Talk to us
by XcitiumTechBag Intel Page

Xcitium Web Protection

Your offices resolve every web address before they connect. Bad domains shouldn’t resolve at all — Xcitium Web Protection, the service once sold as Secure Internet Gateway, blocks bad domains at lookup time for every office that forwards its DNS to it, with OTG agents for laptops and Chromebooks off-site and resolvers in Ohio and Frankfurt.

DNS-layer filtering, no decryptionOTG agents for laptops and ChromebooksQuote only; Ohio or Frankfurt resolvers

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price and no licence unit; Web Protection is not on Xcitium’s published per-endpoint list
Quote
Depth
Blocks by domain at lookup time; it cannot see inside an allowed site or decrypt anything
DNS layer
Analysts
No analyst placement for this product was found; do not read the Xcitium brand’s EDR claims across
None found
India
The two regions in Xcitium’s host table; measure resolution time from your own offices first
Ohio or Frankfurt

Quick answer

Xcitium Web Protection, sold earlier as Secure Internet Gateway, filters at the DNS layer: point your forwarders at it and blocked domains never resolve. Preset levels block 7, 12 or 17 categories, OTG agents cover laptops and Chromebooks off-site, and nothing is decrypted. It is quote-only, and the only regions Xcitium lists are US (Ohio) and EU (Frankfurt), so Indian queries leave the country. Read more ↓ Show less ↑
Part 01 · Orient

The Xcitium platform family

This page covers Xcitium Web Protection — the DNS web filter formerly sold as Secure Internet Gateway. The rest:

Quick facts

30-second orientation
Product
Cloud DNS filtering with a multi-tenant console, the product formerly sold as Secure Internet Gateway (SIG)
Maker
Xcitium, Bloomfield, New Jersey; the former Comodo Security Solutions, led by founder and CEO Melih Abdulhayoglu
Lineage
Comodo Dome Shield, then Xcitium Secure Internet Gateway; the old SIG web address now redirects to Web Protection
Price
Not published and absent from Xcitium’s per-endpoint price list; sold through a demo and a quote
Layer
DNS only: your server or router forwards lookups to Web Protection, which must be the only forwarder
Roaming
OTG 1 agent for laptops off-site, OTG 2 for Chromebooks; Xcitium names Windows, Mac and Chromebook
TLS
No decryption; a root certificate is pushed only so blocked HTTPS sites show the block page, not an error
Logs
Recent Traffic shows the last 200 requests; DNS log files can be pulled by API for the previous 5 days
India
Regions listed: US (Ohio) and EU (Frankfurt); no Indian resolver, office or distributor is documented
In India via
TechBag — latency test from your offices, log-retention plan, quote in INR with GST
Part 02 · Learn

Understand DNS web filtering before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a DNS web filter?

Your offices send every name lookup to Web Protection, and blocked domains never resolve, on any device behind that site.

Rules on each router and nothing off-site vs one cloud DNS filter — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionRouter rules per office, nothing off-siteXcitium Web Protection
Where filtering happensA rule list on each office routerOne cloud resolver every site forwards to
Users working from homeUnfiltered once they leave the officeOTG agents on laptops and Chromebooks
A branch with a changing IPLeft out, or a VPN back to head officeDynamic IP agent or a dynamic DNS name
What a blocked user seesA timeout or a browser errorYour branded block page, once the root cert is in
Running many customersA separate console per clientOne multi-tenant console with a global default
What it is NOT—TLS inspection, CASB, an Indian resolver or a public price

The cheapest test is one office: repoint its forwarder, push the root certificate, and watch Recent Traffic for a week before the next site.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where every lookup is answered

Resolvers

Regional DNS and portal hosts

Each region has two DNS hosts, a portal and a reporting host; Xcitium lists only US (Ohio) and EU (Frankfurt), with the IP addresses sent by email at sign-up.

02
How a site is recognised

Locations

Static, dynamic, DDNS and virtual

A location is a public IP the service will answer: a static address or CIDR block, a dynamic IP kept current by an agent, a dynamic DNS name, or a tagged virtual site.

03
What gets blocked

Policies

Levels, domains and Safe Search

A default policy picks Essential, Enhanced, Optimum or Custom category sets, adds allowed and blocked domains, forces Safe Search, and can be overridden per location or user.

