Why Cloud-Proxy SSE Struggles in China and Restricted Regions

Why Cloud-Proxy SSE Struggles in China and Restricted Regions

The short answer

Cloud-proxy SSE platforms struggle in China and other restricted regions because they depend on a backhaul hop: the user's traffic has to reach a vendor point of presence to be inspected. When a national firewall or a heavily filtered network sits between the user and that point of presence, the hop degrades or fails, and the security, along with the user's connectivity, goes with it.

On-device inspection does not have this problem, because there is no remote hop to fail. Inspection happens on the endpoint, and traffic goes straight to its destination. We cover the underlying model in the SSE architecture guide.

Why the Great Firewall breaks backhauling

A cloud proxy only works if the user can reliably reach its point of presence. In most of the world that is a safe assumption. In China it is not.

The Great Firewall inspects, throttles, and blocks cross-border traffic. A backhaul architecture that tries to route a user's traffic out to a point of presence, often one hosted outside the country, runs straight into that filtering. The result is unpredictable: sessions slow to a crawl, connections drop, and the security tool that depends on the hop stops enforcing consistently. This is a known reliability problem for backhaul-dependent SSE vendors in the region.

The same shape of problem shows up anywhere the path to the inspection point is filtered, throttled, or unreliable: restricted regions, heavily regulated networks, and places with poor connectivity to the nearest PoP.

Why on-device keeps working

The failure comes from the dependency on a remote inspection point. Remove the dependency and the failure mode disappears.

dope.security inspects traffic on the device. There is no point of presence to reach, so there is no backhaul hop for a national firewall to break. The Fly-Direct Secure Web Gateway decrypts and inspects locally and sends traffic straight to its destination, which means enforcement stays consistent even where cross-border routing is filtered. It is one of the clearest cases where the on-device model is not just faster but structurally more reliable. See what is backhauling.

Where this matters

  • Companies with staff or offices in China, who need consistent web security and acceptable performance for those users.
  • Manufacturing, supply chain, and multinational teams with people in restricted or heavily filtered regions. A mid-market manufacturing organization moved off Forcepoint specifically to fix the backhauled experience for users in restricted regions. See the manufacturing Forcepoint displacement story.
  • Travelers, whose experience through filtered networks with a cloud proxy is inconsistent at best.

What to check before you assume a vendor works there

  • Does the vendor inspect at a point of presence, and if so, where is the nearest one to your users in the region?
  • Does enforcement degrade gracefully or fail when the hop to that point of presence is unreliable?
  • Is there a way to inspect without depending on cross-border routing at all?

That last question is the one that separates the architectures. If inspection requires a remote hop, a national firewall can break it. If inspection runs on the device, it cannot.

Frequently asked questions

Does Zscaler work in China? Zscaler is a cloud-proxy architecture that depends on reaching a point of presence, which is exactly what the Great Firewall interferes with, so performance and reliability in China are a common concern for backhaul-dependent SSE. Results vary with routing and configuration.

Why do cloud SWGs struggle in China? Because they backhaul traffic to an inspection point, and the Great Firewall filters and throttles the cross-border routing that hop relies on. When the hop degrades, so does the security and the user's connectivity.

How does dope.security work in restricted regions? It inspects traffic on the device, so there is no remote point of presence to reach and no backhaul hop for a national firewall to break. Enforcement stays consistent.

Is on-device SSE more reliable internationally? For users behind filtered or unreliable cross-border networks, yes, because it removes the dependency on reaching a distant inspection point.

See it in action

Have users in China or other restricted regions? Start a free trial or book a 20-minute demo at dope.security.

SSE
SSE
Secure Web Gateway
Secure Web Gateway
Remote Work Security
Remote Work Security
back to blog Home