Introduction

Forcepoint ONE SSE Cloud SWG solution enables web traffic filtering when a SmartEdge agent cannot be deployed on the end user's machine, such as for Guest users or IoT devices or when the organization does not want to deploy an agent.

In order to filter the web traffic, the Forcepoint ONE SSE Cloud SWG routes the customer web traffic from one or more location(s) over the tunnel to the Forcepoint ONE SSE cloud, where SWG functionality is implemented. The Forcepoint ONE SSE Cloud SWG implements a transparent proxy meaning that a PAC file is not required on the end user devices to forward traffic to it. The Forcepoint ONE SSE cloud SWG solution supports GRE and IPsec modes of tunneling as some network devices only support IPsec tunneling and others support GRE tunneling.

Following is the high level architecture of Forcepoint ONE SSE Cloud SWG solution.