Your web traffic is encrypted and your auditors want it inspected on site. The proxy should live in your own data centre — Skyhigh Secure Web Gateway On-Prem decrypts and inspects web traffic on appliances or VMs in your own data centre, with DLP in the licence, the former McAfee Web Gateway line on 12.2.25, and a hybrid route to Skyhigh’s cloud when you want it.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh Secure Web Gateway On-Prem — the appliance and VM gateway, formerly McAfee Web Gateway. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy in your own data centre that opens, checks and logs web traffic before it leaves your network.
What consolidation actually replaces, dimension by dimension.
| Dimension | An out-of-support proxy and a VPN home | Skyhigh Secure Web Gateway On-Prem |
|---|---|---|
| Software support | A release past its end-of-life date | 12.2.x, the supported main line |
| Encrypted traffic | Passed through without a look inside | Decrypted on the gateway with your own CA |
| Signing keys | A key file on the proxy’s disk | RSA up to 4096-bit; HSM-backed from 13.0 |
| Staff away from the office | A VPN back to head office | The cloud gateway on the same policy, with a cloud licence |
| Uploads of sensitive data | Nothing checks them | DLP included in the WSG-S licence |
| What it is NOT | — | A roaming service on its own, or a published price |
The cheapest test is one gateway or VM on 12.2.25 in front of a pilot group: decrypt, apply your rules, and compare it with what you run now.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A Skyhigh hardware appliance or a VM on your hypervisor runs the proxy, so HTTPS sessions are decrypted, filtered and logged inside your own network rather than at a cloud PoP.
Rule sets for web filtering, TLS, DLP and anti-malware run on the box; ICAP passes content to other scanners, and transparent router and Return to Sender modes are documented.
With a cloud SWG or SSE licence, one policy covers appliances and cloud; under Hybrid Mesh, gateways poll a cloud control plane, enforce locally and keep a cached policy.
13.0 swaps MLOS for SLOS 1.6 on AlmaLinux 9.6, boots in UEFI, turns on TLS 1.2 and 1.3 by default, drops SSLv3 and integrates Entrust, Thales and Fortanix HSMs.
A proxy on Skyhigh appliances or VMs in your data centre — with one policy into Skyhigh’s cloud when licensed.
Skyhigh Secure Web Gateway On-Prem inspects web traffic on hardware you run, before it leaves your network.
Transparent router mode lets the gateway sit in the traffic path without proxy settings on each client; Return to Sender is documented too.
HTTPS is opened on the gateway itself; 12.2.25 adds RSA 3072- and 4096-bit client-context certificates for the signing chain.
ICAP sends uploads and downloads to a third-party DLP or anti-malware engine and waits for its verdict before releasing them.
Data loss prevention is part of the WSG-S SKU, so posts and file uploads are checked on the gateway without a second product.
Gateway Anti-Malware, an ML emulation sandbox, is an add-on for WSG-S; Skyhigh claims 19.5% more protection than standard scanning.
Release 13.0 integrates Entrust nShield, Thales Luna and Fortanix DSM, so the gateway’s keys can be held in a hardware security module.
Add a Cloud SWG or SSE licence and appliances, VMs and Skyhigh’s cloud gateway are managed from a single policy on 12.2.x.
On-prem Secure Service Gateways take policy from the MOWGLI engine in the cloud and keep enforcing from a local cache in a brownout.
Skyhigh dates every line: 12.0 and 12.1 ended on 30 September 2024, and E-series appliances are supported until 31 March 2028.
Skyhigh’s hybrid gateway model, a 2024 RSA Conference session on web security for hybrid workers, and a 2023 look at managed-device control. All from Skyhigh Security’s official channel.
How on-prem gateways and Skyhigh’s cloud service work together under the hybrid model.
A 2024 conference session on web security for staff who split time between office and home.
A 2023 look at shaping web policy by whether the device making the request is managed.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
The gateway decrypts and inspects web sessions on hardware or VMs you run, so decrypted sessions are inspected and logged on your side of the firewall. 12.2.25 accepts RSA 4096-bit client-context certificates, and 13.0 can keep the gateway’s keys in an Entrust, Thales or Fortanix HSM.
Skyhigh is one of few vendors selling the same gateway on premises and as a cloud service. With a Cloud SWG or SSE licence, appliances and the cloud run one policy on 12.2.x, and Hybrid Mesh adds a cloud control plane while appliances keep enforcing from a local cache.
Gateways bought as McAfee Web Gateway carry on as Skyhigh SWG On-Prem. Skyhigh dates the end of life of each line — 10.x, 11.x, 12.0 and 12.1 are already past — so 12.2, and later 13.0, on E or F appliances or a VM is the supported way on.
There is no public price, Gateway Anti-Malware is an add-on, and browser isolation needs a cloud licence. WSG-S includes no cloud service, so laptops off the network need a VPN or that licence. 13.0 cannot yet sync policy to the cloud, and since 12.2.25 CVE details sit behind the customer portal.
List each gateway’s release and appliance model against Skyhigh’s EOL table; anything on 11.x or 12.1 is already unsupported.
Decide between WSG-S alone and Cloud SWG for hybrid, and whether Gateway Anti-Malware belongs on the quote from day one.
Stand up a gateway or VM on 12.2.25, issue the interception CA to pilot devices, and agree a bypass list for sensitive sites.
Move the remaining gateways to 12.2.x, migrate rule sets, and hold 13.0 back until it can sync policy to the cloud.
