Talk to us
by Skyhigh SecurityTechBag Intel Page

Skyhigh Cloud Firewall

Your web traffic is filtered, but RDP, SSH and file transfers leave laptops unchecked. The rest of the traffic needs rules too — Skyhigh Cloud Firewall carries non-web traffic from laptops and branches to a Skyhigh PoP, inspects it and applies rules on ports, processes, countries and named protocols, beside Skyhigh’s web gateway.

Firewall rules for non-web trafficClient Proxy or IPsec on-rampQuote-only pricing

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price for SSEFW; partners quote it per user, and SSE Complete bundles it
Quote
Protocols
Detected-protocol list in Skyhigh’s policy docs, from DNS and SMB to QUIC, RDP and SIP
38 named
Analysts
Skyhigh as a company in Gartner’s 2025 SSE Magic Quadrant; no firewall-specific placement
Niche Player
India
Firewall traffic from Indian users can be inspected in Bangalore, Noida or Mumbai, per the October 2026 status page
3 PoP cities

Quick answer

Skyhigh Cloud Firewall is the firewall-as-a-service inside Skyhigh’s SSE. The Client Proxy on Windows or macOS, or an IPsec tunnel from a branch, carries non-web traffic to a Skyhigh PoP for deep packet inspection and rules on ports, processes, countries and 38 named protocols; web traffic is handed to the gateway. It is an add-on except in SSE Complete, quoted per user through partners, with Indian PoPs in Bangalore, Noida and Mumbai. Read more ↓ Show less ↑
Part 01 · Orient

The Skyhigh Security platform family

This page covers Skyhigh Cloud Firewall — the SSEFW firewall-as-a-service add-on. The rest:

Quick facts

30-second orientation
Product
Cloud-delivered firewall for outbound non-web traffic, run in the same PoPs as Skyhigh’s web gateway
Maker
Skyhigh Security, owned by Symphony Technology Group; legal entity Musarubra US LLC; CEO Vishal Rao
SKU
SSEFW — an add-on to Cloud SWG and the Essential and Advanced suites; included in SSE Complete
Price
Not published; quoted per user per year through partners, as all Skyhigh licences are
On-ramps
Skyhigh Client Proxy over a WireGuard tunnel, or IPsec tunnels from a branch edge device with no agent
Rules
IPs, ports, process names, users, groups, countries, Cloud Registry services and 38 detected protocols
Actions
Allow, Block, Drop, or Allow with Web Policy to send a flow on for gateway inspection
Clients
Windows and macOS through the Client Proxy; macOS supports fewer rule criteria, and no Linux client is documented
India
Indian firewall flows can enter at Bangalore, Noida or Mumbai PoPs (status page, October 2026); logs can be kept in India
In India via
TechBag — rule design, quote in INR with GST, and a pilot on one user group
Part 02 · Learn

Understand firewall-as-a-service before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a cloud firewall?

A firewall run in the provider’s PoP that applies port, protocol and application rules to traffic wherever the user is.

VPN backhaul and branch boxes vs a cloud firewall — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionVPN backhaul and branch firewallsSkyhigh Cloud Firewall
Where non-web rules liveOn a branch box, or nowhere for home usersIn the PoP, applied wherever the user is
How remote traffic gets thereVPN backhaul to head officeWireGuard from the agent, or IPsec from the site
What a rule can nameIP address and portProcess, user, country, service or protocol
Web and non-webSeparate proxy and firewall consolesOne SSE console, with a hand-off to the gateway
Visibility for home usersNone once they leave the VPNDashboard of protocols, processes and blocked IPs
What it is NOT—A data-centre firewall, an IPS, or a published price

The cheapest test is a pilot: redirect one group through Cloud Firewall on default allow, read the 7-day dashboard, then write your rules.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How a laptop’s traffic gets in

Client Proxy

Skyhigh Client Proxy (SCP)

The same agent that steers web traffic to the gateway encrypts other flows and sends them to Cloud Firewall over a WireGuard tunnel, from Windows or macOS endpoints.

02
How a branch gets in without agents

Site tunnel

IPsec-Firewall integration

Since July 2026 an IPsec-capable router or firewall can forward all IP traffic, web and non-web, to the nearest Skyhigh PoP, covering printers and IoT that take no agent.

03
Where packets are judged

DPI engine

Cloud Firewall in the PoP

Headers are read first; web flows are passed to the gateway after the first packet, while non-web flows get deep packet inspection of every packet before they leave.

