Filter at the lookup
Eight curated threat feeds, a category taxonomy and your own allow and deny lists, checked before a connection opens.
Secure Web Gateway
Category and threat filtering at the DNS lookup, then full TLS inspection and malware scanning on the gateway proxy. One policy, enforced on the gateways your traffic already uses.
Today's challenges
Phishing pages, malware downloads and compromised sites reach users the moment a page loads. By the time an endpoint tool reacts, the credentials are gone or the file is already on disk.
Almost all web traffic is encrypted. A filter that only sees the hostname cannot tell a document from a payload, so a trusted file-sharing site becomes a delivery route.
Custom DNS resolvers, browser settings and personal hotspots route around controls configured on each laptop. Policy has to sit on the path the traffic takes.
When something gets through, IP addresses and hostnames do not tell you which user, which group or which rule allowed it. Investigations stall at the first question.
Our approach
PulseHA SWG runs on the gateways your traffic already passes through. One identity-aware policy decides at the DNS lookup, then again on the decrypted request, and every verdict is logged against the user who made it.
Control DNS-level web gateway policies for your organization.
Drag rows to change evaluation order
| Status | Name | Scope | Rules | ||
|---|---|---|---|---|---|
| Block malware & phishing | All | 6 | |||
| Restricted content | All | 4 | |||
| Contractor web access | Group | 3 | |||
| Streaming during work hours | All | 2 |
Eight curated threat feeds, a category taxonomy and your own allow and deny lists, checked before a connection opens.
The gateway proxy decrypts HTTPS, applies policy to the full request and scans downloads for malware inline.
Each allow and block is logged with the user, destination and gateway, in a tamper-evident audit trail.
How it works
Categories and feeds
BusinessBuild policies from 56 categories across security threats, restricted content, productivity and general browsing, backed by eight curated threat feeds and your own domain lists.
Update the configuration for this web gateway policy.
TLS inspection
EnterpriseThe gateway proxy decrypts HTTPS with a trust root PulseHA provisions for your tenant, so policy applies to the full URL and not just the hostname.
Tenant HTTPS trust
activeInspect web traffic
Filter HTTP requests and HTTPS connection hosts on supported gateways. Turning this off leaves DNS filtering running.
HTTPS inspection
Decrypt HTTPS only after the tenant trust root is active and trusted by managed devices. Sites on the do-not-decrypt list remain opaque.
Inspect all HTTPS except a list Do not decrypt · banking & healthCompatibility exceptions
Microsoft 365 (reviewed 2026-09-18)Malware scanning
EnterpriseFiles on inspected traffic are checked for malware before any byte reaches the device, on the gateway or Orbit location already carrying the traffic. Nothing is kept once the check finishes.
Downloads on inspected traffic are checked for malware before any byte reaches the device. The check happens on whichever gateway or Orbit location is already carrying the traffic, and nothing is kept once the check finishes.
Malware scanning
Check file downloads for malware. On by default when inspection is turned on.
If a file cannot be checked
When the scan engine is unreachable. "Block" is the safer posture; "Allow" keeps downloads working during an engine outage.
Block the download (fail closed)Larger downloads pass through unscanned. The default of 25 MB covers typical installers and documents.
Visibility
BusinessEach allow and block lands in the audit log with the user, destination and gateway behind it, live every fifteen seconds. Turn a false positive into a tenant exception from the event itself.
5 shown · 1,284 total · live every 15s
| Time | Event | Decision | Actor | Destination | Gateway | Protocol |
|---|---|---|---|---|---|---|
| 12s ago | Domain Blocked | Blocked | priya@acme.com | crypto-drainer.net185.220.101.4:443 | gw-london-01 | Web |
| 41s ago | Domain Allowed | Allowed | dana@acme.com | github.com140.82.121.3:443 | gw-london-01 | DNS |
| 1m ago | Domain Blocked | Blocked | omar@acme.com | lucky-spins.bet104.21.7.19:443 | gw-nyc-02 | DNS |
| 2m ago | Domain Blocked | Blocked | kim@acme.com | free-mining.io172.67.3.88:443 | gw-london-01 | DNS |
| 3m ago | Domain Allowed | Allowed | lee@acme.com | salesforce.com13.110.54.9:443 | gw-nyc-02 | Web |
Plans
Business includes DNS-layer filtering. Enterprise adds the gateway proxy, with full TLS inspection and malware scanning under the same policy.
For small teams getting started with zero trust access.
For growing teams who need more control and visibility.
For organizations with advanced security and compliance needs.
Full feature breakdown on the pricing page →
Better together
Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.