Overview

  • SWG builds on outbound APM to provide URL classification to:
    • Increase security with advanced threat detection
    • Increase regulatory compliance with data loss prevention
    • Enforce Corporate AUP with logs that provide forensic level details
    • Increase employee productivity when combines with single sign-on
    • Lower TCO by simplifying on-premise infrastructure
  • Licensed separately from Good/Better/Best bundles in 1/3 year options
  • SWG filtering engine has Real-Time URL classification for Policy-Based Blocking of:
    • Offensive Web Pages
    • Explicit Web Pages
    • Malware Web Pages
    • Phishing Web Pages
    • Time-Wasting Web Pages
    • 41 categories and 24 subcategories
  • SWG enhancements
    • Extended Protection
      • Newly Registered Websites
      • Elevated Exposure
      • Suspicious Content
      • Emerging Exploits

Modes of Operation

Transparent Forward Proxy


  • Browser is unaware it is communicating with a proxy. This solution can also be used with:
    • WCCP
    • GRE
    • Policy-Based Routing (PBR)
  • Works best with browser apps
  • Non-browser apps without proxy capability require extra BIG-IP configuration

    Explicit Forward Proxy

  • Typically used for network with fewer users
  • Requires less configuration
  • Requires manual browser proxy settings, or:
    • Set by Group Policy
    • Set by Proxy Auto-Config (PAC) file
    • Set by Web Proxy Auto-Discovery (WPAD)
    • Works best with browser apps
    • Non-browser apps without proxy capability may not work
    • The user can bypass browser proxy config