SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Access · SSE · Live

Secure Web Gateway

Cloud-based SWG controls and protects your users' web traffic anywhere, anytime. Advanced threat protection, secure access and intelligent web filtering, operated 24/7 by Level-3 engineers.

Overview

Protect users from web threats.

The Open Systems Secure Web Gateway is a comprehensive web security solution that combines advanced threat protection, secure access controls and intelligent web filtering to give organizations a secure and productive web browsing experience. Our cloud SWG helps protect you from web threats and enforces your business policy.

Leverage Open Systems' global distribution of PoPs to provide fast, secure access anywhere in the world. The cloud-based architecture extends to on-premises and IaaS deployments, guaranteeing scalability and performance as your organization grows.

Open Systems Cloud Secure Web Gateway inspecting and filtering user web traffic across global points of presence
Protect yourself from web threats

Benefits.

Global presence

A global distribution of PoPs provides fast, secure access anywhere. The cloud architecture extends to on-premises and IaaS deployments for scale and performance.

Advanced threat protection

Sophisticated mechanisms shield users from malware, phishing and ransomware, on the SWG as well as on the Firewall and Secure Email Gateway.

Web traffic control

Granular web filtering lets administrators define policy and control internet access, reducing exposure to inappropriate or non-business content.

Secure access and authentication

SSO, MFA and IAM integration ensure that only authorized users with valid credentials can access the web.

How does SWG work?

Inspect, filter, enforce.

Authentication

Authenticating users enables different policy groups and different levels of malware protection, URL filtering and SSL scanning.

SWG user authentication mapping users to policy groups

URL filter

The URL filter enforces an organization's internet access policy and protects against the risks associated with employees' internet use.

SWG URL filtering enforcing internet access policy

TLS interception and certificate validation

TLS interception applies malware protection and enforces browsing policy on encrypted traffic. Certificates are verified so only sites with valid certificates are reachable.

SWG TLS interception and certificate validation on encrypted traffic

Malware protection

Malware protection uses machine learning, heuristics and generics to identify malicious code with near-zero false positives.

SWG malware protection using machine learning and heuristics
One platform

Part of the SSE layer.

Secure Web Gateway works alongside ZTNA, CASB, Firewall and Email Security in one managed SSE layer. Add capabilities as you need them and manage them all from a unified interface, on 35 years of operational baseline.

FAQ

Questions about the SWG.

Why a cloud gateway instead of an appliance in our data centre?

Because your users are not in the data centre any more. A cloud SWG inspects traffic at the point of presence nearest the user, so a branch in Singapore is not routed through a European hub to read a web page. The same architecture extends to on-premises and IaaS deployments, so the appliance case is covered without making it the default.

Do you decrypt TLS, and what happens to sensitive sites?

Yes, TLS interception is what makes malware protection and browsing policy work on encrypted traffic, which today is nearly all of it. Certificates are validated so sites with invalid ones are not reachable at all. Categories that must not be inspected, such as banking or health, are excluded by policy, and setting those exceptions up properly is part of the service rather than something you discover in production.

Will web filtering slow browsing down?

Inspection happens inline at a nearby point of presence, and the global distribution of PoPs is what keeps the added latency small enough that users do not go looking for a workaround. A gateway people route around is worse than no gateway.

How do we give different teams different rules?

Through authentication. Once users are identified, they map to policy groups, and each group can have its own level of malware protection, URL filtering and SSL scanning. Single sign-on, MFA and IAM integration mean this rides on the identity system you already run rather than a second user directory.

How is this different from the web filter already in our firewall?

Mostly in what happens to traffic no category list has seen yet. Malware protection here combines machine learning, heuristics and generics to catch malicious code with near-zero false positives, and can be strengthened further with curated zero-day intelligence feeds. A category list tells you what a site was yesterday.

Who maintains the policy once it is live?

Level-3 engineers, 24/7, follow-the-sun. Categories shift, sites get compromised and business tools change, so a web policy that nobody tends becomes either too loose or too annoying within a year. That maintenance is the service, not an extra.
Resources

Go deeper.

Leave complexity behind.

See how Open Systems runs Secure Web Gateway and the full SASE Experience for your organization.

Contact us
Already a customerEverything you use today keeps running.