DNS filtering is the cheapest security control you can deploy and the easiest to bypass. Both facts matter.

At the DNS layer, a resolver refuses to translate a bad domain into an address — no agent, no latency, nothing in the traffic path. A proxy goes further: it terminates the connection, decrypts it, inspects the content and decides. The first costs almost nothing and sees only destinations; the second sees everything and costs a certificate on every device.

Cisco’s DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare’s resolver is free. A browser with DNS-over-HTTPS enabled routes around both, without asking anyone.

Already decided — before the quote

What you need to seedestinations, or content
Where the users areon the network, or anywhere
Whether you can deploy certificatesit decides if TLS inspection is real

Still yours to weigh

LayerDNS · proxy · both
CASBinline, API, or both
BypassDoH, hardcoded resolvers, personal VPNs
If you’ve never bought one

What secure web gateways and DNS filtering actually are

Two controls at two different depths. DNS filtering intercepts the name lookup that starts almost every connection: point your resolvers at the provider, and requests for known-bad or policy-blocked domains never resolve. Nothing sits in the traffic path, there is no agent to deploy on the network, and it costs very little. A secure web gateway is a proxy: traffic is terminated, decrypted, inspected for malware and data, and allowed or blocked by content rather than by destination.

Alongside them sits CASB, which controls how cloud applications are used — and which is genuinely two products under one name. Inline CASB sits in the traffic path and can stop an upload as it happens; API CASB connects to the application out of band and scans what is already there. Most estates need both and are quoted one. When these controls are bought as part of a platform rather than on their own, that is the SASE & SSE guide.

The most common mis-purchase

Buying DNS filtering when the requirement was full web inspection. DNS blocks a domain; it cannot tell you what a user uploaded to an allowed one, scan a download, or distinguish your corporate cloud tenant from a personal one. If the requirement mentions content, data or files, the answer is a proxy.

Often confused withSASE & SSE — where these controls are bought as a platform·Firewall & Network Security — web filtering enforced at your own edge·Email Security — the other delivery path for the same threats

The four routes of network security — and which one is yours

Boundary — the terms this buyer confuses

SWG vs DNS filtering vs proxy · CASB inline vs API

Three enforcement depths often sold as one product, and one acronym that is genuinely two different things. Not a maturity ladder — each sees something the others cannot.

DNS filtering

Blocks at name resolution: the domain never turns into an address. No traffic path, no latency, no certificates, and it covers every device and protocol using your resolver — including things a proxy never sees. It cannot inspect content, cannot tell one page of a site from another, and is bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN. The cheapest real control there is.

Proxy / secure web gateway

Terminates the connection, decrypts TLS, inspects content, and decides on what the traffic actually contains. Sees files, uploads, form data and malware; enforces data-loss rules. Costs a certificate on every device, an exception list for applications that pin certificates, and latency in the path. Everything DNS filtering cannot do, at the price of a project.

CASB inline

In the traffic path, on the way to the cloud application. Can block an upload as it happens, coach a user in real time, and distinguish the corporate tenant of an application from a personal one. Sees only what traverses it, and only while it does — data already sitting in the application is invisible.

CASB API

Connected to the cloud application out of band, scanning what is already there: historical files, sharing permissions, external collaborators, dormant sensitive data. Finds the exposure inline inspection never saw — and can block nothing in real time. The two modes answer different questions and most estates need both.

These are not a maturity ladder. DNS filtering is not a weak proxy — it covers protocols and devices a proxy never touches, at almost no cost. A proxy is not a better DNS filter — it sees content and carries a certificate burden. Inline and API CASB are not tiers of each other. The honest estate deploys DNS filtering everywhere as a floor and adds proxy depth where the data actually lives.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests what documentation establishes (enforcement layer, TLS depth, roaming coverage, CASB mode, standalone availability, India presence); bypass behaviour, false positives and the certificate project are prose because they come from a pilot and an operations plan.