04
Who is covered off the network

OTG agents

On-the-go roaming clients

OTG 1 on a laptop and OTG 2 on Chromebooks carry the policy when users leave a registered location; Chromebooks also need the PEM certificate pushed through Google Workspace.

Sites forward DNS to resolvers in Ohio or Frankfurt — a policy decides, and OTG agents carry it off the network.

Part 03 · Evaluate

Nine capabilities. Filter, cover, manage.

Xcitium Web Protection blocks unwanted sites when their names are looked up, before any connection opens.

Filter
Levels

Three preset category sets

Essential blocks 7 categories such as phishing and spyware, Enhanced 12, Optimum 17; Custom lets you choose your own.

Filter
Domains

Allow and block by domain

Exceptions cover single domains, every subdomain or a whole top-level domain such as .ru, and can be bulk-imported.

Filter
Safe Search

Cleaner search results

One switch enforces Safe Search on Google, Bing and YouTube, and another decides whether brand-new, unclassified sites resolve.

Cover
Sites

Five ways to register a site

Static IP, dynamic IP with a small agent, dynamic DNS, roaming or virtual locations let offices without fixed addresses join.

Cover
Roaming

Laptops and Chromebooks away

The OTG 1 agent filters laptops off-site and OTG 2 covers Chromebooks, so policy follows users who work from home.

Cover
Block page

A page users understand

Your logo and wording appear when a site is refused; a pushed root certificate stops HTTPS blocks showing as errors.

Manage
Multi-tenant

One console, many customers

MSPs add customers, set a global default policy for new ones and drill into each tenant from a single sidebar.

Manage
White label

Your brand on the portal

Replace the page title, logo and footer image, up to 800 × 200 pixels and 1 MB, so customers see the MSP’s name.

Manage
Log export

Pull DNS logs by API

The Data Offload API downloads gzip DNS log files from Amazon S3, but only for the previous 5 days, so collect daily.

Why Xcitium Web Protection

Every connection starts with a name lookup. Web Protection refuses the bad ones before they connect.

Here’s what genuinely sets it apart — and exactly where it stops.

01

A DNS filter an MSP can hand out by the dozen

The console is built for many customers at once: a global default policy for each new tenant, a block page and portal that carry the MSP’s own logo, enforced two-factor sign-in for every admin, and an API. Customers register a site by its public IP and repoint DNS, with no appliance and nothing in the traffic path.

02

Sites without a fixed address still count

Many Indian branches sit behind broadband with a changing public IP. Web Protection accepts a dynamic IP location kept current by a small agent on one PC, a dynamic DNS hostname from the router, or a tagged virtual location, and OTG agents carry the same policy to laptops and Chromebooks off-site.

03

Policies a non-specialist can set

Three preset levels do most of the work: Essential blocks seven threat categories, Enhanced twelve and Optimum seventeen, adding adult, gambling and download sites. Safe Search on Google, Bing and YouTube is one switch, and email alerts tell you when someone hits a blocked category you chose.

04

Where it stops

It filters domains and nothing more: no TLS decryption, no file scanning, no CASB. Its guides say nothing about DNS-over-HTTPS bypass. There is no price, licence unit or trial in public, no analyst coverage, and no official video. Resolvers are listed only in Ohio and Frankfurt, and log files can be pulled for just 5 days.

The idea
Block the domain before it resolves
The residency
Resolvers in Ohio or Frankfurt, not India
The price
Quote only; no published licence unit
Proof, not promises

The numbers behind the platform

7 categories
blocked by the default Essential level, from phishing and spam to spyware and anonymisers
— Vendor
17 categories
blocked by the strictest preset, Optimum, which adds gambling, dating, weapons and more
— Vendor
5 location types
static IP, dynamic IP, dynamic DNS, roaming and virtual, for sites with or without a fixed address
— Vendor
2 regions
listed for the service, US (Ohio) and EU (Frankfurt); neither is in India
— Vendor
5 days
of DNS log files the Data Offload API can still fetch, so a daily pull is needed for audits
— Vendor
200 requests
the size of the Recent Traffic view, the quickest check that a new site is being filtered
— Vendor

What your Xcitium Web Protection rollout looks like

Week 1Model

Map sites and their addresses

List every office’s public IP, mark the ones that change, and count laptops and Chromebooks that work off-site.

