Architectural Limitations and Technical Restrictions for On-Premises Explicit Proxy Deployment
Objective
To provide a clear, technical reference of the hardware and software limitations of the Explicit Proxy feature, ensuring proper scoping, routing design, and authentication planning prior to implementation in a production environment.
Environment
PAN-OS (Next-Generation Firewalls)
-
PA-1400 Series: PAN-OS 11.0 or higher
-
PA-3400 Series: PAN-OS 11.0 or higher
-
PA-5400 Series: PAN-OS 11.0 or higher
-
PA-5450: PAN-OS 12.1 or higher
-
VM-Series: PAN-OS 11.0 or higher
Procedure
-
Protocol and Authentication Limitations
-
Authentication is supported using SAML and Kerberos; however, HTTP/2 processing is exclusively supported for Kerberos. HTTP/2 for SAML is not supported at this moment (SAML connections will automatically degrade to HTTP/1.1).
-
Only Kerberos, SAML 2.0, and Cloud Identity Engine (CIE) are natively supported for explicit proxy authentication redirection. Legacy methods such as NTLM and HTTP Basic Authentication are strictly unsupported.
-
If global or rule-specific "No authentication" profiles are configured to circumvent access prompts, PAN-OS cannot generate or populate authentication event metrics inside the explicit proxy logs.
-
The explicit proxy architecture requires an active SSL Forward Proxy Decryption policy to evaluate Layer 7 application properties and security rules correctly (TLS 1.3 is highly recommended).
- Traffic Redirection & Client Dependencies
-
For direct client connections, the on-premises Explicit Proxy requires PAC files to direct traffic to the proxy interface. The solution supports customer-based hosting for these individual PAC files.
-
Alternative Routing: Instead of direct PAC file routing, the proxy also supports inbound proxy chaining, seamlessly processing X-Forwarded-For (XFF) and X-Authenticated-User (XAU) HTTP headers from downstream proxies.
-
Client machines must have explicit route paths and direct DNS resolution capabilities functional prior to securing the proxy connection to successfully fetch the initial PAC file.
-
Network and Infrastructure Constraints
-
The on-premises Explicit Proxy strictly does not support multi-tenancy.
-
Web Proxy deployments are strictly limited to High Availability Active/Passive (A/P) mode, Active/Active (A/A) clustering is unsupported.
-
Active explicit proxy sessions, control states, and in-flight browser connections are not synchronized between the primary and secondary HA firewalls.
-
The native explicit proxy data path supports IPv4 traffic only; IPv6 processing across explicit proxy listeners is completely unsupported.
-
All components designated for the deployment must reside natively within the same Virtual Router (VR) and the same Virtual System (VSYS).
Additional Information
Sources: