At the DNS layer, a resolver refuses to translate a bad domain into an address — no agent, no latency, nothing in the traffic path. A proxy goes further: it terminates the connection, decrypts it, inspects the content and decides. The first costs almost nothing and sees only destinations; the second sees everything and costs a certificate on every device.
Cisco’s DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare’s resolver is free. A browser with DNS-over-HTTPS enabled routes around both, without asking anyone.
Already decided — before the quote
Still yours to weigh
Two controls at two different depths. DNS filtering intercepts the name lookup that starts almost every connection: point your resolvers at the provider, and requests for known-bad or policy-blocked domains never resolve. Nothing sits in the traffic path, there is no agent to deploy on the network, and it costs very little. A secure web gateway is a proxy: traffic is terminated, decrypted, inspected for malware and data, and allowed or blocked by content rather than by destination.
Alongside them sits CASB, which controls how cloud applications are used — and which is genuinely two products under one name. Inline CASB sits in the traffic path and can stop an upload as it happens; API CASB connects to the application out of band and scans what is already there. Most estates need both and are quoted one. When these controls are bought as part of a platform rather than on their own, that is the SASE & SSE guide.
The most common mis-purchase
Buying DNS filtering when the requirement was full web inspection. DNS blocks a domain; it cannot tell you what a user uploaded to an allowed one, scan a download, or distinguish your corporate cloud tenant from a personal one. If the requirement mentions content, data or files, the answer is a proxy.
Often confused withSASE & SSE — where these controls are bought as a platform →·Firewall & Network Security — web filtering enforced at your own edge →·Email Security — the other delivery path for the same threats →
The four routes of network security — and which one is yours →
Three enforcement depths often sold as one product, and one acronym that is genuinely two different things. Not a maturity ladder — each sees something the others cannot.
DNS filtering
Blocks at name resolution: the domain never turns into an address. No traffic path, no latency, no certificates, and it covers every device and protocol using your resolver — including things a proxy never sees. It cannot inspect content, cannot tell one page of a site from another, and is bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN. The cheapest real control there is.
Proxy / secure web gateway
Terminates the connection, decrypts TLS, inspects content, and decides on what the traffic actually contains. Sees files, uploads, form data and malware; enforces data-loss rules. Costs a certificate on every device, an exception list for applications that pin certificates, and latency in the path. Everything DNS filtering cannot do, at the price of a project.
CASB inline
In the traffic path, on the way to the cloud application. Can block an upload as it happens, coach a user in real time, and distinguish the corporate tenant of an application from a personal one. Sees only what traverses it, and only while it does — data already sitting in the application is invisible.
CASB API
Connected to the cloud application out of band, scanning what is already there: historical files, sharing permissions, external collaborators, dormant sensitive data. Finds the exposure inline inspection never saw — and can block nothing in real time. The two modes answer different questions and most estates need both.
Seven variables decide this purchase. The instrument tests what documentation establishes (enforcement layer, TLS depth, roaming coverage, CASB mode, standalone availability, India presence); bypass behaviour, false positives and the certificate project are prose because they come from a pilot and an operations plan.
DNS-layer versus full proxy inspection
Destinations or content. The single question that decides whether this is a cheap control deployed everywhere or a project with a certificate rollout.
Roaming agent versus network-level deployment
Enforcement for devices that leave the office. Sophos Firewall, Palo Alto CDSS and Advanced DNS Security, FortiProxy and Kaspersky Web Traffic Security have no roaming agent here; the rest document roaming coverage.
TLS inspection depth and the certificate burden
Full, selective, or none — and then the real work: an inspection certificate trusted by every device, plus an exception list for applications that pin their own.
Category coverage and false-positive rate
A block on a business-critical site erodes trust in the control faster than any threat justifies it. Pilot against your own top destinations and check the exception workflow.
CASB — inline versus API
Two different products under one acronym: blocking in flight versus finding what is at rest. Documented per product here; most estates need both.
Standalone or only inside a SASE platform
Most products here sell standalone; Cisco Secure Access, Netskope, Palo Alto CDSS and Sophos Firewall need the platform or appliance underneath, Jamf Safe Internet comes inside Jamf's K-12 offering, and Coro's gateway inside its bundles.
India resolver presence and latency
DNS resolution happens on every request, so resolver distance is felt constantly. Documented for Cloudflare (six cities), Netskope (eight data centres), Zscaler and Prisma Access (four cities each), Forcepoint (five edge cities), Check Point (four), Cato and Skyhigh (three each), Microsoft (Chennai, Pune), Infoblox (Mumbai, Hyderabad), Symantec Cloud SWG (Delhi, Mumbai), Trend Micro (Mumbai) and Cisco Umbrella (Mumbai, Chennai); not established for the rest here.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where Indian resolver presence is not documented it is flagged and stays, never eliminated on an absence of evidence. Every chip is reversible.
Cloud application control
Where it enforces
Encrypted traffic
Where the users are
How you buy it
India
Estate size
Bypass behaviour, false positives and the certificate rollout are in the notes below rather than chips — they decide whether the control survives contact with users, and no datasheet covers them.

per user / month across the tiers (DNS Security Essentials roughly $30–40 per user / year, DNS Advantage $40–55, SIG Essentials $60–90, SIG Advantage $95–135); the DNS tiers are the cheapest real control on this page
Estates that want DNS-layer filtering deployed across every site in an afternoon, with an upgrade path to full proxy inspection in the same console.
The catch: The DNS tiers filter by domain and cannot inspect content — the selective proxy arrives at the SIG tiers, which is where the price roughly triples. Add-on SKUs and premium support push enterprise deployments well above the list. Cisco lists Umbrella data centres in Mumbai and Chennai.

per user / year inside the Secure Access platform rather than standalone; the successor to Umbrella's SIG tiers with full proxy inspection, CASB and ZTNA in one subscription
Cisco estates consolidating Umbrella, VPN and web security into one cloud service under an existing enterprise agreement.
The catch: Not a standalone web filter — it arrives as a platform, which is a larger commitment than the Umbrella DNS tiers it supersedes. Indian PoP cities are not established from documentation.

the 1.1.1.1 resolver and 1.1.1.1 for Families (malware and adult-content blocking) are free; per-user policy DNS filtering is Cloudflare Gateway, listed separately under Cloudflare One (free to 50 users, then $7 per user / month); Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur
Estates that want DNS filtering on the largest documented Indian resolver footprint here, starting at no cost.
The catch: DNS layer only, with fixed Families categories rather than your own policy — no content inspection, no TLS decryption, no CASB. It blocks a destination or it does not; what happens inside an allowed site is invisible.

free for up to 50 users, then $7 per user / month with no user cap; DNS, HTTP and network filtering with TLS inspection, on the same Indian PoP footprint as the resolver
Estates that want full web inspection at a published price, on documented Indian infrastructure, without an enterprise negotiation.
The catch: The $7 tier is capable and is not the Enterprise product: CASB breadth, DLP depth, browser isolation and longer log retention move up to the quoted tier. TLS inspection still means deploying a certificate to every device.

per user / month reported (roughly $72–325 per user / year by edition); a full inline proxy inspecting every session, with CASB, DLP and browser isolation as higher editions or add-ons
Estates that want every session inspected in depth rather than destinations filtered — the reference proxy, and the deepest inspection here.
The catch: A proxy, not a DNS filter: there is no cheap DNS-only tier to start on, and the base edition is the gateway with data protection arriving as editions or add-ons. Zscaler’s published enforcement-node list includes Mumbai, Chennai, New Delhi and Hyderabad.

per user / month within Netskope One; inspects by application instance — allowing the corporate tenant of a cloud application while blocking the personal one — with eight Indian data centres on NewEdge
Estates whose control requirement is per application instance rather than per domain, which domain-level filtering cannot express at all.
The catch: Sold as part of the Netskope One platform rather than as a standalone filter, so a like-for-like comparison against Umbrella's DNS tiers is not meaningful. It is more product than a DNS-only requirement needs.

per user / month within Netskope One; both inline (in the traffic path, able to block in real time) and API-based (out of band, scanning what is already in the cloud application) — the two modes are different products in practice
Estates that need both to control cloud application use: inline to stop an upload as it happens, API to find what was uploaded last year.
The catch: Inline and API modes solve different problems and are frequently confused — API alone cannot block anything in real time, inline alone cannot see historical data at rest. Platform-priced, not standalone.

per-firewall subscriptions layered on a Strata NGFW or Prisma Access — Advanced URL Filtering and Advanced DNS Security are separate CDSS SKUs, enforced wherever that platform enforces (plain DNS Security is end-of-sale)
Palo Alto estates that want web and DNS controls inside the policy engine already running, rather than a second console.
The catch: These firewall subscriptions need the firewall or Prisma Access underneath, and roaming comes from Prisma Access rather than a lightweight DNS agent. The DNS service alone is now sold standalone — see the Advanced DNS Security row.

quoted per user / year by bundle tier through partners (a UK reseller’s 2024 G-Cloud list: Standard £78, Advanced £101, Comprehensive £304 at 50–499 users); web filtering and DNS filtering for off-network users using the same FortiGuard categories as the FortiGate estate, with Security Fabric pricing for existing customers
FortiGate estates extending the web filtering they already run on-premises to users who never come back to the office.
The catch: The categories and console are familiar, which is the point; as a standalone web filter for a non-Fortinet estate it is a less obvious purchase. Indian PoP cities are not established from vendor documentation.

web security inside SecureEdge, licensed per site for the network side and per user for the access side; content filtering and TLS inspection for distributed sites without an enterprise project
Distributed mid-market estates — many small sites — that want web filtering and firewalling from one platform and one bill.
The catch: No CASB capability documented, so cloud application control is outside its scope; documented deployments are mid-market and an Indian resolver location is not established. The split per-site and per-user meter makes comparison awkward.

web protection inside the Standard or Xstream Protection bundle on an XGS appliance; TLS inspection is an Xstream capability, Xstream also includes Sophos DNS Protection (a cloud resolver for your sites) at no extra charge, and enforcement happens at your edge rather than in a cloud PoP
Estates whose users are mostly in the office and who want web filtering enforced by the firewall already inspecting their traffic.
The catch: On-network enforcement only — there is no roaming agent here, so devices off the network are unprotected unless you also run a cloud service. It is the appliance answer to a question the rest of this page answers from the cloud.

quote-only, switched on per site in the console with a paid keycode or a 30-day trial, mostly through MSPs; OpenText publishes no licence unit or rate; 78 BrightCloud categories, a Windows agent over DoH, and DNS forwarding for every other device
MSPs and small multi-site offices that want DNS filtering on Windows laptops off the network and on every device behind a forwarding site, with encrypted-DNS bypass blocked by the agent.
The catch: DNS layer only — no TLS inspection, file scanning or CASB — and the roaming agent is Windows-only; no Indian resolver is documented. OpenText classes its SMB and consumer security line as non-core and is divesting non-core units — ask about the roadmap.

quoted per user, with its own product listing and pricing request; API scanning plus inline enforcement through reverse and forward proxy, carrying the same classification and policy as Forcepoint DLP; cloud regions in Mumbai and edge data centres in Bangalore, Chennai, Hyderabad, Mumbai and New Delhi
Estates that already classify data with Forcepoint DLP and want the same policy applied to sanctioned and shadow SaaS, both in flight and at rest.
The catch: Quote-only, and its pull is the DLP policy it shares: bought alone, it is a CASB competing on features with Netskope. The inline mode still means a proxy and a certificate on every device.

per user / year, quoted, with no firewall required; DNS Security is included in the Prisma Access bundle, while SaaS Security (inline and API CASB) is an add-on; Indian locations in Mumbai, Chennai, New Delhi and Hyderabad
Palo Alto estates, or estates that want its inspection model, covering users who never come back to the office — the roaming counterpart to the firewall-bound CDSS row.
The catch: Enterprise-priced and quoted; CASB in both modes costs extra; the policy model feels native only if you already run Palo Alto firewalls. A web-only requirement buys a whole SSE platform here.

quoted per user; a single-pass engine inspects traffic inside the PoP it already crosses, can run over third-party SD-WAN or IPsec, and pairs inline CASB with an API scanner; Cato’s status page lists PoPs in Chennai, Mumbai (two data centres) and New Delhi
Estates that want web inspection performed on the path rather than beside it, with a route to Cato’s SD-WAN later.
The catch: Most of its advantage comes with Cato’s own network; on another WAN it competes on features alone. One vendor’s inspection across the estate is a deliberate trade, and the price is not published.

per user, quoted — the former Perimeter 81 price list is no longer published; Internet Access combines DNS and URL filtering with TLS inspection performed on the device, and CASB runs inline and by API; an India data-residency region (May 2025) with PoPs in Bengaluru, Chennai, Mumbai and New Delhi
Check Point estates and mid-market teams that want web filtering, inspection and access in one agent, with an Indian residency option.
The catch: Narrower than the SSE leaders on data protection depth, and the PoP cities rest on a June 2025 announcement rather than a current admin guide. Pricing now needs a quote.
Vision One credits: Internet Access is its own ZTSA licence line at 60 credits per user per year (or 5 a month), with a cloud gateway in AWS Mumbai or an on-premises Service Gateway; HTTPS inspection rules and inline cloud-app control; API CASB is a separate Trend product
Trend Vision One estates that want web access decisions informed by the endpoint and email risk scores they already have.
The catch: Credits are opaque until converted into a quote, and the value depends on running Trend elsewhere. Inline control only here — scanning data already in SaaS needs another product.

per user / year, quoted by service tier, without Versa’s SD-WAN; single-pass inspection with SSL decryption, inline and API CASB, and the option to enforce in the cloud or on premises
Estates that want a full web gateway and CASB from the same operating system as their Versa network, or on-premises enforcement alongside the cloud.
The catch: Versa documents no Indian PoP city; Indian deployments often run through partners such as Tata Communications’ hosted SASE. Smaller SSE footprint than the leaders.

sold within Jamf’s K-12 offering, quoted per student device for education; on-device DNS filtering on iPad, Mac, Chromebook and Windows that keeps working off the school network; Apple devices need Jamf School or Pro, ChromeOS and Windows can use other management tools
Schools that want age-appropriate filtering and threat blocking that follows the student device home, managed alongside Jamf School.
The catch: Built for education rather than business, DNS layer only, and not sold as a standalone business filter. Jamf’s hosting is in Ireland and the US, with no Indian resolver documented.

inside Coro’s AI Essentials and AI Complete bundles, quoted through partners; DNS filtering with category and URL allow and block lists per user group, delivered through the Coro agent and its virtual office
Small and mid-sized organisations that want DNS-layer web filtering in the same agent and console as their endpoint, email and cloud protection.
The catch: Not sold on its own and DNS layer only — no TLS inspection or CASB in this module. Coro documents no Indian resolver, and its deployments are small and mid-market.

per user / month paid yearly (₹415 on Microsoft’s Indian price list), and every user also needs Entra ID P1 or P2; the Entra Suite at $12 bundles it; category and FQDN filtering through the Global Secure Access client, TLS inspection generally available since November 2025, points of presence in Chennai and Pune
Microsoft 365 estates already on Entra ID and Conditional Access that want web filtering inside the same identity policy, at a published per-user price.
The catch: No Microsoft-native malware engine — inline threat scanning comes from a Netskope add-on — and no CASB in this licence (Defender for Cloud Apps is separate). URL-path filtering and traffic logs are still in preview.

per user / year on Forcepoint’s own AWS Marketplace listing with a 500-user minimum (browser isolation $32 and a dedicated IP $75 extra); enforced in the cloud or by the SmartEdge agent on the device; a Mumbai cloud region plus edge data centres in Bangalore, Chennai, Hyderabad, Mumbai and New Delhi
Estates that want web traffic held to the same data policy as Forcepoint DLP, enforced in the cloud or on the device for people working remotely.
The catch: API scanning of SaaS needs the separate Cloud App Security licence, the 500-user minimum rules out small estates, and web logs are kept 30 days in a US East data centre — export them to reach CERT-In’s 180 days.

per user / year for the standalone Advanced DNS Security Resolver (July 2025; 5,000 DNS requests per user a day; no firewall needed), or per device as a subscription on Strata firewalls and Prisma Access; plain DNS Security is end-of-sale
Estates that want Palo Alto’s analysis of DNS tunnelling, generated domains and hijacking in front of any network, without buying the firewall.
The catch: DNS layer only, and no standalone roaming agent: laptops off the network are covered only through Prisma Access Agent. Quote-only; its privacy datasheet names India at country level, with no resolver city.

an appliance (400G, 2000G or 4000G) or a yearly VM subscription, plus the required SWG Protection Bundle in 500-user seat lots — web, video and DNS filtering, application control, antivirus, IPS and sandboxing; DLP and browser isolation are add-ons; the proxy and its logs sit on hardware you place
Estates — government offices especially, where CERT-In’s guidelines route internet access through a proxy — that want the gateway and its logs on hardware they control.
The catch: No roaming agent: off-network users come back through a PAC file or VPN. Critical admin-bypass flaws were exploited in 2025 and 2026, so patching is part of the purchase — run 7.6.6 or later.
quoted for MSPs; a standalone product built on technology N-able licenses from DNSFilter, with roaming clients for Windows and macOS and DNS over TLS from clients and relays; the version built into N-central closed to new activations and is removed by 31 March 2026
MSPs that want DNS filtering they can roll out customer by customer, from the vendor they already buy RMM and backup from.
The catch: DNS layer only. Query logs are held 9 days on the DNSFilter platform, so CERT-In’s 180 days means exporting to a SIEM; browser DoH is only partly handled, and no Indian resolver city is documented.

per user, quoted, with one count set by the largest of browser users, ZTNA users or DNS-protected devices; Protected Browser (built with Island), DNS Protection for Windows endpoints and ZTNA, sold since February 2026 with a 30-day trial; DNS Protection can be managed from Sophos Central’s India region
Sophos estates that want web policy in a managed browser and DNS filtering on Windows laptops, on the same licence as their ZTNA.
The catch: The DNS agent covers Windows endpoints only — not macOS or Windows Server — and control is DNS plus in-browser rules, with no proxy TLS inspection or API CASB. No resolver city is documented.
quoted after a demo; DNS-layer category filtering with roaming agents for laptops and Chromebooks, the product earlier sold as Secure Internet Gateway (ex-Comodo Dome Shield); hosted in US (Ohio) and EU (Frankfurt) regions
Smaller estates already on Xcitium endpoint protection that want DNS filtering from the same vendor and console.
The catch: DNS layer only, DNS logs downloadable by API for 5 days, hosting only in the US and EU, and no published price or DoH handling — confirm all four before buying.

quoted, sold as Kaspersky Security for Internet Gateway (partner price lists band it per user); a proxy or ICAP gateway on your own servers with HTTPS inspection, anti-malware and URL filtering, in clusters of up to 20 nodes; version 6.2 (October 2025) is supported to September 2027
Estates that need the web gateway and its logs on their own servers, as a proxy or behind an existing one, with Kaspersky already on the endpoints.
The catch: No roaming agent or CASB, and reputation lookups go to Kaspersky Security Network unless you run its private version. Kaspersky is barred from sale in the US since 2024 — check whether that matters to your customers or auditors.
self-hosted software on your own Linux servers, VMs or cloud instance; a free licence with no time limit covers the proxy and HTTPS inspection, while URL categories, live threat feeds and add-ons need the quoted annual subscription (an archived August 2024 page put it under US$9 per user per year); built in India by a business unit of Office Efficiencies (INDIA) Pvt Ltd
Organisations that must keep the proxy, its policy and its logs on infrastructure they run themselves, including former Seqrite gateway sites.
The catch: You size, patch and operate it; there is no roaming agent (remote Windows laptops come back over a paid VPN add-on), no CASB and no analyst coverage. Logs default to 30 days locally, so forward them for CERT-In’s 180 days.

per licence per month billed yearly, where a licence is one roaming device or 10,000 network DNS queries a day; Core ($1.00) has no roaming client, which starts at Plus ($2.25) along with DNS PreCheck, CyberSight and per-user policies; Enterprise is quoted; 14-day trial
Small and mid-sized teams that want protective DNS deployed the same day at a printed price, on networks and roaming devices.
The catch: DNS layer only: no TLS inspection, proxy or CASB. Query logs are kept 9 days, so CERT-In’s 180 days needs the paid Data Export add-on; DoH is handled automatically only in Firefox; no Indian resolver city is documented.

per user per year, quoted: the Core package is the web tier (gateway, DNS security, unlimited HTTPS decryption, basic CASB) bought without ZTNA or SD-WAN; inline CASB comes with Advanced and API CASB with Complete; Cloud Connector agent on six operating systems
Teams that want a full-inspection cloud web gateway with data centres listed in Mumbai and Delhi, and the option to run the same gateway on premises.
The catch: Log retention and DoH handling are not published, so confirm both and stream logs to a SIEM for CERT-In’s 180 days; the reporting licence is a separate line.

per user, quoted by the products deployed (Protect, Secure and/or Manage) plus add-ons; the one public figure is $130 per user per year on a US-only AWS Marketplace listing for up to 99 users; risky pages run in Menlo’s cloud browser, and its status page lists Mumbai for proxy, web isolation and document isolation
Teams that want risky web sessions rendered in the vendor’s cloud rather than on the laptop, with inline CASB and full TLS inspection.
The catch: An isolation proxy, not a DNS filter, and no API-CASB. Logging is listed as global, so plan a SIEM export for CERT-In’s 180 days; DoH handling is not documented.
quoted per device per year; an agent on Windows and macOS filters the device’s own DNS lookups on and off the network and stops Chrome and Firefox using their own DoH; tenant data sits in Europe, the US or the UK
Small IT teams that want DNS filtering on every laptop from the same agent and dashboard as Heimdal’s patching and antivirus.
The catch: Filters only system-generated DNS, so apps with their own resolver or a full-tunnel VPN bypass it; blocks by domain with no TLS inspection; no Linux agent and no India data region.
quoted per device per year; the office’s DNS is forwarded to Heimdal’s resolvers on AWS, so no agent is installed; how devices behind a forwarder are counted is not documented
Offices that want every device on the network filtered, including printers and guests, without installing anything.
The catch: Covers only traffic on the protected network, with no roaming; the resolver location is not named and the “CASB” view is a list of apps seen in DNS, not a CASB.
Security Tokens, 3 per protected device or workload, quoted or by private offer on AWS and Azure — Infoblox no longer licenses it per user; cloud resolvers in Mumbai and Hyderabad (added May 2025), an on-premises option on NIOS, and the Infoblox Endpoint agent for Windows, macOS, Linux, iOS, Android and ChromeOS
Estates that want protective DNS from the vendor whose DDI already answers their queries, with threat intelligence that flags domains before they turn malicious and Indian resolvers.
The catch: DNS layer only — no TLS inspection, proxy or CASB. The management portal is hosted in North America or Europe, not India, and the portal keeps reports for about a month (60 days in the historical viewer), so export logs for CERT-In’s 180 days.

per user, quoted through partners (Cloud SWG or Cloud SWG Advanced); full TLS inspection, DLP and threat protection included, risky-web isolation from the Advanced tier; Skyhigh Client Proxy for Windows and macOS; status page lists PoPs in Bangalore, Noida and Mumbai, and India is a selectable log-storage location
Estates that want a cloud web gateway that shares one policy with an on-premises gateway they already run, with Indian PoPs and Indian log storage.
The catch: Cloud SWG alone controls apps from Skyhigh’s cloud registry but is not a CASB — shadow-IT and sanctioned-app CASB come with the SSE suites. Logs are kept 100 days by default (365 with an add-on); prices are partner-quoted only.

per user, quoted through partners (WSG-S), on appliances or VMs you run; version 12.2.25 is the main release and 13.0 is limited availability without cloud policy sync; threat protection is an add-on on this SKU
Estates that must keep the web gateway and its logs in their own data centre — government and regulated buyers among them — or that run the old McAfee Web Gateway today.
The catch: No roaming on its own: off-network users need the hybrid cloud gateway and Client Proxy. App control is inline only, and the 13.0 line cannot yet sync policy with the cloud.

per user, quoted through partners — Shadow IT (C02) and unlimited sanctioned SaaS apps (C63) are separate SKUs, both inside the SSE Advanced suite; API scanning plus forward and reverse proxy, with Skyhigh DLP; Mumbai proxy and DLP PoPs
Estates that want to find and govern shadow SaaS and scan sanctioned apps by API, from the CASB lineage that started as Skyhigh Networks.
The catch: Shadow IT and sanctioned-app control are licensed apart, so check which the quote covers. Logs are kept 100 days by default; no named large Indian deployment is published.

quoted through partners; usually licensed with Edge SWG as one per-user, per-year Web Protection licence; PoPs in Delhi and Mumbai (Broadcom KB 167174); the SES agent is the roaming client now that the WSS Agent is end-of-line; CASB is the separate CloudSOC product
Symantec and Blue Coat estates that want a cloud gateway on the same licence and policy as the proxies they already run.
The catch: Quote-only with no published unit price; CASB means buying CloudSOC; the log-storage location is not documented, so get it in writing for CERT-In’s 180 days.

quoted per user per year under the Web Protection licence, with appliances or virtual editions extra; the Blue Coat ProxySG lineage, running on your own hardware; SGOS 7.3 support ends around December 2026
Banks and enterprises that still run ProxySG and need a supported path — renew on Edge SWG, or move users to the cloud gateway under the same licence.
The catch: No roaming on its own (off-network users need Cloud SWG and the SES agent); hardware and support renewals are where Broadcom’s licensing changes bite — model the renewal before signing.

quoted through partners; inline gateway plus API scanning of sanctioned apps, sharing Symantec DLP’s policy engine across cloud, email and web; Mirror Gateway for unmanaged devices
Symantec DLP estates that want the same data policy enforced inside SaaS apps, in flight and at rest.
The catch: No published price or licence unit, and the tenant’s data region is not documented for India — ask in writing.

quoted, with a free trial; a recursive-DNS firewall that proxies only risky domains under the SIA Intelligence licence, or all web traffic on the Full Web Proxy; payload malware scanning needs the SIA Advanced Threat licence; the Akamai Zero Trust Client is the roaming agent (formerly Enterprise Threat Protector)
Teams that want DNS-first filtering everywhere and full inspection only for risky destinations, from a vendor that already runs a carrier-scale recursive DNS service.
The catch: Shadow-IT controls give application visibility, not a CASB. No Indian resolver city is documented and log retention is not stated, so get both in writing and export logs for CERT-In’s 180 days.

per user per year through partners: Internet Access is the web gateway plus firewall-as-a-service, Total Access adds ZTNA and MDR monitoring; US resellers list about $85 and $115–119 per user per year, which are not Indian prices; no Firebox needed
MSP-managed teams that want remote users’ web traffic inspected in the cloud with TLS decryption, under the same console as their Fireboxes.
The catch: No CASB and not a DNS filter (DNSWatch is a Firebox feature); PoP locations and log retention are unpublished, so plan exports for CERT-In’s 180 days.

quoted through MSPs or direct, with a free trial; sites repoint DNS to WebTitan Cloud, the OTG agent covers Windows, macOS and Chromebook laptops off the network, and a DNS proxy with an AD agent gives per-user policy; WebTitan lists a Mumbai instance among its regional instances
MSPs and small multi-site businesses that want DNS filtering with per-user AD policy and roaming laptops, on an instance in Mumbai.
The catch: DNS layer only, with no TLS inspection, proxy or CASB. Antivirus “Secure DNS” features that send DNS over their own encrypted connection bypass it, OTG does not run on virtual machines, and log retention is not published, so plan an export for CERT-In’s 180 days.
Inline CASBRules out Cisco Umbrella — API-based CASB only; it scans what is already in the cloud application and cannot block in real time; Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), Barracuda Network Protection (web security), Sophos Firewall (web protection), OpenText Core DNS Protection (formerly Webroot DNS Protection), Jamf Safe Internet, Coro Network (secure web gateway), Microsoft Entra Internet Access, Palo Alto Advanced DNS Security (incl. the standalone Resolver), N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, DNSFilter, Heimdal DNS Security – Endpoint, Heimdal DNS Security – Network, Infoblox Threat Defense, Skyhigh Secure Web Gateway (cloud and hybrid), Symantec Cloud SWG (Broadcom), Symantec Edge SWG (formerly ProxySG), Akamai Secure Internet Access Enterprise, WatchGuard FireCloud (Internet Access, Total Access) and WebTitan DNS Filtering (TitanHQ) — no CASB capability documented. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Forcepoint CASB, Palo Alto Prisma Access (web), Cato SSE (web), Check Point Harmony SASE (Internet Access), Trend Vision One ZTSA — Internet Access, Versa SSE (web), Forcepoint Web Security, Fortinet FortiProxy, iboss Zero Trust SASE (web), Menlo Secure Enterprise Browser, Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway), Skyhigh CASB and Symantec CloudSOC CASB (Broadcom).
API CASBRules out Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), Barracuda Network Protection (web security), Sophos Firewall (web protection), OpenText Core DNS Protection (formerly Webroot DNS Protection), Jamf Safe Internet, Coro Network (secure web gateway), Microsoft Entra Internet Access, Palo Alto Advanced DNS Security (incl. the standalone Resolver), N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, DNSFilter, Heimdal DNS Security – Endpoint, Heimdal DNS Security – Network, Infoblox Threat Defense, Skyhigh Secure Web Gateway (cloud and hybrid), Symantec Cloud SWG (Broadcom), Symantec Edge SWG (formerly ProxySG), Akamai Secure Internet Access Enterprise, WatchGuard FireCloud (Internet Access, Total Access) and WebTitan DNS Filtering (TitanHQ) — no CASB capability documented; Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Trend Vision One ZTSA — Internet Access, Forcepoint Web Security, Fortinet FortiProxy, Menlo Secure Enterprise Browser and Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway) — inline CASB only; it controls traffic in flight and cannot scan data already at rest. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Forcepoint CASB, Palo Alto Prisma Access (web), Cato SSE (web), Check Point Harmony SASE (Internet Access), Versa SSE (web), iboss Zero Trust SASE (web), Skyhigh CASB and Symantec CloudSOC CASB (Broadcom).
A DNS-layer tierRules out Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Sophos Firewall (web protection), Forcepoint CASB, Cato SSE (web), Trend Vision One ZTSA — Internet Access, Versa SSE (web), Microsoft Entra Internet Access, Forcepoint Web Security, Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, Menlo Secure Enterprise Browser, Skyhigh Secure Web Gateway (cloud and hybrid), Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway), Skyhigh CASB, Symantec Cloud SWG (Broadcom), Symantec Edge SWG (formerly ProxySG), Symantec CloudSOC CASB (Broadcom) and WatchGuard FireCloud (Internet Access, Total Access) — a full proxy with no DNS-layer tier to start on. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), Cloudflare One — Gateway (web), Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security), OpenText Core DNS Protection (formerly Webroot DNS Protection), Palo Alto Prisma Access (web), Check Point Harmony SASE (Internet Access), Jamf Safe Internet, Coro Network (secure web gateway), Palo Alto Advanced DNS Security (incl. the standalone Resolver), Fortinet FortiProxy, N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), DNSFilter, iboss Zero Trust SASE (web), Heimdal DNS Security – Endpoint, Heimdal DNS Security – Network, Infoblox Threat Defense, Akamai Secure Internet Access Enterprise and WebTitan DNS Filtering (TitanHQ).
Full proxy inspectionRules out Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), OpenText Core DNS Protection (formerly Webroot DNS Protection), Jamf Safe Internet, Coro Network (secure web gateway), Palo Alto Advanced DNS Security (incl. the standalone Resolver), N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), DNSFilter, Heimdal DNS Security – Endpoint, Heimdal DNS Security – Network, Infoblox Threat Defense and WebTitan DNS Filtering (TitanHQ) — DNS layer only; it blocks a destination and cannot see inside an allowed one. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security), Sophos Firewall (web protection), Forcepoint CASB, Palo Alto Prisma Access (web), Cato SSE (web), Check Point Harmony SASE (Internet Access), Trend Vision One ZTSA — Internet Access, Versa SSE (web), Microsoft Entra Internet Access, Forcepoint Web Security, Fortinet FortiProxy, Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, iboss Zero Trust SASE (web), Menlo Secure Enterprise Browser, Skyhigh Secure Web Gateway (cloud and hybrid), Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway), Skyhigh CASB, Symantec Cloud SWG (Broadcom), Symantec Edge SWG (formerly ProxySG), Symantec CloudSOC CASB (Broadcom), Akamai Secure Internet Access Enterprise and WatchGuard FireCloud (Internet Access, Total Access).
Full TLS inspectionRules out Cisco Umbrella and Akamai Secure Internet Access Enterprise — selective TLS inspection at the higher tiers rather than full inspection throughout; Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), OpenText Core DNS Protection (formerly Webroot DNS Protection), Jamf Safe Internet, Coro Network (secure web gateway), Palo Alto Advanced DNS Security (incl. the standalone Resolver), N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), DNSFilter, Heimdal DNS Security – Endpoint, Heimdal DNS Security – Network, Infoblox Threat Defense and WebTitan DNS Filtering (TitanHQ) — no TLS inspection; encrypted content is not visible at all. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security), Sophos Firewall (web protection), Forcepoint CASB, Palo Alto Prisma Access (web), Cato SSE (web), Check Point Harmony SASE (Internet Access), Trend Vision One ZTSA — Internet Access, Versa SSE (web), Microsoft Entra Internet Access, Forcepoint Web Security, Fortinet FortiProxy, Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, iboss Zero Trust SASE (web), Menlo Secure Enterprise Browser, Skyhigh Secure Web Gateway (cloud and hybrid), Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway), Skyhigh CASB, Symantec Cloud SWG (Broadcom), Symantec Edge SWG (formerly ProxySG), Symantec CloudSOC CASB (Broadcom) and WatchGuard FireCloud (Internet Access, Total Access).
Off-network coverageRules out Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Sophos Firewall (web protection), Palo Alto Advanced DNS Security (incl. the standalone Resolver), Fortinet FortiProxy, Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, Heimdal DNS Security – Network, Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway) and Symantec Edge SWG (formerly ProxySG) — enforcement happens on your network only; devices elsewhere are uncovered without a second product. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security), OpenText Core DNS Protection (formerly Webroot DNS Protection), Forcepoint CASB, Palo Alto Prisma Access (web), Cato SSE (web), Check Point Harmony SASE (Internet Access), Trend Vision One ZTSA — Internet Access, Versa SSE (web), Jamf Safe Internet, Coro Network (secure web gateway), Microsoft Entra Internet Access, Forcepoint Web Security, N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), DNSFilter, iboss Zero Trust SASE (web), Menlo Secure Enterprise Browser, Heimdal DNS Security – Endpoint, Infoblox Threat Defense, Skyhigh Secure Web Gateway (cloud and hybrid), Skyhigh CASB, Symantec Cloud SWG (Broadcom), Symantec CloudSOC CASB (Broadcom), Akamai Secure Internet Access Enterprise, WatchGuard FireCloud (Internet Access, Total Access) and WebTitan DNS Filtering (TitanHQ).
Buyable standaloneRules out Cisco Secure Access (web), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Sophos Firewall (web protection), Jamf Safe Internet and Coro Network (secure web gateway) — sold inside the vendor's wider platform or on its firewall, not as a standalone web filter. That leaves Cisco Umbrella, Cloudflare DNS (1.1.1.1 resolver · 1.1.1.1 for Families), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security), OpenText Core DNS Protection (formerly Webroot DNS Protection), Forcepoint CASB, Palo Alto Prisma Access (web), Cato SSE (web), Check Point Harmony SASE (Internet Access), Trend Vision One ZTSA — Internet Access, Versa SSE (web), Microsoft Entra Internet Access, Forcepoint Web Security, Palo Alto Advanced DNS Security (incl. the standalone Resolver), Fortinet FortiProxy, N-able DNS Filtering, Sophos Workspace Protection (DNS Protection + Protected Browser), Xcitium Web Protection (formerly Secure Internet Gateway), Kaspersky Web Traffic Security, SafeSquid Secure Web Gateway, DNSFilter, iboss Zero Trust SASE (web), Menlo Secure Enterprise Browser, Heimdal DNS Security – Endpoint, Heimdal DNS Security – Network, Infoblox Threat Defense, Skyhigh Secure Web Gateway (cloud and hybrid), Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway), Skyhigh CASB, Symantec Cloud SWG (Broadcom), Symantec Edge SWG (formerly ProxySG), Symantec CloudSOC CASB (Broadcom), Akamai Secure Internet Access Enterprise, WatchGuard FireCloud (Internet Access, Total Access) and WebTitan DNS Filtering (TitanHQ).
Indian resolver presenceRules nothing out on published terms. It flags Cisco Secure Access (web) — Indian resolver or PoP location not established from vendor documentation, Fortinet FortiSASE (web filtering) — Indian resolver or PoP location not established from vendor documentation, Barracuda Network Protection (web security) — Indian resolver or PoP location not established from vendor documentation, Sophos Firewall (web protection) — Indian resolver or PoP location not established from vendor documentation, OpenText Core DNS Protection (formerly Webroot DNS Protection) — Indian resolver or PoP location not established from vendor documentation, Versa SSE (web) — Indian resolver or PoP location not established from vendor documentation, Jamf Safe Internet — Indian resolver or PoP location not established from vendor documentation, Coro Network (secure web gateway) — Indian resolver or PoP location not established from vendor documentation, Palo Alto Advanced DNS Security (incl. the standalone Resolver) — Indian resolver or PoP location not established from vendor documentation, Fortinet FortiProxy — Indian resolver or PoP location not established from vendor documentation, N-able DNS Filtering — Indian resolver or PoP location not established from vendor documentation, Sophos Workspace Protection (DNS Protection + Protected Browser) — Indian resolver or PoP location not established from vendor documentation, Xcitium Web Protection (formerly Secure Internet Gateway) — Indian resolver or PoP location not established from vendor documentation, Kaspersky Web Traffic Security — Indian resolver or PoP location not established from vendor documentation, SafeSquid Secure Web Gateway — Indian resolver or PoP location not established from vendor documentation, DNSFilter — Indian resolver or PoP location not established from vendor documentation, Heimdal DNS Security – Endpoint — Indian resolver or PoP location not established from vendor documentation, Heimdal DNS Security – Network — Indian resolver or PoP location not established from vendor documentation, Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway) — Indian resolver or PoP location not established from vendor documentation, Symantec Edge SWG (formerly ProxySG) — Indian resolver or PoP location not established from vendor documentation, Symantec CloudSOC CASB (Broadcom) — Indian resolver or PoP location not established from vendor documentation, Akamai Secure Internet Access Enterprise — Indian resolver or PoP location not established from vendor documentation and WatchGuard FireCloud (Internet Access, Total Access) — Indian resolver or PoP location not established from vendor documentation — marked on the cards, not removed.
Above 5,000 filtered usersRules nothing out on published terms. It flags Barracuda Network Protection (web security) — Documented deployments stop short of this size, Sophos Firewall (web protection) — Documented deployments stop short of this size, OpenText Core DNS Protection (formerly Webroot DNS Protection) — Documented deployments stop short of this size, Jamf Safe Internet — Documented deployments stop short of this size, Coro Network (secure web gateway) — Documented deployments stop short of this size, Microsoft Entra Internet Access — Documented deployments stop short of this size, Forcepoint Web Security — Documented deployments stop short of this size, Palo Alto Advanced DNS Security (incl. the standalone Resolver) — Documented deployments stop short of this size, Fortinet FortiProxy — Documented deployments stop short of this size, N-able DNS Filtering — Documented deployments stop short of this size, Sophos Workspace Protection (DNS Protection + Protected Browser) — Documented deployments stop short of this size, Xcitium Web Protection (formerly Secure Internet Gateway) — Documented deployments stop short of this size, Kaspersky Web Traffic Security — Documented deployments stop short of this size, SafeSquid Secure Web Gateway — Documented deployments stop short of this size, DNSFilter — Documented deployments stop short of this size, Heimdal DNS Security – Endpoint — Documented deployments stop short of this size, Heimdal DNS Security – Network — Documented deployments stop short of this size, Skyhigh Secure Web Gateway (cloud and hybrid) — Documented deployments stop short of this size, Skyhigh Secure Web Gateway On-Prem (formerly McAfee Web Gateway) — Documented deployments stop short of this size, Skyhigh CASB — Documented deployments stop short of this size, Symantec Cloud SWG (Broadcom) — Documented deployments stop short of this size, Symantec Edge SWG (formerly ProxySG) — Documented deployments stop short of this size, Symantec CloudSOC CASB (Broadcom) — Documented deployments stop short of this size, Akamai Secure Internet Access Enterprise — Documented deployments stop short of this size, WatchGuard FireCloud (Internet Access, Total Access) — Documented deployments stop short of this size and WebTitan DNS Filtering (TitanHQ) — Documented deployments stop short of this size — marked on the cards, not removed.
