Sangfor Athena SWG – Secure Web Gateway for Modern Enterprises

Sangfor Athena SWG is a next-generation Secure Web Gateway that protects users from web-based threats, enforces secure internet access policies, and provides full visibility and control over web traffic for safer, compliant browsing.

Why Athena SWG?

Full Visibility into Encrypted Traffic Gain complete visibility into encrypted traffic to detect any malicious or suspicious behavior across your network in real time.

User and Application Analytics Identify exactly who is using which applications and when, providing deep insights into user activity across the organization.

Improved Productivity and Compliance Control Maintain full control over internet usage to enhance user productivity while ensuring strict compliance with organizational security policies.

Athena SWG Use Cases

Office Network Management

Without Athena SWG, office networks can become unstructured, with users freely accessing non-work-related content such as video streaming, social media, and entertainment, making it difficult for IT administrators to control bandwidth usage. Athena SWG enables organizations to identify and manage non-business applications, ensuring bandwidth is prioritized for critical business operations and improving overall productivity. It also provides advanced traffic management features for efficient bandwidth allocation and supports unified management across multiple branch offices, including 3G link backup for improved network reliability and performance.

Public WiFi Management

Athena SWG simplifies public WiFi access by supporting flexible authentication methods and unified user management for both wired and wireless networks. It integrates with AD and RADIUS for single sign-on (SSO) and enables guest authentication through platforms such as Facebook, WeChat, and SMS. The solution also supports switch-based user access control to regulate LAN connections, while integration with WLAN vendors like Cisco and Aruba allows a unified authentication center that streamlines network integration and simplifies overall management.

Internet Access Proxy & Web Security

Athena SWG provides a secure web gateway that protects users from web-based threats while enabling safe and controlled internet access. It integrates with both on-premise applications and internet traffic, with high-performance SSL decryption to inspect and analyze all HTTP and HTTPS traffic effectively. Unlike traditional NGFW or UTM solutions, it reduces performance bottlenecks while improving visibility. Powered by AI-based threat intelligence, it delivers advanced web filtering and enhanced detection of both known and unknown threats, ensuring a secure and reliable browsing experience for users.

Legal Compliance

Athena SWG helps organizations comply with local laws and regulations governing internet usage by providing comprehensive monitoring and logging of user activities. It records actions such as file uploads, forum postings, email usage, browsing history, and accessed applications to ensure full audit visibility. This detailed logging supports regulatory compliance and serves as a reliable resource for investigating incidents of unauthorized or illegal network activity.

Athena SWG Key Features and Capabilities

Proxy Avoidance Protection

Traditional web filters used to restrict access to certain web applications and content are becoming less effective against proxy avoidance tools. Athena SWG works together with Athena EPP to strengthen enforcement by detecting and blocking attempts to bypass security controls, ensuring stronger protection of the security perimeter. In addition, Sangfor’s R&D team continuously updates application signatures by categorizing and adding new proxy avoidance tools, keeping detection and blocking capabilities accurate and up to date.

Intelligent Traffic Management

Athena SWG enhances bandwidth utilization by over 30% through advanced traffic management capabilities. Dynamic Traffic Control automatically adjusts policies and allocates idle bandwidth efficiently to optimize network performance. Intelligent Flow Control manages both uplink and downlink P2P traffic, enabling organizations to assign customized traffic packages, set usage quotas, and limit bandwidth for heavy users to ensure fair and efficient network distribution.

Gateway and Client Decryption to Uncover Encrypted Traffic

Most internet traffic today is protected using SSL/TLS encryption, which helps secure data but can also hide malicious content such as malware. Athena SWG addresses this challenge by offering both gateway and client-based decryption methods. Organizations can choose to use either approach or run both in parallel, providing flexible and effective visibility into encrypted traffic based on their security policies and IT strategy.

Unified Network-wide Management of all Clients

Athena SWG provides unified management across both wired and wireless networks, enabling centralized control of all client devices within the organization. It supports flexible authentication methods such as username/password, IP/MAC binding, QR codes, SMS, social media logins, SAML 2.0, and other third-party systems. Access permissions can be managed based on user identity, application, location, and device type, ensuring secure and consistent access control while simplifying network management and reducing operational costs.

Precise and Accurate Application Control

Athena SWG delivers comprehensive application control using one of the largest application signature databases in Asia, capable of identifying over 6,000 applications, including cloud, mobile, and web applications. The database is updated every two weeks to ensure accuracy and relevance. It enables fine-grained control by distinguishing specific application behaviors such as uploads and downloads, while also supporting bulk management for large enterprises to improve operational efficiency and simplify policy enforcement.

Offloading Performance When Using ICAP Integration With Third Party System

Athena SWG functions as an ICAP client and integrates with any ICAP-enabled server or network appliance to offload security processing and value-added services. It supports both request and response inspection modes, allowing flexible traffic analysis. Additionally, ICAP server groups can operate in round-robin or concurrent modes, improving load distribution, performance efficiency, and overall system scalability.

Secure Onboarding Devices With Endpoint Security Posture

Athena SWG can identify and secure endpoint devices with or without agents, ensuring that all connected devices meet security and compliance requirements. It provides full visibility and control over devices within the environment while maintaining network performance and minimizing operational impact.