Your proxies live in the data centre; your users don’t. Web policy should travel with them — Symantec Cloud SWG decrypts and inspects web traffic in Broadcom’s cloud PoPs, Delhi and Mumbai among them, isolates high-risk sites, and shares one per-user Web Protection Suite licence with Edge SWG on site.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Symantec Cloud SWG — the cloud proxy formerly called WSS, usually bought in the Web Protection Suite. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy in the cloud sits between users and the internet, opening encrypted sessions to check each page and file.
What consolidation actually replaces, dimension by dimension.
| Dimension | A head-office proxy rack | Symantec Cloud SWG |
|---|---|---|
| Inspection point | A proxy rack at head office | A Cloud SWG PoP, or Edge SWG on site |
| Remote laptops | Filtered only while the VPN is up | The SES agent tunnels them to the cloud |
| Uncategorised sites | A blanket block and a helpdesk ticket | Opened in High Risk Isolation |
| HTTPS content | Passed through unread | Decrypted and inspected in the PoP |
| Web log history | Whatever the appliance disk holds | 100 days, or 365 with Hosted Reporting |
| What it is NOT | — | API CASB, ZTNA or DLP without add-ons |
The cheapest test is a single branch: tunnel it to the Mumbai or Delhi PoP, move ten laptops to the SES agent, and read a week of reports.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Offices send traffic over IPsec or explicit proxy over IPsec, or forward it from a proxy they already run; laptops use the SES or SEP agent’s Web and Cloud Access Protection.
The proxy terminates and decrypts SSL/TLS, rates the URL with Intelligence Services, applies Application Visibility & Control and runs Deep File Inspection on downloads.
Broadcom runs the service on a Google Cloud backbone; KB 167174 names 94 locations, compute PoPs and localisation zones, with Delhi and Mumbai as Indian compute PoPs.
Under a Web Protection Suite licence the same users can sit behind an on-site Edge SWG, managed centrally with the cloud, which can upload its logs for 365-day Hosted Reporting.
Tunnels and the SES agent into Delhi, Mumbai and global PoPs — with Edge SWG on site under the same per-user licence.
Symantec Cloud SWG inspects every web request in a cloud PoP, and one user licence also covers gateways on site.
Office firewalls and routers build IPsec tunnels to a Cloud SWG PoP, or use explicit proxy over IPsec where PAC files already exist.
SES and SEP carry Web and Cloud Access Protection, which Broadcom says matches the WSS Agent’s features on Windows and macOS.
Cloud SWG Premium Routing gives dedicated egress IPs, so SaaS tenants and partner sites can allow-list your web traffic by address.
The proxy terminates and decrypts SSL/TLS, so category, application and file rules act on what is inside HTTPS, minus exemptions you set.
Deep File Inspection scans downloads before they reach the user; Cloud Sandboxing for unknown files is sold as a separate add-on.
Application Visibility & Control names the cloud apps and actions inside web traffic; more granular CASB controls are an add-on.
High Risk Isolation, part of Cloud SWG, opens risky or uncategorised sites in a remote browser; Full Browser Isolation costs extra.
Cloud Firewall Service, available with Cloud SWG, applies rules to traffic on any TCP or UDP port, not only HTTP and HTTPS.
Standard reporting holds 100 days; the Hosted Reporting licence holds 365 days with no size cap, for cloud and Edge SWG logs alike.
Admin access moving to Enterprise Console (2026), plus three 2022 demos: first policy, SSL decryption and High Risk Isolation. All from the official Symantec channel.
How administrator access to Cloud SWG moves into Broadcom’s new Enterprise Console experience.
A 2022 demo of switching on SSL decryption so that policy can see inside encrypted sessions.
A 2022 demo of routing risky and uncategorised sites to remote isolation through a policy rule.
A 2022 walkthrough of the first policy a new Cloud SWG tenant needs before users are moved over.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Broadcom sells the Web Protection Suite as a fixed cost per user per year, and that one licence runs Cloud SWG or Edge SWG for the same people. Roaming staff use the cloud proxy while head office keeps an on-site gateway under central management. Hardware has been priced apart from software since 2021.
Cloud SWG itself carries SSL/TLS decryption, Deep File Inspection, Intelligence Services ratings, Application Visibility & Control and High Risk Isolation for risky or uncategorised sites. What sits on top is listed plainly: Cloud Sandboxing, Full Browser Isolation, ZTNA, finer CASB controls and DLP.
Broadcom KB 167174 lists Delhi and Mumbai as compute PoPs, each a dedicated-IP and policy-based-routing site. Standard reporting keeps logs 100 days, short of CERT-In’s 180; the Hosted Reporting licence keeps 365 days with no size limit. Ask the partner to state in writing where logs are stored.
There is no public price. Gartner placed Broadcom a Niche Player in its 2025 SSE Magic Quadrant. API scanning of SaaS data needs CloudSOC, a separate purchase. The WSS Agent is end-of-line, so roaming laptops move to the SES agent, and admin access is shifting to a new Enterprise Console during 2026.
List users, offices and any ProxySG or Edge SWG boxes, and confirm whether one WPS user licence should cover both.
Pick 100-day standard reporting or Hosted Reporting for 365 days, and list which SSE add-ons, if any, you really need.
Build an IPsec tunnel from one branch firewall, push the root certificate, and confirm whether Delhi or Mumbai serves it.
Turn on Web and Cloud Access Protection in the SES or SEP agent, then retire WSS Agent installs on Windows and Macs.
Move administrators to Enterprise Console, enable High Risk Isolation, and bring any on-site Edge SWG under one view.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our Edge SWG boxes stayed at the Pune plant while the sales team moved to Cloud SWG on the same WPS user count.”
