Your web traffic is filtered, but RDP, SSH and file transfers leave laptops unchecked. The rest of the traffic needs rules too — Skyhigh Cloud Firewall carries non-web traffic from laptops and branches to a Skyhigh PoP, inspects it and applies rules on ports, processes, countries and named protocols, beside Skyhigh’s web gateway.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh Cloud Firewall — the SSEFW firewall-as-a-service add-on. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A firewall run in the provider’s PoP that applies port, protocol and application rules to traffic wherever the user is.
What consolidation actually replaces, dimension by dimension.
| Dimension | VPN backhaul and branch firewalls | Skyhigh Cloud Firewall |
|---|---|---|
| Where non-web rules live | On a branch box, or nowhere for home users | In the PoP, applied wherever the user is |
| How remote traffic gets there | VPN backhaul to head office | WireGuard from the agent, or IPsec from the site |
| What a rule can name | IP address and port | Process, user, country, service or protocol |
| Web and non-web | Separate proxy and firewall consoles | One SSE console, with a hand-off to the gateway |
| Visibility for home users | None once they leave the VPN | Dashboard of protocols, processes and blocked IPs |
| What it is NOT | — | A data-centre firewall, an IPS, or a published price |
The cheapest test is a pilot: redirect one group through Cloud Firewall on default allow, read the 7-day dashboard, then write your rules.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The same agent that steers web traffic to the gateway encrypts other flows and sends them to Cloud Firewall over a WireGuard tunnel, from Windows or macOS endpoints.
Since July 2026 an IPsec-capable router or firewall can forward all IP traffic, web and non-web, to the nearest Skyhigh PoP, covering printers and IoT that take no agent.
Headers are read first; web flows are passed to the gateway after the first packet, while non-web flows get deep packet inspection of every packet before they leave.
Ordered rules match on IPs, ports, process, user, country or detected protocol; the first match wins, and anything unmatched is allowed unless you add a final block rule.
One agent or an IPsec tunnel into the PoP — non-web flows inspected packet by packet, web flows handed to the gateway.
Skyhigh Cloud Firewall applies firewall rules to non-web traffic in the cloud, wherever the user is.
The Client Proxy wraps non-web flows in a WireGuard tunnel to Cloud Firewall, so roaming users get the same rules as office users.
A branch router sends DNS, FTP, SSH and other traffic down an IPsec tunnel, so devices that cannot run an agent are still covered.
Where there is no direct internet route, an on-prem Skyhigh gateway can act as a SOCKS relay that carries tunnelled traffic to the cloud.
Non-web traffic is inspected packet by packet; web flows are identified on the first packet and handed to the gateway for content checks.
Rules can name a detected protocol rather than a port, from DNS, SMB and LDAP to QUIC, RDP, SIP and Gnutella, whatever port it uses.
Eleven default cards show traffic by protocol, top blocked client and destination IPs, top processes and top apps, for the last 7 days.
On Windows a rule can target a process such as zoom.exe or teams.exe, with its path and signer, not just the port it happens to use.
Source Country and Destination Country criteria let you drop traffic to or from places where you have no staff, offices or customers.
The Allow with Web Policy action passes a permitted flow on to the gateway’s rules, so one decision covers the port and the payload.
Skyhigh’s own 2023 demo of the Cloud Firewall console — the only official video for this product.
A 2023 walk-through of the console; IPsec site tunnels and the newer default rules arrived after it was filmed.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Laptops already running the Skyhigh Client Proxy for the web gateway need nothing new: the same client tunnels non-web flows over WireGuard to Cloud Firewall. Web traffic that reaches the firewall is identified on its first packet and passed to the gateway, so the two services share a policy console rather than splitting a user across two vendors.
A rule can match a Windows process with its path and signer, a service from Skyhigh’s Cloud Registry, a user group or a source or destination country, as well as IPs, ports and 38 detected protocols. That lets you allow Teams media while dropping RDP to the internet, or refuse any flow towards countries where you have nobody.
Skyhigh is one of few vendors that still sells an on-prem web gateway beside its cloud. Here that matters: an on-prem gateway can relay tunnelled firewall traffic as a SOCKS proxy where there is no direct route out, and a July 2026 IPsec option lets branch routers send all traffic with no endpoint agent at all.
There is no price list and no firewall-specific analyst coverage, and only one official video, from 2023. The docs describe rules and deep packet inspection but no intrusion-prevention engine. It is outbound control, not a data-centre firewall. Unmatched traffic is allowed by default, macOS supports fewer rule criteria, and no Linux client is documented.
Inventory what leaves laptops and branches besides web: DNS, RDP, SSH, SIP, file shares, and the processes behind each.
Check whether your SKU is Cloud SWG or an SSE suite, price SSEFW as an add-on, and compare it with SSE Complete.
Turn on firewall redirection in the Client Proxy for a pilot group, keep default allow, and watch the 7-day dashboard.
Add process, country and protocol rules from what the pilot showed, then enable the final deny rule for the group.
Bring agentless branch devices in over IPsec, test macOS rules separately, and extend redirection to every user.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We already pushed the Client Proxy for web filtering, so adding the firewall was a policy change, not another agent rollout.”