Week 2Decide

Time lookups from India

Query the Ohio and Frankfurt resolvers from two offices and compare with your current DNS before you sign anything.

Week 3Pilot

Pilot one site in Essential

Add the location, repoint its DNS forwarder, push the root certificate, and watch Recent Traffic for false blocks.

Week 4Prove

Set levels and exceptions

Pick Enhanced or Optimum per site, allow the business portals that trip a category, and switch on Safe Search.

Month 2Commit

Roll out agents and log pulls

Install OTG agents on roaming devices and schedule a daily Data Offload job so DNS logs outlive the 5-day window.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
27+ reviews*
74% would recommend
Ease of rollout4.3
MSP console4.1
Category accuracy3.8
Reporting and logs3.4
Value for money3.9
5★
34%
4★
40%
3★
17%
2★
6%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
IT Services
“We moved forty client offices onto it in a fortnight. Changing the router’s DNS was the whole install at most of them.”
MSP Operations Lead
IT Services
Retail
“Our branches are on broadband with changing IPs. The dynamic IP agent on one front-desk PC kept every site recognised.”
IT Manager
Retail
Education
“Push the root certificate before go-live. Until we did, blocked HTTPS sites showed scary browser errors, not our page.”
Systems Administrator
Education
Manufacturing
“Enhanced was right for the shop floor; the office needed Custom because a supplier portal fell into Download Sites.”
Head of IT
Manufacturing
BFSI
“Lookups go to Frankfurt for us. It is usable, but we measured page loads before and after, and the auditor asked why.”
Network Engineer
BFSI
Healthcare
“The five-day log window caught us out. We now pull files every night by API so we still have them when an audit comes.”
Security Analyst
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the DNS and web filtering market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Secure Web & DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Xcitium Web ProtectionThis page

Quote only; no published unit, trial or analyst coverage.

Grid 02 · The architecture

Indian Presence × Inspection Depth

The grid nobody publishes — how close the documented resolvers or PoPs sit to Indian offices vs how far past the domain each product can see.

Deep, but far from IndiaDeep and India-nearDNS floors abroadDNS floors in India
Xcitium Web ProtectionThis page

DNS only; regions in Ohio and Frankfurt.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Xcitium Web Protection vs the DNS and web filtering field

Against OpenText Core DNS Protection, Cisco Umbrella, Cloudflare One (Gateway), DNSFilter and Zscaler Internet Access — on layer, roaming, encrypted DNS, TLS, price, logs and India.

DimensionXcitium Web ProtectionOpenText Core DNS ProtectionCisco UmbrellaCloudflare One (Gateway)DNSFilterZscaler Internet Access
What it isMSP DNS web filterMSP DNS filterDNS tiers, SIG aboveGateway in a SASEProtective DNSInline cloud proxy
Enforcement layerDNS onlyDNS onlyDNS, proxy at SIGDNS, HTTP, networkDNS onlyFull inline proxy
Roaming coverageOTG 1 and OTG 2Windows agent onlySecure Client moduleWARP clientClients on 5 platformsClient Connector
Encrypted DNS bypassNot documentedBlocks 53, DoH, DoTDoH/DoT categoryPer-location DoH, DoTEncryption includedInspects DoH inline
TLS and certificatesBlock page onlyNo TLS inspectionSelective at SIGFull on paid plansNo TLS inspectionFull TLS inspection
Categories and policyPresets of 7, 12, 1778 BrightCloud catsTalos intelligence330+ city networkAppAware at PlusContent-aware rules
Pricing modelUnit not publishedPer site, by keycodePer user, by tierPer user a monthPer licence a monthPer user, by edition
Published entry priceNot publishedNot published~$30–40/user/yearFree; then $7/user/mo$1.00/licence/mo~$6–12/user/month
Included vs add-onContents unstatedAll in each policyProxy costs moreDNS in the free planAdd-ons pricedEditions add depth
Logs and retention5-day log filesReports to 13 monthsS3 export24 h free, 30 days paid9-day query logsStream to your SIEM
MSP and adminMulti-tenant, brandedMSP console, APICisco and MerakiOne Cloudflare consoleMSP from $150/monthEnterprise admin
India resolver or PoPOhio or FrankfurtNot documentedMumbai and ChennaiSix Indian citiesNo Indian city namedFour Indian cities
Trial and exitDemo, then repoint30-day trialTrial; repoint DNSFree to 50 users14-day trialPoC; unwind tunnels
Best fitMSPs on XcitiumWindows-heavy MSPsDNS now, proxy laterPrice-led, India-nearSelf-serve SMB DNSFull inspection
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Xcitium Web Protection if…

