Skip to content
Notifications
Clear all

My simple test: Netskope vs. plain old DNS filtering for blocking malware domains.

2 Posts
2 Users
0 Reactions
24 Views
(@jacksonw)
Estimable Member
Joined: 3 months ago
Posts: 63
Topic starter   [#15888]

I was setting up a new branch office and needed a quick security layer. Budget was tight, so I first tried a DNS filtering service (like OpenDNS/Cisco Umbrella). It worked for basic known-bad domain blocking.

Then I got a Netskope trial. The difference was immediate. DNS filtering only caught the call to `badstuff[.]com`. Netskope showed the full path: the Excel macro that downloaded the payload, the callout, and even the C2 traffic *after* the initial DNS call because it was SSL-inspected.

My naive question: for blocking malware, is the main value of a CASB/SWG like Netskope just the SSL decryption? Or is there something else in the inspection engine I'm missing? I'm used to spreadsheets and simple SQL logic, so the "how" here is a bit of a black box to me.


not a buyer, just a nerd


   
Quote
(@brianl)
Honorable Member
Joined: 3 months ago
Posts: 506
 

I'm a systems manager at a mid-size industrial equipment manufacturer (around 300 users), and we run both NetSuite for ERP and a hybrid stack of on-prem and SaaS tools. We've had Netskope in production for about two years now, primarily for cloud app security and shadow IT discovery, but we use its SWG functions for remote users.

Here's a breakdown from our deployment and the eval we did against DNS filtering:

1. **Inspection Depth - It's Not Just SSL Decryption:** You're right that SSL inspection is a huge part of it, but the engine is doing more. DNS filtering sees a request for `badstuff.com` and blocks it. Netskope sees that same request, but also inspects the *content* of allowed connections. In our environment, it caught a compromised WordPress plugin on our marketing site that was making encrypted, legitimate-looking POST requests to an exfil server. A DNS filter would have missed it because the domain was a benign CDN. The value is full traffic inspection, not just the domain.

2. **Pricing Reality - The Gap is Significant:** Our DNS filtering (Cisco Umbrella) was roughly $1.50 to $2 per user per month for the security tier. Netskope's SWG/CASB bundle, for us, landed between $7 and $9 per user per month with our commitment. The hidden cost is in setup and tuning - you need someone to manage policies for SSL decryption, which can be a project.

3. **Deployment Effort - Days vs. Months:** Turning on a DNS filter is an afternoon project: change DHCP or push a config. Rolling out Netskope's client for full traffic inspection took us about three months of phased testing, dealing with application breakage from SSL decryption (old internal tools, some SaaS apps), and tuning exemptions. It's not a "set and forget" layer.

4. **Where It Breaks - Performance and Exceptions:** There's a tangible performance hit when you enable full SSL inspection, especially on latency-sensitive applications like VoIP or video conferencing. We had to create bypass policies for those. Also, some client applications (especially some older, unsigned thick clients) don't play nice with the forwarded proxy and will fail silently. You'll spend time in the logs figuring those out.

For your specific question on blocking malware, I'd recommend sticking with DNS filtering unless you have a reason to go deeper. DNS filtering is good enough for basic web-borne threats and is vastly simpler. Move to a full SWG like Netskope only if you need to see *what's inside* allowed traffic, you're worried about data exfiltration over permitted channels, or you have a compliance need to log all web activity. For your branch office use case, tell us if you have compliance drivers (like PCI) or if the main concern is users clicking on bad links.



   
ReplyQuote