Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
At the DNS layer, a resolver refuses to translate a bad domain into an address — no agent, no latency, nothing in the traffic path. A proxy goes further: it terminates the connection, decrypts it, inspects the content and decides. The first costs almost nothing and sees only destinations; the second sees everything and costs a certificate on every device.
Cisco’s DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare’s resolver is free. A browser with DNS-over-HTTPS enabled routes around both, without asking anyone.
Already decided — before the quote
Still yours to weigh
Two controls at two different depths. DNS filtering intercepts the name lookup that starts almost every connection: point your resolvers at the provider, and requests for known-bad or policy-blocked domains never resolve. Nothing sits in the traffic path, there is no agent to deploy on the network, and it costs very little. A secure web gateway is a proxy: traffic is terminated, decrypted, inspected for malware and data, and allowed or blocked by content rather than by destination.
Alongside them sits CASB, which controls how cloud applications are used — and which is genuinely two products under one name. Inline CASB sits in the traffic path and can stop an upload as it happens; API CASB connects to the application out of band and scans what is already there. Most estates need both and are quoted one. When these controls are bought as part of a platform rather than on their own, that is the SASE & SSE guide.
The most common mis-purchase
Buying DNS filtering when the requirement was full web inspection. DNS blocks a domain; it cannot tell you what a user uploaded to an allowed one, scan a download, or distinguish your corporate cloud tenant from a personal one. If the requirement mentions content, data or files, the answer is a proxy.
Often confused withSASE & SSE — where these controls are bought as a platform →·Firewall & Network Security — web filtering enforced at your own edge →·Email Security — the other delivery path for the same threats →
The four routes of network security — and which one is yours →
Three enforcement depths often sold as one product, and one acronym that is genuinely two different things. Not a maturity ladder — each sees something the others cannot.
DNS filtering
Blocks at name resolution: the domain never turns into an address. No traffic path, no latency, no certificates, and it covers every device and protocol using your resolver — including things a proxy never sees. It cannot inspect content, cannot tell one page of a site from another, and is bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN. The cheapest real control there is.
Proxy / secure web gateway
Terminates the connection, decrypts TLS, inspects content, and decides on what the traffic actually contains. Sees files, uploads, form data and malware; enforces data-loss rules. Costs a certificate on every device, an exception list for applications that pin certificates, and latency in the path. Everything DNS filtering cannot do, at the price of a project.
CASB inline
In the traffic path, on the way to the cloud application. Can block an upload as it happens, coach a user in real time, and distinguish the corporate tenant of an application from a personal one. Sees only what traverses it, and only while it does — data already sitting in the application is invisible.
CASB API
Connected to the cloud application out of band, scanning what is already there: historical files, sharing permissions, external collaborators, dormant sensitive data. Finds the exposure inline inspection never saw — and can block nothing in real time. The two modes answer different questions and most estates need both.
Seven variables decide this purchase. The instrument tests what documentation establishes (enforcement layer, TLS depth, roaming coverage, CASB mode, standalone availability, India presence); bypass behaviour, false positives and the certificate project are prose because they come from a pilot and an operations plan.
DNS-layer versus full proxy inspection
Destinations or content. The single question that decides whether this is a cheap control deployed everywhere or a project with a certificate rollout.
Roaming agent versus network-level deployment
Enforcement for devices that leave the office. Sophos and Palo Alto CDSS are network- or platform-bound here; the rest document roaming coverage.
TLS inspection depth and the certificate burden
Full, selective, or none — and then the real work: an inspection certificate trusted by every device, plus an exception list for applications that pin their own.
Category coverage and false-positive rate
A block on a business-critical site erodes trust in the control faster than any threat justifies it. Pilot against your own top destinations and check the exception workflow.
CASB — inline versus API
Two different products under one acronym: blocking in flight versus finding what is at rest. Documented per product here; most estates need both.
Standalone or only inside a SASE platform
Cisco Umbrella, Cloudflare, Zscaler, FortiSASE and Barracuda sell standalone; Cisco Secure Access, Netskope, Palo Alto CDSS and Sophos require the platform or appliance underneath.
India resolver presence and latency
DNS resolution happens on every request, so resolver distance is felt constantly. Documented for Cloudflare (six cities) and Netskope (eight data centres); not established for the rest here.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where Indian resolver presence is not documented it is flagged and stays, never eliminated on an absence of evidence. Every chip is reversible.
Cloud application control
How you buy it
Where it enforces
Encrypted traffic
Where the users are
India
Estate size
Bypass behaviour, false positives and the certificate rollout are in the notes below rather than chips — they decide whether the control survives contact with users, and no datasheet covers them.