01

DNS-layer versus full proxy inspection

Destinations or content. The single question that decides whether this is a cheap control deployed everywhere or a project with a certificate rollout.

02

Roaming agent versus network-level deployment

Enforcement for devices that leave the office. Sophos and Palo Alto CDSS are network- or platform-bound here; the rest document roaming coverage.

03

TLS inspection depth and the certificate burden

Full, selective, or none — and then the real work: an inspection certificate trusted by every device, plus an exception list for applications that pin their own.

04

Category coverage and false-positive rate

A block on a business-critical site erodes trust in the control faster than any threat justifies it. Pilot against your own top destinations and check the exception workflow.

05

CASB — inline versus API

Two different products under one acronym: blocking in flight versus finding what is at rest. Documented per product here; most estates need both.

06

Standalone or only inside a SASE platform

Cisco Umbrella, Cloudflare, Zscaler, FortiSASE and Barracuda sell standalone; Cisco Secure Access, Netskope, Palo Alto CDSS and Sophos require the platform or appliance underneath.

07

India resolver presence and latency

DNS resolution happens on every request, so resolver distance is felt constantly. Documented for Cloudflare (six cities) and Netskope (eight data centres); not established for the rest here.

The narrowing instrument · the reasoning is the product

Narrow 11 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where Indian resolver presence is not documented it is flagged and stays, never eliminated on an absence of evidence. Every chip is reversible.

Cloud application control

How you buy it

Where it enforces

Encrypted traffic

Where the users are

India

Estate size

Bypass behaviour, false positives and the certificate rollout are in the notes below rather than chips — they decide whether the control survives contact with users, and no datasheet covers them.

Still in11/ 11
Cisco logo
$2.25–6.50₹187

per user / month across the tiers (DNS Security Essentials roughly $30–40 per user / year, DNS Advantage $40–55, SIG Essentials $60–90, SIG Advantage $95–135); the DNS tiers are the cheapest real control on this page

Estates that want DNS-layer filtering deployed across every site in an afternoon, with an upgrade path to full proxy inspection in the same console.

The catch: The DNS tiers filter by domain and cannot inspect content — the selective proxy arrives at the SIG tiers, which is where the price roughly triples. Add-on SKUs and premium support push enterprise deployments well above the list. An Indian resolver location is not established from vendor documentation.

Cheapest entryDNS → SIG ladderIndia resolver: unverified
Intel page →
Cisco logo

per user / year inside the Secure Access platform rather than standalone; the successor to Umbrella's SIG tiers with full proxy inspection, CASB and ZTNA in one subscription

Cisco estates consolidating Umbrella, VPN and web security into one cloud service under an existing enterprise agreement.

The catch: Not a standalone web filter — it arrives as a platform, which is a larger commitment than the Umbrella DNS tiers it supersedes. Indian PoP cities are not established from documentation.

Platform, not a filterFull proxyNot standalone
Intel page →
Cloudflare logo

the public resolver is free; policy-based DNS filtering sits inside Cloudflare Zero Trust (free to 50 users, then $7 per user / month); Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur

Estates that want DNS filtering on the largest documented Indian resolver footprint here, starting at no cost.

The catch: DNS layer only in this SKU — no content inspection, no TLS decryption, no CASB. It blocks a destination or it does not; what happens inside an allowed site is invisible.

Free to start6 India citiesDNS layer only
Intel page →
Cloudflare logo
Free → $7₹581

free for up to 50 users, then $7 per user / month with no user cap; DNS, HTTP and network filtering with TLS inspection, on the same Indian PoP footprint as the resolver

Estates that want full web inspection at a published price, on documented Indian infrastructure, without an enterprise negotiation.

The catch: The $7 tier is capable and is not the Enterprise product: CASB breadth, DLP depth, browser isolation and longer log retention move up to the quoted tier. TLS inspection still means deploying a certificate to every device.