“North India users land on the Delhi PoP now, and the latency complaints from backhauled VPN browsing stopped.”
“Our auditor asked about log history first. 100 days would not have met CERT-In, so Hosted Reporting went on the order.”
“Newly registered domains open in High Risk Isolation now, instead of becoming another unblock ticket for my team.”
“Moving laptops off the WSS Agent onto SES Web and Cloud Access Protection took us a quarter. Start that early.”
“The proxy is solid, but the old portal felt dated and a price took two partner calls. The new console should help.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Niche Player in Gartner’s 2025 SSE MQ; KuppingerCole Zero Trust leader, 2026.
The grid nobody publishes — how many places the gateway can enforce, Indian PoPs included, vs how deeply it inspects each request.
Cloud plus Edge SWG on one licence; Delhi and Mumbai PoPs; isolation included.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Internet Access, Netskope Next Gen SWG, Skyhigh Secure Web Gateway, Palo Alto Prisma Access and Cisco Umbrella — on deployment, steering, roaming, inspection, isolation, CASB, price, India PoPs, logs and analyst standing.
| Dimension | Symantec Cloud SWG | Zscaler Internet Access | Netskope Next Gen SWG | Skyhigh Secure Web Gateway | Palo Alto Prisma Access | Cisco Umbrella |
|---|---|---|---|---|---|---|
| What it is | Cloud proxy, ex-WSS | Zero Trust Exchange SWG | Netskope One gateway | Cloud SWG, hybrid rights | Cloud-delivered SSE | DNS layer, then SIG |
| Deployment options | Cloud, Edge SWG on site | Cloud only | NewEdge cloud | Cloud plus appliances | Cloud; NGFW on site | Cloud data centres |
| How traffic arrives | IPsec, proxy, agent | GRE, IPsec, connector | Client and GRE/IPsec | Tunnels picked by GRM | IPsec and GlobalProtect | DNS, client, SD-WAN |
| Roaming devices | SES agent; WSS Agent EOL | Client Connector | Netskope Client | No Linux client | GlobalProtect agent | Roaming client, DNS |
| Inspection and threats | TLS, DFI, Intelligence | Full TLS; sandbox tiers | Inline TLS, own engine | SSL + GAM emulation | TLS, WildFire verdicts | Domains; proxy in SIG |
| Browser isolation | Risky sites included | Higher edition or add-on | Platform module | Risky-web RBI in Adv. | Own licence | Via Secure Access |
| CASB and DLP | Inline AVC; CASB extra | Inline and API, by tier | CASB heritage | DLP in; CASB at SSE | SaaS Security add-on | API CASB with SIG |
| Pricing model | Per user per year (WPS) | Per user, editions | Inside Netskope One | Per user via partners | Users plus bandwidth | Per user, by tier |
| Published entry price | UK reseller: £56.25 | ~$6–12/user/mo reported | Not published | Not published | Quote only | $2.25–6.50/user/mo |
| Included vs add-on | Isolation in; ZTNA extra | Climbs by edition | Separate modules | DLP and GAM in | DNS Security in | Proxy needs SIG |
| India PoPs | Delhi and Mumbai | Four Indian cities | Eight Indian DCs | Bangalore, Noida, Mumbai | Four Indian locations | Mumbai and Chennai |
| Log retention | 100 days; 365 paid | 180 days | Confirm in contract | 100 days; 365 add-on | Not verified | Not verified |
| Analyst standing | SSE 2025: Niche | SSE 2025: Leader | SSE 2025: Leader | SSE 2025: Niche | SSE 2025: Leader | Not recorded here |
| Best fit | WPS and SEP estates | Deepest cloud inspection | Per-instance SaaS rules | Hybrid with India logs | Palo Alto firewall shops | DNS-first, fast rollout |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Symantec Cloud SWG is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the gateway; security staff-hour cost). Estimates model the hours spent on proxy upkeep, unblock requests and web-borne infections at an assumed 1.5 hours per user a year, with 70% of that removed by cloud inspection and isolation. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Broadcom publishes no list price for Cloud SWG; buyers go through partners, in India through Westcon-Comstor’s channel. Most estates license it inside the Web Protection Suite, a fixed cost per user per year that also covers Edge SWG on site, with appliance hardware bought separately. The only public figure is a UK G-Cloud reseller’s MSRP of £56.25 per user a year for the suite. ZTNA, Full Browser Isolation, finer CASB, DLP, Cloud Sandboxing and Hosted Reporting are extra. TechBag counts your users and sites, then quotes in INR with GST.
Best for cloud-only web inspection
Best for a broader rollout
Best for estates with on-site proxies too
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are you buying Cloud SWG alone, or the Web Protection Suite, which also covers Edge SWG on site for the same users?
Will existing Edge SWG appliances stay? Hardware is priced apart from WPS, and SGOS 7.3 support ends around December 2026.
Do you need ZTNA, Full Browser Isolation, finer CASB, DLP or Cloud Sandboxing? Each is an add-on to Cloud SWG.
Must SaaS data at rest be scanned? That is CloudSOC, sold in the DLP Cloud bundle, not part of Cloud SWG.
Is 100 days of logs enough, or does CERT-In’s 180-day rule mean licensing Hosted Reporting for 365 days?
Are laptops still on the WSS Agent? Plan the move to the SES or SEP agent’s Web and Cloud Access Protection.
Will offices tunnel to Delhi or Mumbai, and do you need dedicated egress IPs through Premium Routing?
Does the partner quote name the SKUs, user count, add-ons and term, in INR with GST, via the Westcon-Comstor channel?
Count your users, branches and any ProxySG or Edge SWG boxes first, or let a TechBag advisor choose between Cloud SWG and the full suite and itemise the quote in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.