Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Leverage Next-Hop Proxy Capabities in SWG

Skyhigh Secure Web Gateway (SWG) uses the Next-Hop Proxy feature to route client requests through designated external proxy servers. You can configure this feature on a Skyhigh Web Gateway appliance to manage how traffic flows to its destinations. It also allows on-premises Web Gateway appliances to safely forward web traffic directly to the Skyhigh Security Cloud or other hybrid connections.

When you implement next-hop proxies, a rule in the ruleset calls the proxy module (engine) to forward requests using a configured proxy list. For example, requests with internal destinations can be forwarded through internal next-hop proxies. You define the IP addresses of internal destinations in a list, and the forwarding rule uses that list. You also maintain a list of internal next-hop proxies for the rule.

The Skyhigh SWG appliance does not include a next-hop proxy ruleset after initial setup. You can import a ruleset from the library and modify it, or create one of your own. When you import a next-hop proxy ruleset, the system also imports a server list for next-hop proxies. This list is empty by default, and you must configure it by adding servers. You can create multiple lists and use them for routing in different scenarios.

The library ruleset also includes settings for the next-hop proxy module. You can configure these settings to select a proxy list and define how the module uses proxies—either in round-robin mode or failover mode.

Leverage Advanced SSE Use Cases

You can use the Next-Hop Proxy capability to extend advanced cloud security and networking services to on-premises environments.

This capability supports the following use cases:

Protect Data and Prevent Exfiltration (Web DLP)
Goal: Prevent sensitive information leaks and maintain data integrity.
You can use next-hop proxies to inspect outbound data traffic for protection. You route requests to the SSE cloud, where Skyhigh Web Data Loss Prevention (DLP) policies are applied. Based on these policies, you can block or control the transmission of sensitive data before it leaves your network perimeter. 

Enforce Threat Protection and Browser Isolation (Risky Web and RBI)
Goal: Isolate endpoints from web-borne threats and unverified sites for on-premise users.
You can use next-hop proxies to route web traffic to SSE services such as Remote Browser Isolation (RBI) or other inspection layers on the cloud from on-premise locations. This approach enables you to safely access potentially risky or unknown websites with zero exposure to malware and other web-based threats.

  • Was this article helpful?