“Process rules sorted our softphone problem: we allow the dialler binary on SIP and drop SIP from everything else.”
“Destination-country blocking took ten minutes and cut the noise from odd outbound connections on field laptops.”
“The IPsec option let us cover plant-floor devices that will never take an agent. Test the tunnel failover first.”
“Remember the default is allow. We ran for a week before switching on the final deny rule, and found plenty first.”
“Our Mac users get a thinner rule set than Windows, and we wanted IPS signatures on this traffic too.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the firewall-as-a-service market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Add-on below SSE Complete; quoted per user.
The grid nobody publishes — how deeply non-web traffic is inspected vs how many ways traffic can reach the firewall.
Agent, IPsec sites and on-prem SOCKS relay; no IPS documented.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Zero Trust Firewall, Netskope One Cloud Firewall, Palo Alto Prisma Access, Fortinet FortiSASE and Cisco Secure Access — on on-ramps, inspection, rules, price and India.
| Dimension | Skyhigh Cloud Firewall | Zscaler Zero Trust Firewall | Netskope One Cloud Firewall | Palo Alto Prisma Access | Fortinet FortiSASE | Cisco Secure Access |
|---|---|---|---|---|---|---|
| What it is | FWaaS inside Skyhigh SSE | Firewall within ZIA | FWaaS on Netskope One | NGFW stack as a service | FortiOS firewall in SASE | Cloud firewall in SSE |
| How traffic arrives | WireGuard agent, IPsec | Agent or site tunnels | Client, GRE or IPsec | Users plus remote sites | FortiClient agent | Client or network tunnel |
| Protocol coverage | 38 named protocols | All ports and protocols | All ports, FTP gateway | App-ID on every port | FortiGuard app control | L7 only in Advantage |
| Threat inspection | DPI, no IPS documented | IPS in Advanced | Optional IPS | Threat Prevention | IPS in Standard tier | IPS in Advantage |
| Rule criteria | Process, country, user | 10 rules in Standard | 5-tuple plus identity | App, user, zone | FortiOS policy model | Depth by package |
| Pricing model | Per user, via partners | Per user, by edition | Per user, by bundle | Per user or per Mbps | Per user, user bands | Per user, 50 minimum |
| Published entry price | Not published | ~$6–12/user/month | ~$15+/user/month | Quote only | Quote; UK list £78–304 | Tiered, not listed |
| Included vs add-on | Add-on below Complete | Depth is Advanced | IPS is optional | In Enterprise edition | In the subscription | L7 and IPS cost more |
| Endpoint clients | Windows and macOS | Client Connector | Netskope client | GlobalProtect agent | FortiClient | Cisco Secure Client |
| Hybrid and on-prem fit | SOCKS relay via SWG | Cloud only | Cloud only | Same policy as NGFW | FortiGate continuity | Cisco firewall estates |
| India presence | Bangalore, Noida, Mumbai | Four Indian cities | Eight Indian DCs | Four Indian locations | Not documented | Not documented |
| Analyst standing (SSE) | Niche Player 2025 | Top quadrant, 2025 | Top quadrant, 2025 | Top quadrant, 2025 | Challenger, 2025 | Not checked here |
| Lock-in and exit | Needs Skyhigh’s client | Platform commitment | Platform commitment | Deepens PAN estate | Deepens Fabric tie | Fits a Cisco EA |
| Best fit | Skyhigh SWG estates | ZIA customers | Data-first SSE buyers | Palo Alto firewall shops | FortiGate estates | Cisco and Umbrella users |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no firewall-as-a-service guide yet, so Skyhigh Cloud Firewall sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (users whose non-web traffic is covered; engineer-hour cost). Estimates model IT time spent on VPN backhaul issues, per-site firewall rule changes and chasing unexplained outbound connections at an assumed 1.5 hours per user a year, with 70% of it removed by one cloud rule set. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Skyhigh prints no price for Cloud Firewall (SKU SSEFW) or any other product, and sells only through partners, per user per year. It is an add-on to Cloud SWG, Cloud SWG Advanced and the SSE Essential and Advanced suites, and is included in SSE Complete. TechBag compares the add-on against SSE Complete for your licence mix, then quotes in INR with GST.
Best for Skyhigh SWG or SSE Essential/Advanced estates
Best for a broader rollout
Best when you also need Private Access
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is Cloud Firewall in your quote? It is an add-on to Cloud SWG and the Essential and Advanced suites.
Do you need intrusion prevention on non-web traffic? Skyhigh’s firewall docs do not describe an IPS engine.
Have you planned the final deny rule? Cloud Firewall allows unmatched traffic until you add one.
Are all users on Windows or macOS? macOS supports fewer criteria, and no Linux client is documented.
Is every laptop on Client Proxy 4.9.0 or later? 4.8.x reached end of life on 1 May 2026.
Can branch routers build IPsec to a Skyhigh PoP for devices that will never take an agent?
Which PoP will Indian users reach — Bangalore, Noida or Mumbai — and is India set as the log location?
TechBag does not yet have a firewall-as-a-service guide; compare at least two of the alternatives on this page.
Map the non-web traffic leaving your laptops and branches first, or let a TechBag advisor scope a pilot on one user group.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.