Internet Threat Protection (ITP) Architecture

How core components and DNS resolution work in ITP
Updated On: Sep 12, 2025

Internet Threat Protection (ITP) Overview

Internet Threat Protection (ITP) is a Secure Web Gateway (SWG) solution. Its core functions include web traffic filtering (e.g., identifying and blocking access to known threats, domain categories, and URLs), access policy enforcement (e.g., blocking or allowing access to specific domains, categories, apps, or geolocations), and payload inspection of web requests.

The heart of ITP is the secure web gateway (swg) agent, a proxy which lives in the cloud and has distributed points of presence. At each point, swg agent acts as an intermediary between users and the public internet, inspecting traffic and blocking users from malicious content. It integrates 3rd-party threat intelligence and ITP policy rules to determine whether to block or allow users' access to internet resources.

ITP is useful for corporations that want to protect remote and on-site users (threat blocking) and for organizations that have compliance requirements for internet access control (non-compliance blocking).