per user / month across the tiers (DNS Security Essentials roughly $30–40 per user / year, DNS Advantage $40–55, SIG Essentials $60–90, SIG Advantage $95–135); the DNS tiers are the cheapest real control on this page
Estates that want DNS-layer filtering deployed across every site in an afternoon, with an upgrade path to full proxy inspection in the same console.
The catch: The DNS tiers filter by domain and cannot inspect content — the selective proxy arrives at the SIG tiers, which is where the price roughly triples. Add-on SKUs and premium support push enterprise deployments well above the list. An Indian resolver location is not established from vendor documentation.

per user / year inside the Secure Access platform rather than standalone; the successor to Umbrella's SIG tiers with full proxy inspection, CASB and ZTNA in one subscription
Cisco estates consolidating Umbrella, VPN and web security into one cloud service under an existing enterprise agreement.
The catch: Not a standalone web filter — it arrives as a platform, which is a larger commitment than the Umbrella DNS tiers it supersedes. Indian PoP cities are not established from documentation.

the public resolver is free; policy-based DNS filtering sits inside Cloudflare Zero Trust (free to 50 users, then $7 per user / month); Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur
Estates that want DNS filtering on the largest documented Indian resolver footprint here, starting at no cost.
The catch: DNS layer only in this SKU — no content inspection, no TLS decryption, no CASB. It blocks a destination or it does not; what happens inside an allowed site is invisible.

free for up to 50 users, then $7 per user / month with no user cap; DNS, HTTP and network filtering with TLS inspection, on the same Indian PoP footprint as the resolver
Estates that want full web inspection at a published price, on documented Indian infrastructure, without an enterprise negotiation.
The catch: The $7 tier is capable and is not the Enterprise product: CASB breadth, DLP depth, browser isolation and longer log retention move up to the quoted tier. TLS inspection still means deploying a certificate to every device.

per user / month reported (roughly $72–325 per user / year by edition); a full inline proxy inspecting every session, with CASB, DLP and browser isolation as higher editions or add-ons
Estates that want every session inspected in depth rather than destinations filtered — the reference proxy, and the deepest inspection here.
The catch: A proxy, not a DNS filter: there is no cheap DNS-only tier to start on, and the base edition is the gateway with data protection arriving as editions or add-ons. Named Indian PoP cities are not established from vendor documentation.

per user / month within Netskope One; inspects by application instance — allowing the corporate tenant of a cloud application while blocking the personal one — with eight Indian data centres on NewEdge
Estates whose control requirement is per application instance rather than per domain, which domain-level filtering cannot express at all.
The catch: Sold as part of the Netskope One platform rather than as a standalone filter, so a like-for-like comparison against Umbrella's DNS tiers is not meaningful. It is more product than a DNS-only requirement needs.

per user / month within Netskope One; both inline (in the traffic path, able to block in real time) and API-based (out of band, scanning what is already in the cloud application) — the two modes are different products in practice
Estates that need both to control cloud application use: inline to stop an upload as it happens, API to find what was uploaded last year.
The catch: Inline and API modes solve different problems and are frequently confused — API alone cannot block anything in real time, inline alone cannot see historical data at rest. Platform-priced, not standalone.

per-firewall subscriptions layered on a Strata NGFW or Prisma Access — Advanced URL Filtering and DNS Security are separate CDSS SKUs, enforced wherever that platform enforces
Palo Alto estates that want web and DNS controls inside the policy engine already running, rather than a second console.
The catch: Not a standalone product: it requires the firewall or Prisma Access underneath, and roaming coverage comes from Prisma Access rather than a lightweight DNS agent. Each service is its own subscription line.

per user / month list by bundle tier; web filtering and DNS filtering for off-network users using the same FortiGuard categories as the FortiGate estate, with Security Fabric pricing for existing customers
FortiGate estates extending the web filtering they already run on-premises to users who never come back to the office.
The catch: The categories and console are familiar, which is the point; as a standalone web filter for a non-Fortinet estate it is a less obvious purchase. Indian PoP cities are not established from vendor documentation.