Published priceFull inspectionEnterprise tier for depth
Intel page →
Zscaler logo
~$6–12₹498

per user / month reported (roughly $72–325 per user / year by edition); a full inline proxy inspecting every session, with CASB, DLP and browser isolation as higher editions or add-ons

Estates that want every session inspected in depth rather than destinations filtered — the reference proxy, and the deepest inspection here.

The catch: A proxy, not a DNS filter: there is no cheap DNS-only tier to start on, and the base edition is the gateway with data protection arriving as editions or add-ons. Named Indian PoP cities are not established from vendor documentation.

Full inline proxyNo DNS-only tierIndia PoPs: unverified
Intel page →
Netskope logo
Per user

per user / month within Netskope One; inspects by application instance — allowing the corporate tenant of a cloud application while blocking the personal one — with eight Indian data centres on NewEdge

Estates whose control requirement is per application instance rather than per domain, which domain-level filtering cannot express at all.

The catch: Sold as part of the Netskope One platform rather than as a standalone filter, so a like-for-like comparison against Umbrella's DNS tiers is not meaningful. It is more product than a DNS-only requirement needs.

Instance-aware8 India data centresPlatform-priced
Intel page →
Netskope logo
Per user

per user / month within Netskope One; both inline (in the traffic path, able to block in real time) and API-based (out of band, scanning what is already in the cloud application) — the two modes are different products in practice

Estates that need both to control cloud application use: inline to stop an upload as it happens, API to find what was uploaded last year.

The catch: Inline and API modes solve different problems and are frequently confused — API alone cannot block anything in real time, inline alone cannot see historical data at rest. Platform-priced, not standalone.

Inline + APITwo different jobsPlatform module
Intel page →
Palo Alto Networks logo

per-firewall subscriptions layered on a Strata NGFW or Prisma Access — Advanced URL Filtering and DNS Security are separate CDSS SKUs, enforced wherever that platform enforces

Palo Alto estates that want web and DNS controls inside the policy engine already running, rather than a second console.

The catch: Not a standalone product: it requires the firewall or Prisma Access underneath, and roaming coverage comes from Prisma Access rather than a lightweight DNS agent. Each service is its own subscription line.

On the Palo Alto platformSeparate CDSS SKUsNeeds the platform
Intel page →
Fortinet logo
$8–18₹664

per user / month list by bundle tier; web filtering and DNS filtering for off-network users using the same FortiGuard categories as the FortiGate estate, with Security Fabric pricing for existing customers

FortiGate estates extending the web filtering they already run on-premises to users who never come back to the office.

The catch: The categories and console are familiar, which is the point; as a standalone web filter for a non-Fortinet estate it is a less obvious purchase. Indian PoP cities are not established from vendor documentation.

Same FortiGuard categoriesFabric pricingIndia PoPs: unverified
Intel page →
Barracuda logo

web security inside SecureEdge, licensed per site for the network side and per user for the access side; content filtering and TLS inspection for distributed sites without an enterprise project

Distributed mid-market estates — many small sites — that want web filtering and firewalling from one platform and one bill.

The catch: No CASB capability documented, so cloud application control is outside its scope; documented deployments are mid-market and an Indian resolver location is not established. The split per-site and per-user meter makes comparison awkward.

Many small sitesNo CASBMid-market
Intel page →
Sophos logo
In the protection bundle

web protection inside the Standard or Xstream Protection bundle on an XGS appliance; TLS inspection is an Xstream capability, and enforcement happens at your edge rather than in a cloud PoP

Estates whose users are mostly in the office and who want web filtering enforced by the firewall already inspecting their traffic.

The catch: On-network enforcement only — there is no roaming agent here, so devices off the network are unprotected unless you also run a cloud service. It is the appliance answer to a question the rest of this page answers from the cloud.

At your edgeNo roaming agentIn the bundle
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

Inline CASBRules out Cisco Umbrella — API-based CASB only; it scans what is already in the cloud application and cannot block in real time; Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Barracuda Network Protection (web security) and Sophos Firewall (web protection) — no CASB capability documented. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Fortinet FortiSASE (web filtering).