  • ✓You are an MSP already selling Xcitium and want a DNS filter you can brand and hand to many small customers
  • ✓Your sites sit on broadband with changing IPs and need dynamic IP or dynamic DNS locations, not a fixed address
  • ✓The requirement is the DNS floor — blocking phishing, malware and unwanted categories — not inspecting content

Compare alternatives if…

  • ✓Lookups must resolve inside India — Cloudflare lists six Indian cities, Zscaler four and Cisco Umbrella two
  • ✓You want a printed price and a self-serve trial — Cloudflare, DNSFilter and OpenText all offer one
  • ✓Browser DNS-over-HTTPS must be closed off — OpenText’s agent and Cloudflare’s per-location DoH document how

Do not expect…

  • ✓TLS decryption, file scanning or any CASB — the certificate only makes the block page appear
  • ✓More than 5 days of downloadable DNS log files without a daily collection job of your own
  • ✓An Indian region, a published licence unit, analyst coverage or an official product video

Xcitium Web Protection is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do unfiltered web lookups cost you?

Drag the sliders (users behind the filter; IT-hour cost). Estimates model IT time spent cleaning up after phishing and malware sites, and handling web-access tickets, at an assumed 1.5 hours per user a year, with 70% of it removed by DNS-layer blocking. Both figures are assumptions, and a DNS filter does not stop threats inside allowed sites. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual web-threat clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Xcitium sells Web Protection after a demo and prints no price or licence unit; it is absent from the per-endpoint postpaid list ($2.39 to $10.99 a month) that covers its other products. TechBag pins down whether the unit is a user, a device or a site, and quotes in INR with GST.

Direct or MSP customer

Best for small multi-site offices

  • Quote after a demo; unit not published
  • Preset levels, Safe Search, OTG agents
  • Resolvers in US (Ohio) or EU (Frankfurt)

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

MSP multi-tenant

Best for MSPs already selling Xcitium

  • Custom quote for the MSP console
  • White-label portal and block page, 2FA
  • API and 5-day DNS log offload

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Requirement

Is the need to block domains, or to inspect content and uploads? If the second, this is the wrong layer: buy a proxy.

2
Latency

How long do lookups take from each office to the Ohio or Frankfurt resolver, against your current DNS? Measure first.

3
Sites

Which offices have a fixed public IP, and which need the dynamic IP agent or a dynamic DNS name to be recognised?

4
Roaming

Are off-site devices Windows or Mac laptops and Chromebooks the OTG agents cover? Phones need another answer.

5
Bypass

How will you stop browsers using DNS-over-HTTPS to another resolver? The guides are silent, so test it in the pilot.

6
Logs

CERT-In’s 2022 Directions ask for 180 days of logs; who pulls Web Protection’s 5-day DNS files daily and stores them?

7
Regulation

Under SEBI’s CSCRF, guideline 4.e requires that regulated entities “shall implement DNS filtering services”; does a foreign-hosted resolver satisfy your auditor?

8
Licence

What is the licence unit — user, device or site — and the term? Ask for it in writing, in INR with GST.

FAQ

Questions buyers ask

It is Xcitium’s cloud DNS filtering service. Each office is registered by its public IP and forwards DNS to Web Protection, so lookups for blocked categories or domains get a block page instead of an address. OTG agents extend the same policy to laptops and Chromebooks away from the office.

Ready to evaluate Xcitium Web Protection?

Time DNS lookups from your offices to Ohio and Frankfurt first, or let a TechBag advisor scope a one-site pilot with a daily log pull for audit retention.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.