Glossary · simply explained

SWG (Secure Web Gateway)

A secure web gateway (SWG) inspects and filters user web traffic: requests are checked against policies, reputation data and malware detection before the connection is made. Dangerous destinations are blocked, risky categories are handled according to company policy.

As a cloud service, the SWG is a core building block of SASE/SSE: protection follows the user — in the office, at home, on the road — instead of ending at the headquarters perimeter.

How does an SWG work?

Device traffic is routed through the cloud service — typically via an agent on the device or the site tunnel. Several inspection stages apply: DNS and URL filtering by category and reputation, TLS inspection for content checks, malware scanning of downloads, and policies down to application and action level, such as upload bans for certain services.

Modern SWGs couple with data loss prevention and CASB, creating end-to-end control from the request through the content to the data movement.

What an SWG prevents day to day

  • Access to phishing and malware sites — including freshly registered domains.
  • Drive-by downloads and infected files from the web.
  • Unwanted services according to policy, such as anonymous file-sharing portals.
  • Data exfiltration via web uploads, combined with DLP rules.

Frequently asked questions about SWG (Secure Web Gateway)

Does an SWG replace the classic web proxy?

Yes — the SWG is the successor of the on-premises proxy, as a cloud service without backhauling: traffic no longer has to be hairpinned through headquarters. That saves latency and makes protection location-independent, including in home offices.

Does an SWG need TLS inspection?

For content inspection yes: without decryption the gateway only sees destination domains, not content or files. TLS inspection is applied policy-driven — sensitive categories such as banking or health can be exempted deliberately.

How do SWG and SASE relate?

The SWG is one of the core building blocks of the SASE or SSE architecture, alongside ZTNA, CASB and FWaaS. In one platform these services share policies, identities and logs — instead of operating four separate products with four consoles.

Does an SWG slow users down?

With cloud SWGs on global networks the detour is minimal: inspection happens at the closest provider location. Compared with the old model — backhauling through headquarters — browsing usually gets faster for distributed teams.

What distinguishes an SWG from a DNS filter?

A DNS filter blocks at the name resolution level — fast and simple, but coarse. An SWG additionally inspects URLs, content and files and enforces finer policies. In practice both stages are combined: DNS as the first, SWG as the deep line of defence.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.