web security inside SecureEdge, licensed per site for the network side and per user for the access side; content filtering and TLS inspection for distributed sites without an enterprise project
Distributed mid-market estates — many small sites — that want web filtering and firewalling from one platform and one bill.
The catch: No CASB capability documented, so cloud application control is outside its scope; documented deployments are mid-market and an Indian resolver location is not established. The split per-site and per-user meter makes comparison awkward.

web protection inside the Standard or Xstream Protection bundle on an XGS appliance; TLS inspection is an Xstream capability, and enforcement happens at your edge rather than in a cloud PoP
Estates whose users are mostly in the office and who want web filtering enforced by the firewall already inspecting their traffic.
The catch: On-network enforcement only — there is no roaming agent here, so devices off the network are unprotected unless you also run a cloud service. It is the appliance answer to a question the rest of this page answers from the cloud.
Inline CASBRules out Cisco Umbrella — API-based CASB only; it scans what is already in the cloud application and cannot block in real time; Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Barracuda Network Protection (web security) and Sophos Firewall (web protection) — no CASB capability documented. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Fortinet FortiSASE (web filtering).
API CASBRules out Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Barracuda Network Protection (web security) and Sophos Firewall (web protection) — no CASB capability documented; Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Fortinet FortiSASE (web filtering) — inline CASB only; it controls traffic in flight and cannot scan data already at rest. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG and Netskope CASB.
Buyable standaloneRules out Cisco Secure Access (web), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Sophos Firewall (web protection) — sold inside the vendor's wider platform or on its firewall, not as a standalone web filter. That leaves Cisco Umbrella, Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security).
A DNS-layer tierRules out Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB and Sophos Firewall (web protection) — a full proxy with no DNS-layer tier to start on. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security).
Full proxy inspectionRules out Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — DNS layer only; it blocks a destination and cannot see inside an allowed one. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security) and Sophos Firewall (web protection).
Full TLS inspectionRules out Cisco Umbrella — selective TLS inspection at the higher tiers rather than full inspection throughout; Cloudflare DNS (1.1.1.1 for Families · Gateway DNS) — no TLS inspection; encrypted content is not visible at all. That leaves Cisco Secure Access (web), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security), Fortinet FortiSASE (web filtering), Barracuda Network Protection (web security) and Sophos Firewall (web protection).
Off-network coverageRules out Palo Alto Cloud-Delivered Security Services (URL Filtering, DNS Security) and Sophos Firewall (web protection) — enforcement happens on your network only; devices elsewhere are uncovered without a second product. That leaves Cisco Umbrella, Cisco Secure Access (web), Cloudflare DNS (1.1.1.1 for Families · Gateway DNS), Cloudflare One — Gateway (web), Zscaler Internet Access (ZIA), Netskope Next Gen SWG, Netskope CASB, Fortinet FortiSASE (web filtering) and Barracuda Network Protection (web security).
Indian resolver presenceRules nothing out on published terms. It flags Cisco Umbrella — Indian resolver or PoP location not established from vendor documentation, Cisco Secure Access (web) — Indian resolver or PoP location not established from vendor documentation, Zscaler Internet Access (ZIA) — Indian resolver or PoP location not established from vendor documentation, Fortinet FortiSASE (web filtering) — Indian resolver or PoP location not established from vendor documentation, Barracuda Network Protection (web security) — Indian resolver or PoP location not established from vendor documentation and Sophos Firewall (web protection) — Indian resolver or PoP location not established from vendor documentation — marked on the cards, not removed.
Above 5,000 filtered usersRules nothing out on published terms. It flags Barracuda Network Protection (web security) — Documented deployments stop short of this size and Sophos Firewall (web protection) — Documented deployments stop short of this size — marked on the cards, not removed.
Both facts about DNS filtering are true at onceIt is the cheapest security control you can deploy — Cisco's DNS Security Essentials runs roughly $30–40 per user per year and Cloudflare's resolver is free — and it is the easiest to bypass. DNS-over-HTTPS in a browser, a hardcoded public resolver, a personal VPN, or an application that ignores the system resolver all route around it. That does not make it worthless: it stops a large share of commodity threats at almost no cost and no latency. It makes it a floor rather than a ceiling, and anyone selling it as complete web security is selling you the floor.