04
Where admins decide

Policy

Rules in the SSE console

Ordered rules match on IPs, ports, process, user, country or detected protocol; the first match wins, and anything unmatched is allowed unless you add a final block rule.

One agent or an IPsec tunnel into the PoP — non-web flows inspected packet by packet, web flows handed to the gateway.

Part 03 · Evaluate

Nine capabilities. Steer, inspect, control.

Skyhigh Cloud Firewall applies firewall rules to non-web traffic in the cloud, wherever the user is.

Steer
WireGuard

Agent tunnel to the PoP

The Client Proxy wraps non-web flows in a WireGuard tunnel to Cloud Firewall, so roaming users get the same rules as office users.

Steer
IPsec sites

Branches with no agent

A branch router sends DNS, FTP, SSH and other traffic down an IPsec tunnel, so devices that cannot run an agent are still covered.

Steer
On-prem relay

Through your existing proxy

Where there is no direct internet route, an on-prem Skyhigh gateway can act as a SOCKS relay that carries tunnelled traffic to the cloud.

Inspect
DPI

Whole-packet checks off the web

Non-web traffic is inspected packet by packet; web flows are identified on the first packet and handed to the gateway for content checks.

Inspect
Protocols

38 protocols by name

Rules can name a detected protocol rather than a port, from DNS, SMB and LDAP to QUIC, RDP, SIP and Gnutella, whatever port it uses.

Inspect
Dashboard

Seven days at a glance

Eleven default cards show traffic by protocol, top blocked client and destination IPs, top processes and top apps, for the last 7 days.

Control
Processes

Rules per application binary

On Windows a rule can target a process such as zoom.exe or teams.exe, with its path and signer, not just the port it happens to use.

Control
Geo rules

Block a country both ways

Source Country and Destination Country criteria let you drop traffic to or from places where you have no staff, offices or customers.

Control
Web hand-off

Allow, then inspect content

The Allow with Web Policy action passes a permitted flow on to the gateway’s rules, so one decision covers the port and the payload.

See it, don’t just read it

Watch Skyhigh Cloud Firewall in action

Skyhigh’s own 2023 demo of the Cloud Firewall console — the only official video for this product.

Skyhigh Security (official)·Demo, October 2023

Skyhigh Cloud Firewall Demo

A 2023 walk-through of the console; IPsec site tunnels and the newer default rules arrived after it was filmed.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Skyhigh Cloud Firewall

Web filtering covers only part of what leaves a laptop. Cloud Firewall puts rules on the rest, in the same PoPs.

Here’s what genuinely sets it apart — and exactly where it stops.

01

One agent for web and everything else

Laptops already running the Skyhigh Client Proxy for the web gateway need nothing new: the same client tunnels non-web flows over WireGuard to Cloud Firewall. Web traffic that reaches the firewall is identified on its first packet and passed to the gateway, so the two services share a policy console rather than splitting a user across two vendors.

02

Rules that know the app and the country

A rule can match a Windows process with its path and signer, a service from Skyhigh’s Cloud Registry, a user group or a source or destination country, as well as IPs, ports and 38 detected protocols. That lets you allow Teams media while dropping RDP to the internet, or refuse any flow towards countries where you have nobody.

03

Fits an estate that still runs appliances

Skyhigh is one of few vendors that still sells an on-prem web gateway beside its cloud. Here that matters: an on-prem gateway can relay tunnelled firewall traffic as a SOCKS proxy where there is no direct route out, and a July 2026 IPsec option lets branch routers send all traffic with no endpoint agent at all.

04

Where it stops

There is no price list and no firewall-specific analyst coverage, and only one official video, from 2023. The docs describe rules and deep packet inspection but no intrusion-prevention engine. It is outbound control, not a data-centre firewall. Unmatched traffic is allowed by default, macOS supports fewer rule criteria, and no Linux client is documented.

The idea
Firewall rules for non-web traffic, in the PoP
The on-ramps
Client Proxy over WireGuard, or IPsec from a site
The price
Quote only; add-on below SSE Complete
Proof, not promises

The numbers behind the platform

38 protocols
named in the detected-protocol list a Cloud Firewall rule can match, whatever the port
— Vendor
4 actions
per rule: Allow, Block, Drop, or Allow with Web Policy for content checks downstream
— Vendor
5 default rules
switched on in a new tenant, for SharePoint and OneDrive, DNS, Teams, HTTPS and NTP
— Vendor
3 Indian PoPs
Bangalore, Noida and Mumbai, as listed on Skyhigh’s status page in October 2026
— Vendor
145+ PoPs
worldwide by Skyhigh’s own count in March 2026; the status page names fewer
— Vendor
7 days
of firewall traffic on the default dashboard view, with PDF and scheduled reports
— Vendor

What your Skyhigh Cloud Firewall rollout looks like

Week 1Model

List the non-web traffic

Inventory what leaves laptops and branches besides web: DNS, RDP, SSH, SIP, file shares, and the processes behind each.

