac file - explicit proxy over ipsec

  • 9 May 2023
  • 4 replies
  • 61 views

Badge +3

Hi all,

 

I have a customer that uses pac file mandatory, for users with the agent installed and users who don't have agent, and can't differentiate between them, therefore all the pc's use pac file.

 

With non-Netskope explicit proxies over ipsec, this pac file configuration does everything works ok.


addon-customer1.goskope.com -> proxy
*.goskope.com -> direct

 

When the proxy is a Netskope explicit proxy over ipsec, the agent is disabled.

 

Is there a way to change the behavior so that the pac file can coexist with Netskope explicit proxy ipsec without the agent not being automatically disabled?

 

Thanks!!

 


4 replies

Userlevel 6
Badge +16

@aatienza Hello! The default behavior of the Netskope client is to disable itself when it detects another steering method is present.  This behavior can be changed via a backend flag.  However, there are some considerations like identity when changing this behavior.  I'd suggest reaching out to your local Netskope team so we can dig deeper into this case as there may be better ways to handle this case. 

Userlevel 3
Badge +11

 

@aatienza 

Hello!

"We had to remove the PAC file as it conflicted with the Netskope client - we also have WCCP enabled on the edge before the [legacy] proxy we are decommissioning that intercepts 80/443 with an access-list to bypass the proxy for traffic known not to like the proxy connection.  " quote from the Lead Network Engineer.

Badge +3

@sshiflett We are considering that option with the local SE.

Thanks!!

Badge +3

Hi @wilson

For our client, the pac file is essential. We must integrate it with the Netskope agent and EPoT.

Thanks!

Reply