API CASBRules out Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Barracuda Network Protection (web security) and Sophos Firewall (web protection) — no CASB capability documented; Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Fortinet FortiSASE (web filtering) — inline CASB only; it controls traffic in flight and cannot scan data already at rest. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG and Netskope CASB.

Buyable standaloneRules out Cisco Secure Access (web), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Sophos Firewall (web protection) — sold inside the vendor's wider platform or on its firewall, not as a standalone web filter. That leaves Cisco Umbrella, Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security).

A DNS-layer tierRules out Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB and Sophos Firewall (web protection) — a full proxy with no DNS-layer tier to start on. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security).

Full proxy inspectionRules out Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — DNS layer only; it blocks a destination and cannot see inside an allowed one. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security) and Sophos Firewall (web protection).

Full TLS inspectionRules out Cisco Umbrella — selective TLS inspection at the higher tiers rather than full inspection throughout; Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — no TLS inspection; encrypted content is not visible at all. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security) and Sophos Firewall (web protection).

Off-network coverageRules out Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Sophos Firewall (web protection) — enforcement happens on your network only; devices elsewhere are uncovered without a second product. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security).

Indian resolver presenceRules nothing out on published terms. It flags Cisco Umbrella — Indian resolver or PoP location not established from vendor documentation, Cisco Secure Access (web) — Indian resolver or PoP location not established from vendor documentation, Zscaler Internet Access (ZIA) — Indian resolver or PoP location not established from vendor documentation, Fortinet FortiSASE (web filtering) — Indian resolver or PoP location not established from vendor documentation, Barracuda Network Protection (web security) — Indian resolver or PoP location not established from vendor documentation and Sophos Firewall (web protection) — Indian resolver or PoP location not established from vendor documentation — marked on the cards, not removed.

Above 5,000 filtered usersRules nothing out on published terms. It flags Barracuda Network Protection (web security) — Documented deployments stop short of this size and Sophos Firewall (web protection) — Documented deployments stop short of this size — marked on the cards, not removed.

Both facts about DNS filtering are true at onceIt is the cheapest security control you can deploy — Cisco's DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare's resolver is free — and it is the easiest to bypass. DNS-over-HTTPS in a browser, a hardcoded public resolver, a personal VPN, or an application that ignores the system resolver all route around it. That does not make it worthless: it stops a large share of commodity threats at almost no cost and no latency. It makes it a floor rather than a ceiling, and anyone selling it as complete web security is selling you the floor.

TLS inspection is a certificate project before it is a security controlMost traffic is encrypted, so inspecting content means decrypting it, which means your inspection certificate must be trusted by every device — managed laptops, phones, contractors' machines, and the applications that pin their own certificates and will simply break. Full TLS inspection is documented at Cloudflare One, Zscaler, Netskope, Palo Alto CDSS, FortiSASE, Barracuda and Sophos; Cisco Umbrella's DNS tiers are selective at the proxy tiers, and Cloudflare's DNS-only SKU does none. Plan the certificate rollout and the exception list before the licence, not after.

Inline CASB and API CASB are different products wearing one nameInline sits in the traffic path and can stop an upload as it happens; it sees only what traverses it, and only while it traverses. API-based CASB connects to the cloud application out of band and scans what is already there — historical files, sharing permissions, dormant data — and cannot block anything in real time. Netskope and Cloudflare document both; Cisco Umbrella is API-based; Palo Alto CDSS and FortiSASE are inline; Barracuda and Sophos document none. Estates usually need both, and are usually quoted one.

False positives are how the control diesA category engine that blocks a business application erodes trust fast: the exception list grows, then someone disables the policy for a group, then for everyone. Ask for the exception workflow and who can approve one, and pilot against your own top fifty destinations rather than a vendor's test list. Measured false-positive behaviour on Indian business sites is delivery-team knowledge: [TechBag to confirm].

Under 200 usersPublished pricing excludes nobody at this size: Cloudflare is free to 50 users and $7 beyond, Cisco Umbrella's DNS tiers start around $2.25 per user per month, and Fortinet's band starts at 50 users. The platform-bundled options (Cisco Secure Access, Netskope, Palo Alto CDSS) publish no standalone floor. Current published minimums, by vendor: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the depth named

Each shortlist states whether the answer is the DNS floor or proxy depth, and what it costs to deploy. If the requirement mentions content or data, start from the second row.

Something cheap, deployed everywhere, this week

Why: DNS filtering needs a resolver change and nothing else — Cloudflare's is free to start and documents six Indian cities; Cisco's DNS tiers run roughly $30–40 per user per year.

The trade-off: It blocks destinations and cannot see inside an allowed one, and DNS-over-HTTPS or a personal VPN routes around it. A floor, deliberately chosen, is a legitimate answer — an assumed ceiling is not.

The requirement is actually full web inspection

Why: Content inspection, malware scanning and data controls need a proxy in the path with TLS decryption — Zscaler is the depth reference, Cloudflare publishes a price, Netskope adds application-instance awareness.

The trade-off: All three mean a certificate on every device and an exception list for applications that pin certificates. Budget the rollout as a project, not a setting.

Control the corporate cloud tenant, block the personal one

Why: Instance awareness is the capability domain-level filtering cannot express at all: same domain, different tenant, different verdict.

The trade-off: It requires inline inspection and a platform-priced product — this is more capability than a DNS-only requirement needs, and the quote reflects that.

Find what is already sitting in the cloud applications

Why: API-based CASB connects out of band and scans historical data, sharing permissions and dormant files — the half inline inspection cannot see.

The trade-off: API CASB blocks nothing in real time. Estates usually need both modes; Netskope and Cloudflare document both, Cisco Umbrella is API-based.

Users are mostly in the office and there is already a firewall

Why: Web filtering enforced by the appliance already inspecting the traffic avoids a second console and a second subscription entirely.

The trade-off: Sophos and Palo Alto CDSS have no lightweight roaming agent here — devices off the network are uncovered without a cloud service, which is the whole reason the rest of this page exists.

Already running FortiGate or Palo Alto

Why: The same categories, the same policy engine and the same console extended to roaming users — Fortinet gives existing FortiGate customers Security Fabric pricing.

The trade-off: Familiarity is worth real money in operations and deepens single-vendor commitment. Neither Fortinet nor Cisco documents Indian PoP cities here.

Indian resolver presence must be documented

Why: Cloudflare documents six Indian cities and Netskope eight Indian data centres — resolution and inspection latency is felt on every request, not just at connection time.

The trade-off: Cisco, Zscaler, Fortinet, Barracuda and Sophos do not document Indian resolver locations on this guide — flagged, not ruled out. Ask for the location and test it.

Many small sites, one platform, no enterprise project

Why: Barracuda licenses web security inside SecureEdge per site and per user; Umbrella deploys per site by resolver change; Cloudflare covers roaming users at a published price.

The trade-off: Barracuda documents no CASB, so cloud application control needs another product. Normalise the split per-site and per-user meter before comparing.

The spine of the decision

Three depths of enforcement, and what each one cannot see

Each depth sees something the one above it misses, and costs more to deploy. Place your actual requirement on this ladder before reading a price.

Depth 1

DNS resolution

The domain never resolves. Covers every device and protocol using your resolver, costs almost nothing, adds no latency — and sees no content at all. Bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN.

Depth 2

Proxy with TLS inspection

The connection is terminated, decrypted and inspected: files, uploads, malware, data-loss rules. Everything depth one cannot do — at the cost of a certificate on every device and an exception list for pinned applications.

Depth 3

Application-instance awareness

Same domain, different tenant, different verdict: allow the corporate instance of a cloud application and block the personal one. Domain-level filtering cannot express this at all.

The other axis

API CASB — data at rest

Not deeper inspection but a different vantage point: connected out of band to the cloud application, scanning historical files, sharing permissions and dormant data that never traversed your proxy.

The bypass test

Ask these before the pilot, in this order.

  • What happens when a browser enables DNS-over-HTTPS? It is on by default in several browsers. Ask how the product detects and handles it, because otherwise your DNS control is advisory.
  • Who deploys the inspection certificate, and to which devices? Managed laptops are easy; phones, contractors and certificate-pinning applications are the project.
  • Pilot against our own top fifty destinations. Not the vendor’s list. A false positive on a business-critical site is how the control gets disabled.
  • Which CASB mode is in this quote — inline, API, or both? They are different products, and most estates need both.

The India layer

Resolution latency is felt on every single request.

  • Documented Indian presence: Cloudflare’s points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur — the largest documented footprint here; Netskope operates eight Indian data centres on NewEdge.
  • Not established from documentation: Indian resolver or point-of-presence locations for Cisco Umbrella, Cisco Secure Access, Zscaler, FortiSASE, Barracuda and Sophos — flagged, never ruled out. Ask for the location and measure it from your own offices.
  • Why it matters more here than elsewhere: DNS resolution happens before every connection. A resolver a continent away adds delay to everything a user does, and users notice it as “the internet is slow” rather than as a security control.
What breaks as you grow

What changes at 200, 2,000 and 20,000 users

Web and DNS controls scale by devices covered and by exceptions accumulated. The bill follows the per-user tier; the credibility follows the false-positive rate.

200users

Deployment speed is the constraint

  • A resolver change covers every device on the network in an afternoon: Cloudflare free to 50 users, Cisco's DNS tiers from about $2.25 per user per month.
  • TLS inspection is probably not worth the certificate project yet unless a specific requirement demands content inspection.
  • Roaming coverage matters as soon as anyone works from home — a DNS agent on the laptop is the cheap answer.

Put this in your PoC

Turn on DNS filtering, then check how many devices actually use your resolver. The gap is the real coverage number.

2,000users

TLS and false positives are the constraints

  • Content inspection now has a business case, and with it a certificate rollout to every managed device and an exception list for pinned applications.
  • The exception workflow becomes a real process: who approves an unblock, how fast, and where it is recorded.
  • Cloud application control appears as a requirement — and the inline versus API question arrives with it.

Put this in your PoC

Run the proxy in monitor mode for two weeks and count what it would have blocked. The false positives in that list are your rollout risk.

20,000users

Coverage gaps and residency are the constraints

  • Bypass becomes systematic rather than incidental: DoH, unmanaged devices, personal VPNs. The control needs measurement, not just deployment.
  • Resolver and inspection location become regulator-visible questions alongside latency ones.
  • Barracuda and Sophos web protection are flagged unverified above 5,000 users; the platform products document large estates.

Put this in your PoC

Measure what fraction of egress actually traverses the control. If nobody knows, the coverage number is aspirational.

Cisco, Cloudflare, Zscaler, Netskope, Palo Alto and Fortinet document large estates; Barracuda Network Protection and Sophos Firewall web protection are flagged unverified above 5,000 users. Where a specific filter strains for your traffic mix: [TechBag to confirm].

The switching cost

Leaving a web gateway is a certificate and policy migration

The category lists, the exception list and the trust chain are all per platform. Moving means rebuilding the policy and re-trusting every device, while the old control still carries production traffic.

The category policy

Years of accumulated allow and block decisions, many with no recorded reason. Category names differ between vendors, so it is a translation rather than an export.

Exit costTranslate, then audit

The certificate

A new inspection certificate trusted by every device before the switch, and the old one removed afterwards — or inspection silently fails for someone.

Exit costNew trust chain first

The exception list

Applications that pin certificates, sites that break under inspection, and the business tools someone got unblocked in 2023. All of it re-tested.

Exit costRe-test every exception

The overlap

Both controls run while users and sites cut over. Two subscriptions for a quarter is cheaper than one week of blocked business traffic.

Exit costTwo bills, one quarter

Policy translation, certificate rollout and exception re-testing for your estate: [TechBag to confirm] — TechBag scopes it from your policy size and device inventory.

What it costs

Per user per month — and the depth decides the multiple

What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the licence leaves out — which, for web security, is the certificate project and the exceptions.

01

Do you already own one?

Four places this filtering may already exist. Three of them genuinely do.

Your existing NGFW subscription
Often Web filtering and DNS security are frequently already in the bundle you renew — for traffic on your network. Audit it before buying the same categories twice.
Cloudflare's free tier
Partly The public resolver is free and Zero Trust is free to 50 users, with real policy-based DNS filtering. A legitimate control, not an enterprise gateway.
Your endpoint vendor's web filtering
Partly Many endpoint agents filter web traffic on the device, and it travels with the user. Thinner on inspection, CASB and reporting than a cloud gateway.
Your SASE or SSE subscription
Often Secure web gateway is the base module of every platform on the neighbouring guide. If you already pay for SSE, you already own this — check the tier before buying it again.

If the filtering you need is already inside something you renew, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Published and reported per-user meters (INR for scale), worked at 200 / 2,000 / 20,000 users per year. The DNS tiers and the proxy tiers are deliberately shown together, because the gap between them — roughly threefold at Cisco — is the real decision on this page.

200users · per year
  • Cisco Umbrella DNS Essentials(list ~$30–40 / user / yr)$6,0008,000 ₹4,98,000₹6,64,000
  • Cisco Umbrella SIG Advantage(list ~$95–135 / user / yr)$19,00027,000 ₹15,77,000₹22,41,000
  • Cloudflare One Gateway(published $7 / user / mo beyond 50 free)$16,800 ₹13,94,400
  • FortiSASE web filtering(list $8–18 / user / mo by tier)$19,20043,200 ₹15,93,600₹35,85,600
  • Zscaler ZIA(reported ~$6–12 / user / mo)$14,40028,800 ₹11,95,200₹23,90,400
  • Cloudflare DNS(public resolver)Quote
  • Netskope Next Gen SWG(platform-priced)Quote
  • Netskope CASB(platform-priced)Quote
  • Palo Alto CDSS(per firewall subscription)Quote
  • Cisco Secure Access(in the platform)Quote
  • Barracuda web security(per site / per user)Quote
  • Sophos web protection(in the appliance bundle)Quote
2,000users · per year
  • Cisco Umbrella DNS Essentials(list ~$30–40 / user / yr)$60,00080,000 ₹49,80,000₹66,40,000
  • Cisco Umbrella SIG Advantage(list ~$95–135 / user / yr)$1,90,0002,70,000 ₹1,57,70,000₹2,24,10,000
  • Cloudflare One Gateway(published $7 / user / mo beyond 50 free)$1,68,000 ₹1,39,44,000
  • FortiSASE web filtering(list $8–18 / user / mo by tier)$1,92,0004,32,000 ₹1,59,36,000₹3,58,56,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$1,44,0002,88,000 ₹1,19,52,000₹2,39,04,000
  • Cloudflare DNS(public resolver)Quote
  • Netskope Next Gen SWG(platform-priced)Quote
  • Netskope CASB(platform-priced)Quote
  • Palo Alto CDSS(per firewall subscription)Quote
  • Cisco Secure Access(in the platform)Quote
  • Barracuda web security(per site / per user)Quote
  • Sophos web protection(in the appliance bundle)Quote
20,000users · per year
  • Cisco Umbrella DNS Essentials(list ~$30–40 / user / yr)$6,00,0008,00,000 ₹4,98,00,000₹6,64,00,000
  • Cisco Umbrella SIG Advantage(list ~$95–135 / user / yr)$19,00,00027,00,000 ₹15,77,00,000₹22,41,00,000
  • Cloudflare One Gateway(published $7 / user / mo beyond 50 free)$16,80,000 ₹13,94,40,000
  • FortiSASE web filtering(list $8–18 / user / mo by tier)$19,20,00043,20,000 ₹15,93,60,000₹35,85,60,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$14,40,00028,80,000 ₹11,95,20,000₹23,90,40,000
  • Cloudflare DNS(public resolver)Quote
  • Netskope Next Gen SWG(platform-priced)Quote
  • Netskope CASB(platform-priced)Quote
  • Palo Alto CDSS(per firewall subscription)Quote
  • Cisco Secure Access(in the platform)Quote
  • Barracuda web security(per site / per user)Quote
  • Sophos web protection(in the appliance bundle)Quote

The certificate project — stated apart, because it is not in any licence

Every device must trust you. The inspection certificate goes to every managed laptop, phone and server — and to contractors’ machines, which you do not manage. Without it, TLS inspection either fails or throws warnings users learn to click through.
The applications that refuse. Certificate-pinning applications break under inspection by design. Every deployment carries a bypass list, and it needs an owner and a review date rather than growing quietly.
The DNS floor costs none of this. Which is the honest argument for deploying DNS filtering everywhere and proxy depth only where the data actually lives — roughly a threefold price difference at Cisco, and a project difference that is larger still.
Tier-match: DNS is not SIG. Cisco’s DNS Security Essentials and SIG Advantage differ roughly threefold and do different jobs; Cloudflare’s $7 tier is not Enterprise; Netskope and Palo Alto sell these as platform modules. Price the depth you actually need.
Term-match: per user per year or per month, billed annually. Cisco publishes annual per-user bands; Cloudflare, Fortinet and Zscaler quote monthly per user. The grid normalises to a year at published or reported rates; add-ons and premium support push enterprise deals well above list.
The India line. Cloudflare documents six Indian cities and Netskope eight data centres; the others are flagged. Quotes reach Indian buyers in INR with GST via the channel. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The certificate rollout

An inspection certificate trusted by every device, plus the bypass list for applications that pin their own. It is a device-management project with a security deadline, and it is in no licence. Your device count: [TechBag to confirm].

The exceptions and who owns them

Every unblock request, every pinned application, every business tool that broke. Small individually; the list is what the control actually is after two years.

The coverage you do not have

Devices not using your resolver, browsers with DNS-over-HTTPS, personal VPNs and unmanaged machines. Measure the fraction of egress that actually traverses the control before reporting coverage.

Before you commit

What goes wrong

Documented filtering behaviour and deployment outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the first audit.

DNS filtering bypassed by DoH, hardcoded resolvers or a VPN

The policy was deployed and a browser setting routed around it. Ask how the product detects DNS-over-HTTPS, and measure what fraction of egress actually uses your resolver.

Certificate deployment stalling the TLS rollout

Inspection was licensed, configured and never enabled because the certificate never reached the devices. It is a device-management project — plan it before the licence.

False positives blocking business apps and eroding trust

One blocked business-critical site produced an exception, then a group exemption, then a disabled policy. Pilot in monitor mode against your own top destinations.

Buying DNS filtering when the requirement was web inspection

The requirement mentioned files and data; the purchase blocked domains. DNS cannot see inside an allowed destination — that is a proxy, at roughly triple the price.

Assuming CASB means both modes

The quote was API-based and the requirement was to block uploads in real time. Inline and API are different products under one acronym.

Roaming devices left uncovered

Enforcement was network-level and half the workforce stopped coming to the office. Two products here have no roaming agent at all.

Resolver latency mistaken for a slow internet connection

Resolution ran through another continent and every page felt slower. Ask for the Indian resolver location and measure it from your own offices.

Coverage reported from licences, not from traffic

The report counted seats; the control saw a fraction of egress. Measure what actually traverses it, not what was purchased.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Network Security & SASE map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.