TLS inspection is a certificate project before it is a security controlMost traffic is encrypted, so inspecting content means decrypting it, which means your inspection certificate must be trusted by every device — managed laptops, phones, contractors' machines, and the applications that pin their own certificates and will simply break. Full TLS inspection is documented at Cloudflare One, Zscaler, Netskope, Palo Alto CDSS, FortiSASE, Barracuda and Sophos; Cisco Umbrella's DNS tiers are selective at the proxy tiers, and Cloudflare's DNS-only SKU does none. Plan the certificate rollout and the exception list before the licence, not after.
Inline CASB and API CASB are different products wearing one nameInline sits in the traffic path and can stop an upload as it happens; it sees only what traverses it, and only while it traverses. API-based CASB connects to the cloud application out of band and scans what is already there — historical files, sharing permissions, dormant data — and cannot block anything in real time. Netskope and Cloudflare document both; Cisco Umbrella is API-based; Palo Alto CDSS and FortiSASE are inline; Barracuda and Sophos document none. Estates usually need both, and are usually quoted one.
False positives are how the control diesA category engine that blocks a business application erodes trust fast: the exception list grows, then someone disables the policy for a group, then for everyone. Ask for the exception workflow and who can approve one, and pilot against your own top fifty destinations rather than a vendor's test list. Measured false-positive behaviour on Indian business sites is delivery-team knowledge: [TechBag to confirm].
Under 200 usersPublished pricing excludes nobody at this size: Cloudflare is free to 50 users and $7 beyond, Cisco Umbrella's DNS tiers start around $2.25 per user per month, and Fortinet's band starts at 50 users. The platform-bundled options (Cisco Secure Access, Netskope, Palo Alto CDSS) publish no standalone floor. Current published minimums, by vendor: [TechBag to confirm].
Each shortlist states whether the answer is the DNS floor or proxy depth, and what it costs to deploy. If the requirement mentions content or data, start from the second row.
Why: DNS filtering needs a resolver change and nothing else — Cloudflare's is free to start and documents six Indian cities; Cisco's DNS tiers run roughly $30–40 per user per year.
The trade-off: It blocks destinations and cannot see inside an allowed one, and DNS-over-HTTPS or a personal VPN routes around it. A floor, deliberately chosen, is a legitimate answer — an assumed ceiling is not.
Why: Content inspection, malware scanning and data controls need a proxy in the path with TLS decryption — Zscaler is the depth reference, Cloudflare publishes a price, Netskope adds application-instance awareness.
The trade-off: All three mean a certificate on every device and an exception list for applications that pin certificates. Budget the rollout as a project, not a setting.
Why: Instance awareness is the capability domain-level filtering cannot express at all: same domain, different tenant, different verdict.
The trade-off: It requires inline inspection and a platform-priced product — this is more capability than a DNS-only requirement needs, and the quote reflects that.
Why: API-based CASB connects out of band and scans historical data, sharing permissions and dormant files — the half inline inspection cannot see.
The trade-off: API CASB blocks nothing in real time. Estates usually need both modes; Netskope and Cloudflare document both, Cisco Umbrella is API-based.
Why: Web filtering enforced by the appliance already inspecting the traffic avoids a second console and a second subscription entirely.
The trade-off: Sophos and Palo Alto CDSS have no lightweight roaming agent here — devices off the network are uncovered without a cloud service, which is the whole reason the rest of this page exists.
Why: The same categories, the same policy engine and the same console extended to roaming users — Fortinet gives existing FortiGate customers Security Fabric pricing.
The trade-off: Familiarity is worth real money in operations and deepens single-vendor commitment. Neither Fortinet nor Cisco documents Indian PoP cities here.
Why: Cloudflare documents six Indian cities and Netskope eight Indian data centres — resolution and inspection latency is felt on every request, not just at connection time.
The trade-off: Cisco, Zscaler, Fortinet, Barracuda and Sophos do not document Indian resolver locations on this guide — flagged, not ruled out. Ask for the location and test it.
Why: Barracuda licenses web security inside SecureEdge per site and per user; Umbrella deploys per site by resolver change; Cloudflare covers roaming users at a published price.
The trade-off: Barracuda documents no CASB, so cloud application control needs another product. Normalise the split per-site and per-user meter before comparing.
Each depth sees something the one above it misses, and costs more to deploy. Place your actual requirement on this ladder before reading a price.
Depth 1
DNS resolution
The domain never resolves. Covers every device and protocol using your resolver, costs almost nothing, adds no latency — and sees no content at all. Bypassed by DNS-over-HTTPS, a hardcoded resolver or a personal VPN.
Depth 2
Proxy with TLS inspection
The connection is terminated, decrypted and inspected: files, uploads, malware, data-loss rules. Everything depth one cannot do — at the cost of a certificate on every device and an exception list for pinned applications.
Depth 3
Application-instance awareness
