Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Enhanced Capabilities of Skyhigh Client

The following table lists the enhanced capabilities of the new Skyhigh Client over the existing Skyhigh Client Proxy.

Skyhigh Client Skyhigh Client Proxy
Intelligent traffic routing using Mowgli-based policy capabilities. Mowgli-based policy capabilities are not supported.
Provision to add multiple gateways. This enables more flexible routing for complex networks and enhances fault tolerance. Provision to add two gateways: Primary and Alternate.
More flexible and powerful policy management UI to define traffic selection (interception, bypass, and block) and forwarding preferences suitable for the environment. A simple and rigid policy management UI to define traffic redirection. 
Configuring wildcard-based entries is possible during the configuration of domain-based lists that could be used for Bypass, Block, and Traffic forwarding. Configuring wildcard-based entries is not possible during the configuration of domain-based lists that could be used for Bypass, Block, and Traffic forwarding.
Enhanced flexibility to block or bypass sub-domains. Limited flexibility to block or bypass sub-domains.
Skyhigh Client can bypass, block, or steer the traffic to any gateway based on granular rules right at the Client itself. SCP could block traffic with granular rules/ACLs only with Secure Web Gateway, limiting the Client's role to a minimum.
Supports customizable Client profiles per Client policy or a group of policies. Global Client Configuration is applied to all policies. Customizable Client profile settings are not supported.
Skyhigh Client has a local proxy interface on a standard port controlled via Client Profile. The Local proxy can be used by approved applications as an explicit proxy. Skyhigh Client Proxy had a private proxy interface with dynamic non-standard ports. It was not exposed to other end-user traffic.
The Device Risk Assessment, Local Proxy, and Firewall Settings are localized and are specific to individual Client profiles. The Device Risk Assessment, Local Proxy, and Firewall Settings are globalized and are not specific to individual Client profiles.
The Smart Match capabilities are supported. Smart Match for domain names enables greater flexibility and usability while matching a specific domain against a list of domains with multiple levels of subdomains. The Smart Match capabilities are not supported.
Client UI (SSE) with enhanced visibility and troubleshooting capabilities. Client UI (SSE) with limited visibility and troubleshooting capabilities.
Introduction of the new endpoint Client UI to monitor Client connectivity status and enrich user experience. Absence of endpoint Client UI.
  • Was this article helpful?