Your offices resolve every web address before they connect. Bad domains shouldn’t resolve at all — Xcitium Web Protection, the service once sold as Secure Internet Gateway, blocks bad domains at lookup time for every office that forwards its DNS to it, with OTG agents for laptops and Chromebooks off-site and resolvers in Ohio and Frankfurt.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Xcitium Web Protection — the DNS web filter formerly sold as Secure Internet Gateway. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Your offices send every name lookup to Web Protection, and blocked domains never resolve, on any device behind that site.
What consolidation actually replaces, dimension by dimension.
| Dimension | Router rules per office, nothing off-site | Xcitium Web Protection |
|---|---|---|
| Where filtering happens | A rule list on each office router | One cloud resolver every site forwards to |
| Users working from home | Unfiltered once they leave the office | OTG agents on laptops and Chromebooks |
| A branch with a changing IP | Left out, or a VPN back to head office | Dynamic IP agent or a dynamic DNS name |
| What a blocked user sees | A timeout or a browser error | Your branded block page, once the root cert is in |
| Running many customers | A separate console per client | One multi-tenant console with a global default |
| What it is NOT | — | TLS inspection, CASB, an Indian resolver or a public price |
The cheapest test is one office: repoint its forwarder, push the root certificate, and watch Recent Traffic for a week before the next site.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Each region has two DNS hosts, a portal and a reporting host; Xcitium lists only US (Ohio) and EU (Frankfurt), with the IP addresses sent by email at sign-up.
A location is a public IP the service will answer: a static address or CIDR block, a dynamic IP kept current by an agent, a dynamic DNS name, or a tagged virtual site.
A default policy picks Essential, Enhanced, Optimum or Custom category sets, adds allowed and blocked domains, forces Safe Search, and can be overridden per location or user.
OTG 1 on a laptop and OTG 2 on Chromebooks carry the policy when users leave a registered location; Chromebooks also need the PEM certificate pushed through Google Workspace.
Sites forward DNS to resolvers in Ohio or Frankfurt — a policy decides, and OTG agents carry it off the network.
Xcitium Web Protection blocks unwanted sites when their names are looked up, before any connection opens.
Essential blocks 7 categories such as phishing and spyware, Enhanced 12, Optimum 17; Custom lets you choose your own.
Exceptions cover single domains, every subdomain or a whole top-level domain such as .ru, and can be bulk-imported.
One switch enforces Safe Search on Google, Bing and YouTube, and another decides whether brand-new, unclassified sites resolve.
Static IP, dynamic IP with a small agent, dynamic DNS, roaming or virtual locations let offices without fixed addresses join.
The OTG 1 agent filters laptops off-site and OTG 2 covers Chromebooks, so policy follows users who work from home.
Your logo and wording appear when a site is refused; a pushed root certificate stops HTTPS blocks showing as errors.
MSPs add customers, set a global default policy for new ones and drill into each tenant from a single sidebar.
Replace the page title, logo and footer image, up to 800 × 200 pixels and 1 MB, so customers see the MSP’s name.
The Data Offload API downloads gzip DNS log files from Amazon S3, but only for the previous 5 days, so collect daily.
Here’s what genuinely sets it apart — and exactly where it stops.
The console is built for many customers at once: a global default policy for each new tenant, a block page and portal that carry the MSP’s own logo, enforced two-factor sign-in for every admin, and an API. Customers register a site by its public IP and repoint DNS, with no appliance and nothing in the traffic path.
Many Indian branches sit behind broadband with a changing public IP. Web Protection accepts a dynamic IP location kept current by a small agent on one PC, a dynamic DNS hostname from the router, or a tagged virtual location, and OTG agents carry the same policy to laptops and Chromebooks off-site.
Three preset levels do most of the work: Essential blocks seven threat categories, Enhanced twelve and Optimum seventeen, adding adult, gambling and download sites. Safe Search on Google, Bing and YouTube is one switch, and email alerts tell you when someone hits a blocked category you chose.
It filters domains and nothing more: no TLS decryption, no file scanning, no CASB. Its guides say nothing about DNS-over-HTTPS bypass. There is no price, licence unit or trial in public, no analyst coverage, and no official video. Resolvers are listed only in Ohio and Frankfurt, and log files can be pulled for just 5 days.
List every office’s public IP, mark the ones that change, and count laptops and Chromebooks that work off-site.
Query the Ohio and Frankfurt resolvers from two offices and compare with your current DNS before you sign anything.
Add the location, repoint its DNS forwarder, push the root certificate, and watch Recent Traffic for false blocks.
Pick Enhanced or Optimum per site, allow the business portals that trip a category, and switch on Safe Search.
Install OTG agents on roaming devices and schedule a daily Data Offload job so DNS logs outlive the 5-day window.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We moved forty client offices onto it in a fortnight. Changing the router’s DNS was the whole install at most of them.”
“Our branches are on broadband with changing IPs. The dynamic IP agent on one front-desk PC kept every site recognised.”