Both facts about DNS filtering are true at onceIt is the cheapest security control you can deploy — Cisco's DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare's resolver is free — and it is the easiest to bypass. DNS-over-HTTPS in a browser, a hardcoded public resolver, a personal VPN, or an application that ignores the system resolver all route around it. That does not make it worthless: it stops a large share of commodity threats at almost no cost and no latency. It makes it a floor rather than a ceiling, and anyone selling it as complete web security is selling you the floor.
TLS inspection is a certificate project before it is a security controlMost traffic is encrypted, so inspecting content means decrypting it, which means your inspection certificate must be trusted by every device — managed laptops, phones, contractors' machines, and the applications that pin their own certificates and will simply break. Full TLS inspection is documented at Cloudflare One, Zscaler, Netskope, Palo Alto (CDSS and Prisma Access), FortiSASE, FortiProxy, Forcepoint, Skyhigh (cloud and on-prem gateways and CASB), Symantec (Cloud and Edge SWG, CloudSOC), Cato, Check Point, Trend Micro, Versa, Microsoft Entra Internet Access, Kaspersky, Barracuda and Sophos Firewall; Cisco Umbrella is selective at the proxy tiers, and the DNS-only products here (Cloudflare DNS, Advanced DNS Security, N-able, Xcitium, OpenText, Jamf, Coro and Sophos Workspace Protection) do none. Plan the certificate rollout and the exception list before the licence, not after.
Inline CASB and API CASB are different products wearing one nameInline sits in the traffic path and can stop an upload as it happens; it sees only what traverses it, and only while it traverses. API-based CASB connects to the cloud application out of band and scans what is already there — historical files, sharing permissions, dormant data — and cannot block anything in real time. Netskope, Cloudflare, Forcepoint CASB, Skyhigh CASB, Symantec CloudSOC, Prisma Access, Cato, Check Point and Versa document both; Cisco Umbrella is API-based; Palo Alto CDSS, FortiSASE, FortiProxy, Trend Micro and Forcepoint Web Security are inline; Microsoft Entra Internet Access leaves CASB to the separate Defender for Cloud Apps; Barracuda, Sophos and the DNS-only products document none. Estates usually need both, and are usually quoted one.
False positives are how the control diesA category engine that blocks a business application erodes trust fast: the exception list grows, then someone disables the policy for a group, then for everyone. Ask for the exception workflow and who can approve one, and pilot against your own top fifty destinations rather than a vendor's test list. Measured false-positive behaviour on Indian business sites is delivery-team knowledge: [TechBag to confirm].
What Indian regulators actually requireSEBI's Cybersecurity and Cyber Resilience Framework (20 August 2024) is the plainest: guideline 4.e says regulated entities "shall implement DNS filtering services", 4.c requires web filters and 4.b proxy servers — for every SEBI-regulated entity except the smallest self-certifying ones. CERT-In's Directions (28 April 2022) require 180 days of logs, and its FAQ names proxy-server logs; FAQ Q35 lets them sit outside India if they can be produced in reasonable time. CERT-In's June 2023 guidelines for government entities go further: an internal or NIC resolver (1.10.10.10) with public DNS blocked, and internet access through a proxy only. RBI's 2016 framework says banks should "consider" secure web gateways that inspect HTTPS — advice, not a mandate. Check each product's log retention against the 180 days before you sign.
Under 200 usersPublished pricing excludes nobody at this size: Cloudflare is free to 50 users and $7 beyond, Cisco Umbrella's DNS tiers start around $2.25 per user per month, Microsoft Entra Internet Access lists $5 per user per month on top of Entra ID P1, and Fortinet's band starts at 50 users. Forcepoint's listed $55 per user per year carries a 500-user minimum. The platform-bundled options (Cisco Secure Access, Netskope, Palo Alto CDSS) publish no standalone floor. Current published minimums, by vendor: [TechBag to confirm].
Each shortlist states whether the answer is the DNS floor or proxy depth, and what it costs to deploy. If the requirement mentions content or data, start from the second row.
Why: DNS filtering needs a resolver change and nothing else — Cloudflare's is free to start and documents six Indian cities; Cisco's DNS tiers run roughly $30–40 per user per year.
The trade-off: It blocks destinations and cannot see inside an allowed one, and DNS-over-HTTPS or a personal VPN routes around it. A floor, deliberately chosen, is a legitimate answer — an assumed ceiling is not.
Why: Content inspection, malware scanning and data controls need a proxy in the path with TLS decryption — Zscaler is the depth reference, Cloudflare publishes a price, Netskope adds application-instance awareness.
The trade-off: All three mean a certificate on every device and an exception list for applications that pin certificates. Budget the rollout as a project, not a setting.
Why: Instance awareness is the capability domain-level filtering cannot express at all: same domain, different tenant, different verdict.
The trade-off: It requires inline inspection and a platform-priced product — this is more capability than a DNS-only requirement needs, and the quote reflects that.
Why: API-based CASB connects out of band and scans historical data, sharing permissions and dormant files — the half inline inspection cannot see.
The trade-off: API CASB blocks nothing in real time. Estates usually need both modes; Netskope and Cloudflare document both, Cisco Umbrella is API-based.
Why: Web filtering enforced by the appliance already inspecting the traffic avoids a second console and a second subscription entirely.
The trade-off: Sophos and Palo Alto CDSS have no lightweight roaming agent here — devices off the network are uncovered without a cloud service, which is the whole reason the rest of this page exists.
Why: The same categories, the same policy engine and the same console extended to roaming users — Fortinet gives existing FortiGate customers Security Fabric pricing.
The trade-off: Familiarity is worth real money in operations and deepens single-vendor commitment. Neither Fortinet nor Cisco documents Indian PoP cities here.
Why: Cloudflare documents six Indian cities, Netskope eight Indian data centres, Zscaler four cities and Cisco Umbrella Mumbai and Chennai — resolution and inspection latency is felt on every request, not just at connection time.
The trade-off: Cisco Secure Access, Fortinet, Barracuda and Sophos do not document Indian resolver locations on this guide — flagged, not ruled out. Ask for the location and test it.
