Proton

How to deploy Proton Pass behind Zscaler proxy solutions

Okuma süresi
1 dakikalık
Kategori
Proton Pass for Business

If you’re using a Zscaler cloud proxy, you’ll need to take these steps in order to configure Proton Pass and its SSO capabilities:

  1. Exempt Proton Pass from Zscaler authentication.(yeni pencere)
  2. Exempt Proton Pass from SSL inspection.(yeni pencere)
  3. Create a custom URL category for Proton Pass(yeni pencere).
  4. Allowlist the following Proton Pass domains(yeni pencere):
  • pass.proton.me
  • pass-api.proton.me
  • account.proton.me
  • account-api.proton.me

You may also need to create Security Exceptions for these domains. You can find Security Exceptions in your Zscaler account by selecting PolicyMalware ProtectionSecurity Exceptions.

Proton Pass needs access to those domains to sync data across different devices. These domains all follow the latest security protocols and are exclusively used by Proton Pass and other Proton products.

Some enterprise firewalls can’t use domain names for allowlisting and instead require lists of IP addresses. While we don’t change these IP addresses regularly, it is not considered best practice to allowlist specific IPs. If the IPs you’ve allowlisted change, the end user experience behind that firewall would be equivalent to an outage.


The full list of current IP addresses owned by Proton and announced by our ASN 62371 can be found independently in online IRR databases (for example, RIPE(yeni pencere)).