Week 2Decide

Confirm the licence path

Check whether your SKU is Cloud SWG or an SSE suite, price SSEFW as an add-on, and compare it with SSE Complete.

Week 3Pilot

Pilot on one user group

Turn on firewall redirection in the Client Proxy for a pilot group, keep default allow, and watch the 7-day dashboard.

Month 2Prove

Write rules, then deny

Add process, country and protocol rules from what the pilot showed, then enable the final deny rule for the group.

Month 3Commit

Add branches and roll out

Bring agentless branch devices in over IPsec, test macOS rules separately, and extend redirection to every user.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
34+ reviews*
77% would recommend
Rule flexibility4.2
Fit with Skyhigh SWG4.3
Inspection depth3.6
macOS parity3.4
Value for money3.8
5★
36%
4★
38%
3★
18%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We already pushed the Client Proxy for web filtering, so adding the firewall was a policy change, not another agent rollout.”
Network Security Lead
BFSI
BPO
“Process rules sorted our softphone problem: we allow the dialler binary on SIP and drop SIP from everything else.”
IT Infrastructure Manager
BPO
Pharmaceuticals
“Destination-country blocking took ten minutes and cut the noise from odd outbound connections on field laptops.”
Security Analyst
Pharmaceuticals
Manufacturing
“The IPsec option let us cover plant-floor devices that will never take an agent. Test the tunnel failover first.”
OT Network Engineer
Manufacturing
Education
“Remember the default is allow. We ran for a week before switching on the final deny rule, and found plenty first.”
Firewall Administrator
Education
Media
“Our Mac users get a thinner rule set than Windows, and we wanted IPS signatures on this traffic too.”
Head of IT
Media
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the firewall-as-a-service market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Cloud Firewall Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Skyhigh Cloud FirewallThis page

Add-on below SSE Complete; quoted per user.

Grid 02 · The architecture

Inspection Depth × On-ramp Reach

The grid nobody publishes — how deeply non-web traffic is inspected vs how many ways traffic can reach the firewall.

Wide reach, light inspectionFull-depth cloud firewallsBasic port filtersDeep but narrow on-ramps
Skyhigh Cloud FirewallThis page

Agent, IPsec sites and on-prem SOCKS relay; no IPS documented.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Skyhigh Cloud Firewall vs the cloud firewall field

Against Zscaler Zero Trust Firewall, Netskope One Cloud Firewall, Palo Alto Prisma Access, Fortinet FortiSASE and Cisco Secure Access — on on-ramps, inspection, rules, price and India.

DimensionSkyhigh Cloud FirewallZscaler Zero Trust FirewallNetskope One Cloud FirewallPalo Alto Prisma AccessFortinet FortiSASECisco Secure Access
What it isFWaaS inside Skyhigh SSEFirewall within ZIAFWaaS on Netskope OneNGFW stack as a serviceFortiOS firewall in SASECloud firewall in SSE
How traffic arrivesWireGuard agent, IPsecAgent or site tunnelsClient, GRE or IPsecUsers plus remote sitesFortiClient agentClient or network tunnel
Protocol coverage38 named protocolsAll ports and protocolsAll ports, FTP gatewayApp-ID on every portFortiGuard app controlL7 only in Advantage
Threat inspectionDPI, no IPS documentedIPS in AdvancedOptional IPSThreat PreventionIPS in Standard tierIPS in Advantage
Rule criteriaProcess, country, user10 rules in Standard5-tuple plus identityApp, user, zoneFortiOS policy modelDepth by package
Pricing modelPer user, via partnersPer user, by editionPer user, by bundlePer user or per MbpsPer user, user bandsPer user, 50 minimum
Published entry priceNot published~$6–12/user/month~$15+/user/monthQuote onlyQuote; UK list £78–304Tiered, not listed
Included vs add-onAdd-on below CompleteDepth is AdvancedIPS is optionalIn Enterprise editionIn the subscriptionL7 and IPS cost more
Endpoint clientsWindows and macOSClient ConnectorNetskope clientGlobalProtect agentFortiClientCisco Secure Client
Hybrid and on-prem fitSOCKS relay via SWGCloud onlyCloud onlySame policy as NGFWFortiGate continuityCisco firewall estates
India presenceBangalore, Noida, MumbaiFour Indian citiesEight Indian DCsFour Indian locationsNot documentedNot documented
Analyst standing (SSE)Niche Player 2025Top quadrant, 2025Top quadrant, 2025Top quadrant, 2025Challenger, 2025Not checked here
Lock-in and exitNeeds Skyhigh’s clientPlatform commitmentPlatform commitmentDeepens PAN estateDeepens Fabric tieFits a Cisco EA
Best fitSkyhigh SWG estatesZIA customersData-first SSE buyersPalo Alto firewall shopsFortiGate estatesCisco and Umbrella users
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Skyhigh Cloud Firewall if…