Why: Barracuda licenses web security inside SecureEdge per site and per user; Umbrella deploys per site by resolver change; Cloudflare covers roaming users at a published price.
The trade-off: Barracuda documents no CASB, so cloud application control needs another product. Normalise the split per-site and per-user meter before comparing.
Why: Entra Internet Access puts web filtering inside the Conditional Access policy you already run, at a published $5 per user per month on top of Entra ID P1, with points of presence in Chennai and Pune.
The trade-off: No CASB in that licence and no Microsoft-native malware engine — Defender for Cloud Apps and the Netskope add-on cost extra. Compare against a specialist before calling it complete.
Why: SEBI's CSCRF guideline 4.e asks regulated entities to implement DNS filtering services; a DNS-layer service meets the letter of that quickly, and the three here cover free, cheapest-paid and standalone-enterprise options.
The trade-off: DNS filtering is a floor, not web inspection — 4.c also asks for web filters. Check that query logs can be kept or exported for CERT-In's 180 days; several DNS services hold them for days, not months.
Each depth sees something the one above it misses, and costs more to deploy. Place your actual requirement on this ladder before reading a price.
Depth 1
DNS resolution
The domain never resolves. Covers every device and protocol using your resolver, costs almost nothing, adds no latency — and sees no content at all. Bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN.
Depth 2
Proxy with TLS inspection
The connection is terminated, decrypted and inspected: files, uploads, malware, data-loss rules. Everything depth one cannot do — at the cost of a certificate on every device and an exception list for pinned applications.
Depth 3
Application-instance awareness
Same domain, different tenant, different verdict: allow the corporate instance of a cloud application and block the personal one. Domain-level filtering cannot express this at all.
The other axis
API CASB — data at rest
Not deeper inspection but a different vantage point: connected out of band to the cloud application, scanning historical files, sharing permissions and dormant data that never traversed your proxy.
The bypass test
Ask these before the pilot, in this order.
The India layer
Resolution latency is felt on every single request.
Web and DNS controls scale by devices covered and by exceptions accumulated. The bill follows the per-user tier; the credibility follows the false-positive rate.
Deployment speed is the constraint
Put this in your PoC
Turn on DNS filtering, then check how many devices actually use your resolver. The gap is the real coverage number.
TLS and false positives are the constraints
Put this in your PoC
Run the proxy in monitor mode for two weeks and count what it would have blocked. The false positives in that list are your rollout risk.
Coverage gaps and residency are the constraints
Put this in your PoC
Measure what fraction of egress actually traverses the control. If nobody knows, the coverage number is aspirational.
Cisco, Cloudflare, Zscaler, Netskope, Palo Alto and Fortinet document large estates; Barracuda Network Protection and Sophos Firewall web protection are flagged unverified above 5,000 users. Where a specific filter strains for your traffic mix: [TechBag to confirm].
The category lists, the exception list and the trust chain are all per platform. Moving means rebuilding the policy and re-trusting every device, while the old control still carries production traffic.
The category policy
Years of accumulated allow and block decisions, many with no recorded reason. Category names differ between vendors, so it is a translation rather than an export.
The certificate
A new inspection certificate trusted by every device before the switch, and the old one removed afterwards — or inspection silently fails for someone.
The exception list
Applications that pin certificates, sites that break under inspection, and the business tools someone got unblocked in 2023. All of it re-tested.
The overlap
Both controls run while users and sites cut over. Two subscriptions for a quarter is cheaper than one week of blocked business traffic.
Policy translation, certificate rollout and exception re-testing for your estate: [TechBag to confirm] — TechBag scopes it from your policy size and device inventory.
What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the licence leaves out — which, for web security, is the certificate project and the exceptions.
Four places this filtering may already exist. Three of them genuinely do.
If the filtering you need is already inside something you renew, we say so. It costs us a sale and saves you one.
Published and reported per-user meters (INR for scale), worked at 200 / 2,000 / 20,000 users per year. The DNS tiers and the proxy tiers are deliberately shown together, because the gap between them — roughly threefold at Cisco — is the real decision on this page.
The certificate project — stated apart, because it is not in any licence
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
An inspection certificate trusted by every device, plus the bypass list for applications that pin their own. It is a device-management project with a security deadline, and it is in no licence. Your device count: [TechBag to confirm].
Every unblock request, every pinned application, every business tool that broke. Small individually; the list is what the control actually is after two years.
Devices not using your resolver, browsers with DNS-over-HTTPS, personal VPNs and unmanaged machines. Measure the fraction of egress that actually traverses the control before reporting coverage.
Documented filtering behaviour and deployment outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the first audit.
DNS filtering bypassed by DoH, hardcoded resolvers or a VPN
The policy was deployed and a browser setting routed around it. Ask how the product detects DNS-over-HTTPS, and measure what fraction of egress actually uses your resolver.
Certificate deployment stalling the TLS rollout
Inspection was licensed, configured and never enabled because the certificate never reached the devices. It is a device-management project — plan it before the licence.
False positives blocking business apps and eroding trust
One blocked business-critical site produced an exception, then a group exemption, then a disabled policy. Pilot in monitor mode against your own top destinations.
Buying DNS filtering when the requirement was web inspection
The requirement mentioned files and data; the purchase blocked domains. DNS cannot see inside an allowed destination — that is a proxy, at roughly triple the price.
Assuming CASB means both modes
The quote was API-based and the requirement was to block uploads in real time. Inline and API are different products under one acronym.
Roaming devices left uncovered
Enforcement was network-level and half the workforce stopped coming to the office. Five products here have no roaming agent at all.
Resolver latency mistaken for a slow internet connection
Resolution ran through another continent and every page felt slower. Ask for the Indian resolver location and measure it from your own offices.
Coverage reported from licences, not from traffic
The report counted seats; the control saw a fraction of egress. Measure what actually traverses it, not what was purchased.
Our retail & e-commerce guide maps CERT-In, DPDP, PCI DSS and what gateways, marketplaces and ONDC demand to the controls a store chain or online seller needs. This category answers:
Vendor-neutral. No gated content.