Same domain, different tenant, different verdict: allow the corporate instance of a cloud application and block the personal one. Domain-level filtering cannot express this at all.
The other axis
API CASB — data at rest
Not deeper inspection but a different vantage point: connected out of band to the cloud application, scanning historical files, sharing permissions and dormant data that never traversed your proxy.
The bypass test
Ask these before the pilot, in this order.
The India layer
Resolution latency is felt on every single request.
Web and DNS controls scale by devices covered and by exceptions accumulated. The bill follows the per-user tier; the credibility follows the false-positive rate.
Deployment speed is the constraint
Put this in your PoC
Turn on DNS filtering, then check how many devices actually use your resolver. The gap is the real coverage number.
TLS and false positives are the constraints
Put this in your PoC
Run the proxy in monitor mode for two weeks and count what it would have blocked. The false positives in that list are your rollout risk.
Coverage gaps and residency are the constraints
Put this in your PoC
Measure what fraction of egress actually traverses the control. If nobody knows, the coverage number is aspirational.
Cisco, Cloudflare, Zscaler, Netskope, Palo Alto and Fortinet document large estates; Barracuda Network Protection and Sophos Firewall web protection are flagged unverified above 5,000 users. Where a specific filter strains for your traffic mix: [TechBag to confirm].
The category lists, the exception list and the trust chain are all per platform. Moving means rebuilding the policy and re-trusting every device, while the old control still carries production traffic.
The category policy
Years of accumulated allow and block decisions, many with no recorded reason. Category names differ between vendors, so it is a translation rather than an export.
The certificate
A new inspection certificate trusted by every device before the switch, and the old one removed afterwards — or inspection silently fails for someone.
The exception list
Applications that pin certificates, sites that break under inspection, and the business tools someone got unblocked in 2023. All of it re-tested.
The overlap
Both controls run while users and sites cut over. Two subscriptions for a quarter is cheaper than one week of blocked business traffic.
Policy translation, certificate rollout and exception re-testing for your estate: [TechBag to confirm] — TechBag scopes it from your policy size and device inventory.
What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the licence leaves out — which, for web security, is the certificate project and the exceptions.
Four places this filtering may already exist. Three of them genuinely do.
If the filtering you need is already inside something you renew, we say so. It costs us a sale and saves you one.
Published and reported per-user meters (INR for scale), worked at 200 / 2,000 / 20,000 users per year. The DNS tiers and the proxy tiers are deliberately shown together, because the gap between them — roughly threefold at Cisco — is the real decision on this page.
The certificate project — stated apart, because it is not in any licence
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
An inspection certificate trusted by every device, plus the bypass list for applications that pin their own. It is a device-management project with a security deadline, and it is in no licence. Your device count: [TechBag to confirm].
Every unblock request, every pinned application, every business tool that broke. Small individually; the list is what the control actually is after two years.
Devices not using your resolver, browsers with DNS-over-HTTPS, personal VPNs and unmanaged machines. Measure the fraction of egress that actually traverses the control before reporting coverage.
Documented filtering behaviour and deployment outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the first audit.
DNS filtering bypassed by DoH, hardcoded resolvers or a VPN
The policy was deployed and a browser setting routed around it. Ask how the product detects DNS-over-HTTPS, and measure what fraction of egress actually uses your resolver.
Certificate deployment stalling the TLS rollout
Inspection was licensed, configured and never enabled because the certificate never reached the devices. It is a device-management project — plan it before the licence.
False positives blocking business apps and eroding trust
One blocked business-critical site produced an exception, then a group exemption, then a disabled policy. Pilot in monitor mode against your own top destinations.
Buying DNS filtering when the requirement was web inspection
The requirement mentioned files and data; the purchase blocked domains. DNS cannot see inside an allowed destination — that is a proxy, at roughly triple the price.
Assuming CASB means both modes
The quote was API-based and the requirement was to block uploads in real time. Inline and API are different products under one acronym.
Roaming devices left uncovered
Enforcement was network-level and half the workforce stopped coming to the office. Two products here have no roaming agent at all.
Resolver latency mistaken for a slow internet connection
Resolution ran through another continent and every page felt slower. Ask for the Indian resolver location and measure it from your own offices.
Coverage reported from licences, not from traffic
The report counted seats; the control saw a fraction of egress. Measure what actually traverses it, not what was purchased.
Vendor-neutral. No gated content.