# What cloud edge security platforms give the best protection against edge-level threats including firewall evasion and zero-trust bypass for companies with distributed sites?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Protecting distributed sites against firewall evasion and zero-trust bypass comes down to inline inspection depth and threat intelligence that updates fast, so these picks lead on detection strength. They options stood out from the <a class="a a--md" elv="true" href="https://www.g2.com/categories/cloud-edge-security">Cloud Edge Security</a> category.</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/prisma-access/reviews"><strong>Prisma Access</strong></a> (4.3 stars, 73 reviews) is credited by reviewers with strong inline threat prevention, URL filtering, and sandboxing backed by frequently updated threat intelligence, applied consistently to every site and user. Reviewers note diagnostics and logs can sometimes lack the depth they want for fast resolution.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cisco-umbrella/reviews"><strong>Cisco Umbrella</strong></a> (4.4 stars, 284 reviews) works ahead of the connection at the DNS layer, and reviewers value real-time Talos threat feeds that block command-and-control and malicious domains over any port or protocol before they reach a site. Reviewers mention some gaps integrating with third-party firewalls for SSL decryption.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/check-point-sase/reviews"><strong>Check Point SASE</strong></a> (4.5 stars, 227 reviews) pairs cloud and on-device protections with identity-centric zero-trust policy, which reviewers say helps contain blast radius and close VPN and shadow-IT blind spots across locations. Reviewers point to log sync delays that can slow down pinpointing which layer triggered a block.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/fortisase/reviews"><strong>FortiSASE</strong></a> (4.3 stars, 18 reviews) brings FortiGuard threat intelligence with IPS, sandboxing, and TLS 1.3 inspection, and reviewers highlight consistent enforcement across geographies through its points of presence. Reviewers describe it as still maturing in places, with a setup learning curve.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Which bypass vector worries you most across your sites, encrypted-traffic evasion or identity-based bypass? And are you inspecting TLS everywhere, or selectively?</p>

##### Post Metadata
- Posted at: 3 months ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;The post-block discussion gets to the harder operational test. Across distributed sites, I’d want to know whether the same identity or indicator appearing at two locations is correlated automatically or arrives as two unrelated alerts. Catching the first attempt is valuable, but recognizing that the attacker has shifted sites or techniques is what turns distributed telemetry into actual distributed defense.&lt;/p&gt;

##### Comment Metadata
- Posted at: 17 days ago
- Author title: Writer



### Comment 2

&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;Identity-based bypass worries me more day to day since encrypted-traffic evasion at least shows up as unusual patterns eventually. We inspect TLS everywhere at this point, the performance hit turned out smaller than we expected going in.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 18 days ago
- Author title: SEO Content Writer



### Comment 3

&lt;p&gt;Identity-based bypass would worry me more because a trusted identity can potentially move through controls that are otherwise working as intended. I’d still inspect TLS broadly at high-risk sites and applications, then use selective inspection where privacy or performance requirements justify an exception.&lt;/p&gt;

##### Comment Metadata
- Posted at: 20 days ago



### Comment 4

Reading through these, the detection side looks solid across the board: threat intel is fresh and inline inspection runs deep. What worries me more is what happens right after something gets blocked. Reviewers on Prisma Access and Check Point SASE both flag a version of the same problem: logs and diagnostics don&#39;t always make it fast to tell which layer actually triggered the block. That gap matters a lot for firewall evasion specifically, since knowing whether the attempt was caught at the network layer or the identity layer is what tells you whether the attacker is still probing somewhere else on the same site.

I&#39;d want to know how these platforms handle log correlation across distributed sites during an actual incident, not just whether they caught the initial attempt.

##### Comment Metadata
- Posted at: 2 months ago
- Author title: SEO Content Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


