Security / Secure Web Gateway

Secure Web Gateway

Web security,
at the gateway.

Category and threat filtering at the DNS lookup, then full TLS inspection and malware scanning on the gateway proxy. One policy, enforced on the gateways your traffic already uses.

DNS filtering on Business · TLS inspection and malware scanning on Enterprise

Today's challenges

The open web is where attacks start.

Most attacks start with a link.

Phishing pages, malware downloads and compromised sites reach users the moment a page loads. By the time an endpoint tool reacts, the credentials are gone or the file is already on disk.

Our approach

Filter at the lookup.
Inspect on the proxy.

PulseHA SWG runs on the gateways your traffic already passes through. One identity-aware policy decides at the DNS lookup, then again on the decrypted request, and every verdict is logged against the user who made it.

Secure Web

Control DNS-level web gateway policies for your organization.

View filter logs Settings
PoliciesDomain ListsExceptions
New Policy
Search policies... 4 of 4 policies

Drag rows to change evaluation order

Status Name Scope Rules
Block malware & phishing All 6
Restricted content All 4
Contractor web access Group 3
Streaming during work hours All 2
Business

Filter at the lookup

Eight curated threat feeds, a category taxonomy and your own allow and deny lists, checked before a connection opens.

Enterprise

Inspect the traffic

The gateway proxy decrypts HTTPS, applies policy to the full request and scans downloads for malware inline.

Business

Record every verdict

Each allow and block is logged with the user, destination and gateway, in a tamper-evident audit trail.

How it works

Secure Web Gateway capabilities

Categories and feeds

Business

Block whole categories in a few clicks.

Build policies from 56 categories across security threats, restricted content, productivity and general browsing, backed by eight curated threat feeds and your own domain lists.

  • Malware, phishing, command-and-control and newly registered domains
  • Allow, deny and bypass domain lists, plus URL prefix rules
  • Policies evaluated top to bottom, reordered by drag
Back to policies

Edit Policy

Update the configuration for this web gateway policy.

2

Filtering Rules

Rule 1
Category Malware
Action
Block Allow
Rule 2
Category Phishing
Action
Block Allow
Rule 3
Category Newly Registered
Action
Block Allow
Add Rule

TLS inspection

Enterprise

See inside encrypted traffic.

The gateway proxy decrypts HTTPS with a trust root PulseHA provisions for your tenant, so policy applies to the full URL and not just the hostname.

  • Inspect all HTTPS, or only the traffic your policies select
  • Do-not-decrypt lists for sites that must stay private
  • Reviewed Microsoft 365 compatibility bundle

Web inspection

Tenant HTTPS trust

active
Active generation
2
Active fingerprint
9f:2a:41:c7:…:e0
Active root expires
14/09/2031

Inspect web traffic

Filter HTTP requests and HTTPS connection hosts on supported gateways. Turning this off leaves DNS filtering running.

HTTPS inspection

Decrypt HTTPS only after the tenant trust root is active and trusted by managed devices. Sites on the do-not-decrypt list remain opaque.

Inspect all HTTPS except a list Do not decrypt · banking & health

Compatibility exceptions

Microsoft 365 (reviewed 2026-09-18)

Malware scanning

Enterprise

Downloads scanned before they land.

Files on inspected traffic are checked for malware before any byte reaches the device, on the gateway or Orbit location already carrying the traffic. Nothing is kept once the check finishes.

  • Bitdefender engine, running on your own gateways
  • Fail open or fail closed if a file cannot be checked
  • Scan size limit you set, 25 MB by default

Web inspection

Malware protection

Downloads on inspected traffic are checked for malware before any byte reaches the device. The check happens on whichever gateway or Orbit location is already carrying the traffic, and nothing is kept once the check finishes.

Malware scanning

Check file downloads for malware. On by default when inspection is turned on.

If a file cannot be checked

When the scan engine is unreachable. "Block" is the safer posture; "Allow" keeps downloads working during an engine outage.

Block the download (fail closed)
Maximum file size to scan (MB) 25

Larger downloads pass through unscanned. The default of 25 MB covers typical installers and documents.

Visibility

Business

Every decision, with a name on it.

Each allow and block lands in the audit log with the user, destination and gateway behind it, live every fifteen seconds. Turn a false positive into a tenant exception from the event itself.

  • Filter by DNS, web or malware events
  • Tenant exceptions created from a denied event
  • Tamper-evident audit trail

Audit

AllAuditPostureSCIMExitAccessContent Filter
1h24h

5 shown · 1,284 total · live every 15s

TimeEventDecisionActorDestinationGatewayProtocol
12s ago Domain Blocked Blocked priya@acme.com crypto-drainer.net185.220.101.4:443 gw-london-01 Web
41s ago Domain Allowed Allowed dana@acme.com github.com140.82.121.3:443 gw-london-01 DNS
1m ago Domain Blocked Blocked omar@acme.com lucky-spins.bet104.21.7.19:443 gw-nyc-02 DNS
2m ago Domain Blocked Blocked kim@acme.com free-mining.io172.67.3.88:443 gw-london-01 DNS
3m ago Domain Allowed Allowed lee@acme.com salesforce.com13.110.54.9:443 gw-nyc-02 Web

Plans

SWG unlocks at Business.

Business includes DNS-layer filtering. Enterprise adds the gateway proxy, with full TLS inspection and malware scanning under the same policy.

Core

For small teams getting started with zero trust access.

  • Full Network product
  • DNS-layer web filtering
  • Firewall & access policies

Enterprise

For organizations with advanced security and compliance needs.

  • Everything in Business
  • Posture & trust score enforcement
  • Custom audit retention & SLAs

Full feature breakdown on the pricing page →

Common questions

Is PulseHA a secure web gateway?
Yes. Business includes identity-aware DNS filtering. Enterprise adds the gateway proxy, with full TLS inspection and inline malware scanning.
Does PulseHA inspect HTTPS traffic and scan downloads?
Yes, on Enterprise. The gateway proxy decrypts HTTPS, applies your policy to the full request, and scans downloaded files for malware before they reach the device. Destinations you never want decrypted go on a never-decrypt list.
Which plan includes SWG?
DNS-layer filtering ships on Business and Enterprise. The gateway proxy, TLS inspection and malware scanning are Enterprise. Core includes the network, not SWG.

Better together

Network comes with every plan.

Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.

  • You already have it. Network ships in every plan.
  • One policy model across network and security.
  • Application-aware routing and enforcement, together.
Explore Network