Skip to main content

AD_4nXe2v9Asf1IpGgX8rFkBBMKWqU15Pu_x28ZGjT6hTfiR6cS7e0_AHMpGOLKturNGWT6XhiX_qget2IQLnP2FsgH2bbK44ndyjxxkHqkNLVfiAdWk33BFzqpZa0azaWNAE02aJThlaQ?key=PWDw9Wr-ImMySZE8kVYz2Ps3

Netskope Global Technical Success (GTS)

Best Practices - Allow All Web Traffic

 

Netskope Cloud Version - 125

 

Objective

Provide an overview of best practices for securely enabling unrestricted web access.

 

Prerequisite

Netskope SWG / NGSWG license is required

 

Context

A customer may have a use case where unrestricted internet access is required for IT, executive users, or other specific individuals. In such cases, what is Netskope’s recommendation for securely enabling unrestricted web access?

 

Do You Know?

  • As of April 30, 2025, Netskope maintains a set of 132 predefined web categories, with every internet destination classified into one of these categories.
  • List of Netskope predefined web categories - Link

 

Details

  • Netskope does not recommend providing unrestricted internet access without proper safeguards.
  • Prior to enabling such access through Realtime policies, baseline security policies should be implemented to mitigate risk.
  • Netskope recommend Realtime policy structure

AD_4nXf0W2PpZnU-XNM4gpPmplJNYBjZ7xL-6oDqBOgtsmsvub7swVoZIM__gkDyKsKgDKsGPED-EJ60HSWbAHWrG1TEJCHmPt5smIhm8V2_rX8p1rD7f6TlUoLL0VhuSH0j2RhHTQhs2g?key=PWDw9Wr-ImMySZE8kVYz2Ps3

 

  • Unrestricted Internet access Realtime policy should be below Threat & Utility

Policy Order

Action

Ref.

License Required

DOH Block Policy

Block

Click

SWG / NGSWG

Patient Zero Policy

Block

Click

Click

Advance Threat Protection

Threat Protection Policy

Block

Click

Standard Threat Protection

Security Risk 

Block

Click

SWG / NGSWG

ITAR (International Traffic in Arms Regulations)

Block

Click

Click

SWG / NGSWG

RBI (Remote Browser Isolation)

Isolate

Click

RBI 

Online Ads

Block

Click

 

Unrestricted Internet access

Allow

Image 1

SWG / NGSWG

 

  • Unrestricted internet access  Realtime protection policy

Path: Netskope Tenant UI >>> Policies >>> Real-time Protection >>> New Policy

Image 1

AD_4nXd3Jd37mkU84XbXrwugQEXTdrUuyP1VrIfWt_dsHdeAxcIL8vCn-7EZeNXbHMP8PRoFbRxeTFRkIbmQqy5XnALrE7n4O-BAxJHTXZT9Cw6fylEhEgWZsTvTRsFGPgL-lTAlXnDw?key=PWDw9Wr-ImMySZE8kVYz2Ps3

 

 

Author Notes

  • Customers without an Advanced Threat Protection (ATP) or Remote Browser Isolation (RBI) license should block the following web categories and associated activities to maintain security.

Category: Newly Released Domains, Newly Observed Domains, Uncategorized, Parked domains, Unreachable, Miscellaneous, and Web Hosting, ISP & Telco, Shareware/Freeware

Activities: Upload and Download

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

Be the first to reply!