Connecting to Websites

When connecting to a Website through SDM, traffic is proxied from your system, through your Gateways/Relays to reach the final site. For your system to understand what network traffic needs to be proxied, you will need to set up a proxy rule to forward *.sdm.network through SDM. We recommend using our PAC (Proxy Auto-Config) file.

PAC configuration - Windows

  1. Open the “Settings” app from the Windows menu.
  2. Click on “Network & Internet”.
  3. Open the “Proxy” tab
  4. Turn on “Use setup script”
  5. Add https://app.strongdm.com/proxy.pac to “Script Address” HTTP Windows

PAC configuration - macOS

  1. Open your System Preferences and select the Network icon.
  2. Choose your current connection method - wireless or ethernet - and click the “Advanced” button. HTTP Advanced
  3. Click on the “Proxies” tab.
  4. Check the box to enable “Automatic Proxy Configuration”.
  5. Add https://app.strongdm.com/proxy.pac to the URL box. HTTP PAC
  6. Click OK.
  7. Click Apply.

Add to an existing proxy

If your system is already has a proxy configured, you can append the following rules to your existing configuration.

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "proxyerror.sdm.network")) {
    return "DIRECT";
  }
  if (shExpMatch(host, "*.sdm.network")) {
    return "PROXY 127.0.0.1:65230";
  }
  return "DIRECT";
}

FAQ

Q: What is the “proxy.pac” file that the URL is pointing to?
A: A PAC file is a piece of Javascript that tells the HTTP client which proxy server to connect to for specifically defined URLs.

Q: What does the strongDM PAC file do?
A: It tells the HTTP client when it receives a connection attempt for ‘sdm.network’ - talk to a port on the localhost. For everything else, go directly to the site.

Q: Is there an alternative to pointing to the strongDM hosted PAC file?
A: Yes, you could also download the PAC file and distribute it to your Users. It does not have to be dynamically loaded from our server.

Q: Are there any potential security concerns with this approach?
A: strongDM controls full access to this proxy configuration, so the risk of falsely redirected traffic is very low. However, if you have concerns, you can choose to distribute the PAC file yourself, as metioned above.