Send logs to your SIEM, keep at least 180 days for CERT-In, and connect branches or remote staff to the cloud if licensed.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We moved from 11.2 to 12.2 ahead of end of life. The rule sets came across cleanly; the certificate chain took a weekend.”
“Our auditors wanted decrypted traffic kept on our own racks. A gateway in our data centre answered that without argument.”
“Wiring ICAP into our existing DLP scanner took an afternoon; uploads pause at the gateway until the verdict comes back.”
“Branch staff now go through the cloud gateway on the same rules as head office. One policy, two places it is enforced.”
“We are staying on 12.2 for now. Release 13.0 cannot push policy to the cloud yet, and our hybrid setup relies on that.”
“Anti-malware turned out to be its own line on the quote, which we missed at first. Get every add-on listed in writing.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per user through partners; no public price.
The grid nobody publishes — how many ways a gateway can run under one policy vs how deeply it inspects what passes through.
Appliance, VM and hybrid cloud on one policy; DLP in, anti-malware add-on.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Fortinet FortiProxy, Symantec Edge SWG, Forcepoint Web Security, Zscaler Internet Access and Sophos Firewall web protection — on deployment, TLS, roaming, hybrid policy, price, add-ons, lifecycle and India.
| Dimension | Skyhigh Secure Web Gateway On-Prem | Fortinet FortiProxy | Symantec Edge SWG | Forcepoint Web Security | Zscaler Internet Access | Sophos Firewall (web protection) |
|---|---|---|---|---|---|---|
| What it is | Ex-McAfee Web Gateway | Fortinet’s on-site SWG | The former ProxySG | Cloud SWG, DLP-led | Cloud-only proxy | Firewall web filtering |
| Deployment | Appliance or VM | Appliance or VM | Appliance, VM or cloud | Cloud, plus an old line | No on-site option | XGS appliance only |
| TLS inspection | Full, RSA to 4096-bit | Full, hardware-assisted | Full, SSL Visibility | Full HTTPS | Full, in the cloud | Xstream bundle only |
| Off-network users | Via a cloud licence | No roaming agent | Through Cloud SWG | SmartEdge, mobile apps | Client Connector | No roaming agent |
| One policy with cloud | Yes on 12.2; not 13.0 | Separate FortiSASE | Universal Policy | Cloud and agent | Cloud is the policy | Sophos Central |
| Cloud app control | No CASB in WSG-S | Inline CASB only | Visibility, no API | Inline; API extra | Inline and API | No CASB |
| Threat and data protection | DLP in; sandbox add-on | AV, IPS, sandbox in | Content Analysis apart | Inline DLP built in | Sandbox in the stack | IPS, DPI; no DLP noted |
| Pricing model | Per user, via partners | Device + 500-user lots | Per user (reported) | Per user, 12 months | Per user, by edition | Appliance + bundle |
| Published entry price | Not published | Not published | No public price | $55/user/yr listed | ~$6–12/user/mo | Quoted in a bundle |
| Included vs add-on | Anti-malware extra | DLP, isolation extra | Components apart | RBI, API CASB extra | Editions add depth | TLS needs Xstream |
| Hardware and scale | Sized by appliance | 60,000 users (rated) | Four SSP models | Cloud capacity | 500B+ transactions/day | Per XGS model |
| Lifecycle and assurance | Dated EOL; portal CVEs | Run 7.6.6 or later | FIPS 140-3, CC | Cloud; 8.5.7 on-prem | Nothing to patch | Your box to update |
| India and logs | Your site, your logs | Your site, your logs | Delhi and Mumbai sites | India edge; US logs | Four Indian cities | At your edge |
| Best fit | McAfee-era estates | FortiGate shops | ProxySG renewals | DLP-led, 500+ users | Retiring appliances | Office-bound users |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Skyhigh Secure Web Gateway On-Prem is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the gateway; IT-hour cost). Estimates model admin and helpdesk time spent on web-borne malware clean-ups, blocked-site tickets and keeping several proxies’ rules in step at an assumed 1.5 hours per user a year, with 70% of it removed by one inspecting gateway under one policy. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Skyhigh publishes no price, its pricebook needs a partner login, and all of its sales run through partners. The on-prem gateway is SKU WSG-S, quoted per user, with DLP included and Gateway Anti-Malware as an add-on. A Cloud SWG licence (MVW) also carries the on-prem gateway entitlement and adds hybrid policy; isolation of risky sites starts with Cloud SWG Advanced. TechBag checks your versions and appliances first, then quotes in INR with GST.
Best for inspection kept fully on site
Best for a broader rollout
Best for sites plus remote staff
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is every gateway on 12.2.x? Releases 10.x, 11.x, 12.0 and 12.1 are past end of life, and 13.0 is Limited Availability.
Which appliance models do you run? D-series reached end of life in 2025; E and E2 end on 31 March 2028.
Is WSG-S alone enough, or do you need Cloud SWG for hybrid and remote users? Cloud SWG includes the on-prem entitlement.
Is Gateway Anti-Malware on the quote? It is an add-on for WSG-S, not part of the base on-prem licence.
Who owns the interception CA, which sites bypass decryption, and will 13.0’s HSM support matter to you?
How will laptops off the network be covered: VPN to head office, or Cloud SWG with Client Proxy 4.9?
Where do gateway logs go, and do you keep them 180 days for CERT-In? In hybrid, cloud logs default to 100 days.
Who holds the customer-portal login? Since 12.2.25, CVE and package details are visible only to customers.
Check your gateway versions and appliance models against Skyhigh’s end-of-life dates first, or let a TechBag advisor scope a 12.2.25 pilot on one site.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.