A secure web gateway (SWG) inspects and filters user web traffic: requests are checked against policies, reputation data and malware detection before the connection is made. Dangerous destinations are blocked, risky categories are handled according to company policy.
As a cloud service, the SWG is a core building block of SASE/SSE: protection follows the user — in the office, at home, on the road — instead of ending at the headquarters perimeter.
How does an SWG work?
Device traffic is routed through the cloud service — typically via an agent on the device or the site tunnel. Several inspection stages apply: DNS and URL filtering by category and reputation, TLS inspection for content checks, malware scanning of downloads, and policies down to application and action level, such as upload bans for certain services.
Modern SWGs couple with data loss prevention and CASB, creating end-to-end control from the request through the content to the data movement.
What an SWG prevents day to day
- Access to phishing and malware sites — including freshly registered domains.
- Drive-by downloads and infected files from the web.
- Unwanted services according to policy, such as anonymous file-sharing portals.
- Data exfiltration via web uploads, combined with DLP rules.