“Push the root certificate before go-live. Until we did, blocked HTTPS sites showed scary browser errors, not our page.”
“Enhanced was right for the shop floor; the office needed Custom because a supplier portal fell into Download Sites.”
“Lookups go to Frankfurt for us. It is usable, but we measured page loads before and after, and the auditor asked why.”
“The five-day log window caught us out. We now pull files every night by API so we still have them when an audit comes.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the DNS and web filtering market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote only; no published unit, trial or analyst coverage.
The grid nobody publishes — how close the documented resolvers or PoPs sit to Indian offices vs how far past the domain each product can see.
DNS only; regions in Ohio and Frankfurt.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against OpenText Core DNS Protection, Cisco Umbrella, Cloudflare One (Gateway), DNSFilter and Zscaler Internet Access — on layer, roaming, encrypted DNS, TLS, price, logs and India.
| Dimension | Xcitium Web Protection | OpenText Core DNS Protection | Cisco Umbrella | Cloudflare One (Gateway) | DNSFilter | Zscaler Internet Access |
|---|---|---|---|---|---|---|
| What it is | MSP DNS web filter | MSP DNS filter | DNS tiers, SIG above | Gateway in a SASE | Protective DNS | Inline cloud proxy |
| Enforcement layer | DNS only | DNS only | DNS, proxy at SIG | DNS, HTTP, network | DNS only | Full inline proxy |
| Roaming coverage | OTG 1 and OTG 2 | Windows agent only | Secure Client module | WARP client | Clients on 5 platforms | Client Connector |
| Encrypted DNS bypass | Not documented | Blocks 53, DoH, DoT | DoH/DoT category | Per-location DoH, DoT | Encryption included | Inspects DoH inline |
| TLS and certificates | Block page only | No TLS inspection | Selective at SIG | Full on paid plans | No TLS inspection | Full TLS inspection |
| Categories and policy | Presets of 7, 12, 17 | 78 BrightCloud cats | Talos intelligence | 330+ city network | AppAware at Plus | Content-aware rules |
| Pricing model | Unit not published | Per site, by keycode | Per user, by tier | Per user a month | Per licence a month | Per user, by edition |
| Published entry price | Not published | Not published | ~$30–40/user/year | Free; then $7/user/mo | $1.00/licence/mo | ~$6–12/user/month |
| Included vs add-on | Contents unstated | All in each policy | Proxy costs more | DNS in the free plan | Add-ons priced | Editions add depth |
| Logs and retention | 5-day log files | Reports to 13 months | S3 export | 24 h free, 30 days paid | 9-day query logs | Stream to your SIEM |
| MSP and admin | Multi-tenant, branded | MSP console, API | Cisco and Meraki | One Cloudflare console | MSP from $150/month | Enterprise admin |
| India resolver or PoP | Ohio or Frankfurt | Not documented | Mumbai and Chennai | Six Indian cities | No Indian city named | Four Indian cities |
| Trial and exit | Demo, then repoint | 30-day trial | Trial; repoint DNS | Free to 50 users | 14-day trial | PoC; unwind tunnels |
| Best fit | MSPs on Xcitium | Windows-heavy MSPs | DNS now, proxy later | Price-led, India-near | Self-serve SMB DNS | Full inspection |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Xcitium Web Protection is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the filter; IT-hour cost). Estimates model IT time spent cleaning up after phishing and malware sites, and handling web-access tickets, at an assumed 1.5 hours per user a year, with 70% of it removed by DNS-layer blocking. Both figures are assumptions, and a DNS filter does not stop threats inside allowed sites. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Xcitium sells Web Protection after a demo and prints no price or licence unit; it is absent from the per-endpoint postpaid list ($2.39 to $10.99 a month) that covers its other products. TechBag pins down whether the unit is a user, a device or a site, and quotes in INR with GST.
Best for small multi-site offices
Best for a broader rollout
Best for MSPs already selling Xcitium
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is the need to block domains, or to inspect content and uploads? If the second, this is the wrong layer: buy a proxy.
How long do lookups take from each office to the Ohio or Frankfurt resolver, against your current DNS? Measure first.
Which offices have a fixed public IP, and which need the dynamic IP agent or a dynamic DNS name to be recognised?
Are off-site devices Windows or Mac laptops and Chromebooks the OTG agents cover? Phones need another answer.
How will you stop browsers using DNS-over-HTTPS to another resolver? The guides are silent, so test it in the pilot.
CERT-In’s 2022 Directions ask for 180 days of logs; who pulls Web Protection’s 5-day DNS files daily and stores them?
Under SEBI’s CSCRF, guideline 4.e requires that regulated entities “shall implement DNS filtering services”; does a foreign-hosted resolver satisfy your auditor?
What is the licence unit — user, device or site — and the term? Ask for it in writing, in INR with GST.
Time DNS lookups from your offices to Ohio and Frankfurt first, or let a TechBag advisor scope a one-site pilot with a daily log pull for audit retention.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.