  • ✓Your users already run the Skyhigh Client Proxy for web filtering, and you want non-web traffic under the same console
  • ✓You need rules that name a Windows process, a user group, a country or a detected protocol, not only a port
  • ✓Some sites still route through an on-prem Skyhigh gateway, or branch devices cannot take an agent but can build IPsec

Compare alternatives if…

  • ✓Intrusion prevention on non-web traffic is a requirement — Zscaler Advanced, Netskope, Prisma Access and FortiSASE document it
  • ✓You want a price before a sales call — Fortinet publishes per-user list prices for FortiSASE
  • ✓You must replace data-centre firewalls as well — Palo Alto and Fortinet keep one policy across cloud and hardware

Do not expect…

  • ✓A published price, or Cloud Firewall in any Skyhigh bundle below SSE Complete
  • ✓A documented IPS engine, a Linux client, or full rule parity on macOS
  • ✓A top-quadrant analyst placement — Skyhigh was a Niche Player in Gartner’s 2025 SSE Magic Quadrant

TechBag has no firewall-as-a-service guide yet, so Skyhigh Cloud Firewall sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does unmanaged non-web traffic cost you?

Drag the sliders (users whose non-web traffic is covered; engineer-hour cost). Estimates model IT time spent on VPN backhaul issues, per-site firewall rule changes and chasing unexplained outbound connections at an assumed 1.5 hours per user a year, with 70% of it removed by one cloud rule set. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual firewall-operations cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Skyhigh prints no price for Cloud Firewall (SKU SSEFW) or any other product, and sells only through partners, per user per year. It is an add-on to Cloud SWG, Cloud SWG Advanced and the SSE Essential and Advanced suites, and is included in SSE Complete. TechBag compares the add-on against SSE Complete for your licence mix, then quotes in INR with GST.

Cloud Firewall add-on

Best for Skyhigh SWG or SSE Essential/Advanced estates

  • SKU SSEFW, quoted per user
  • Same Client Proxy as the web gateway
  • No published list price

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

SSE Complete

Best when you also need Private Access

  • Cloud Firewall included
  • Adds Private Access ZTNA and unlimited sanctioned CASB
  • Quoted per user through partners

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Licence

Is Cloud Firewall in your quote? It is an add-on to Cloud SWG and the Essential and Advanced suites.

2
Inspection

Do you need intrusion prevention on non-web traffic? Skyhigh’s firewall docs do not describe an IPS engine.

3
Default action

Have you planned the final deny rule? Cloud Firewall allows unmatched traffic until you add one.

4
Endpoints

Are all users on Windows or macOS? macOS supports fewer criteria, and no Linux client is documented.

5
Client version

Is every laptop on Client Proxy 4.9.0 or later? 4.8.x reached end of life on 1 May 2026.

6
Branches

Can branch routers build IPsec to a Skyhigh PoP for devices that will never take an agent?

7
India

Which PoP will Indian users reach — Bangalore, Noida or Mumbai — and is India set as the log location?

8
Category fit

TechBag does not yet have a firewall-as-a-service guide; compare at least two of the alternatives on this page.

FAQ

Questions buyers ask

It is Skyhigh Security’s firewall-as-a-service. Outbound traffic that is not web browsing — DNS, RDP, SSH, SIP, file transfer and so on — is tunnelled to a Skyhigh PoP, where it gets deep packet inspection and your rules. Web flows that reach it are passed to Skyhigh’s secure web gateway for content checks.

Ready to evaluate Skyhigh Cloud Firewall?

Map the non-web traffic leaving your laptops and branches first, or let a TechBag advisor scope a pilot on one user group.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.