Architectural Limitations and Technical Restrictions for On-Premises Explicit Proxy Deployment

Architectural Limitations and Technical Restrictions for On-Premises Explicit Proxy Deployment

223
Created On 06/17/26 21:50 PM - Last Modified 07/09/26 19:00 PM


Objective


To provide a clear, technical reference of the hardware and software limitations of the Explicit Proxy feature, ensuring proper scoping, routing design, and authentication planning prior to implementation in a production environment.



Environment


PAN-OS (Next-Generation Firewalls) 

  • PA-1400 Series: PAN-OS 11.0 or higher

  • PA-3400 Series: PAN-OS 11.0 or higher

  • PA-5400 Series: PAN-OS 11.0 or higher

  • PA-5450: PAN-OS 12.1 or higher

  • VM-Series: PAN-OS 11.0 or higher



Procedure


  1. Protocol and Authentication Limitations

  • Authentication is supported using SAML and Kerberos; however, HTTP/2 processing is exclusively supported for Kerberos. HTTP/2 for SAML is not supported at this moment (SAML connections will automatically degrade to HTTP/1.1).

  • Only Kerberos, SAML 2.0, and Cloud Identity Engine (CIE) are natively supported for explicit proxy authentication redirection. Legacy methods such as NTLM and HTTP Basic Authentication are strictly unsupported.

  • If global or rule-specific "No authentication" profiles are configured to circumvent access prompts, PAN-OS cannot generate or populate authentication event metrics inside the explicit proxy logs.

  • The explicit proxy architecture requires an active SSL Forward Proxy Decryption policy to evaluate Layer 7 application properties and security rules correctly (TLS 1.3 is highly recommended).

  1. Traffic Redirection & Client Dependencies
  • For direct client connections, the on-premises Explicit Proxy requires PAC files to direct traffic to the proxy interface. The solution supports customer-based hosting for these individual PAC files.

  • Alternative Routing: Instead of direct PAC file routing, the proxy also supports inbound proxy chaining, seamlessly processing X-Forwarded-For (XFF) and X-Authenticated-User (XAU) HTTP headers from downstream proxies.

  • Client machines must have explicit route paths and direct DNS resolution capabilities functional prior to securing the proxy connection to successfully fetch the initial PAC file.

  1. Network and Infrastructure Constraints

  • The on-premises Explicit Proxy strictly does not support multi-tenancy.

  • Web Proxy deployments are strictly limited to High Availability Active/Passive (A/P) mode, Active/Active (A/A) clustering is unsupported.

  • Active explicit proxy sessions, control states, and in-flight browser connections are not synchronized between the primary and secondary HA firewalls.

  • The native explicit proxy data path supports IPv4 traffic only; IPv6 processing across explicit proxy listeners is completely unsupported.

  • All components designated for the deployment must reside natively within the same Virtual Router (VR) and the same Virtual System (VSYS).



Additional Information


Sources:

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-release-notes/limitations/limitations-in-pan-os-11-0

https://docs.paloaltonetworks.com/ngfw/networking/dns/configure-a-web-proxy/exclude-all-explicit-proxy-traffic-from-authentication

https://docs.paloaltonetworks.com/ngfw/networking/dns/configure-a-web-proxy/configure-authentication-for-explicit-web-proxy



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wlQ7KAI&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail