Agent bloat is a huge issue, especially when mutiple agents for the same basic purpose.
While OpenDNS and ZScaler are good platforms there are other options. Especially if you've already have a large scale Cisco routed infrastructure and use ASAs for VPN access they really have the most mature solution for what you're looking for.
Integrated with the Cisco Any Connect client there's a plug-in that you can install called Cisco Web Security. At your fixed sites with the appropriate router using DMVPN / IWAN / PFRv2 your fixed clients can use the same cloud web policy that your mobile/VPN clients use with CWS. (No I'm not a Cisco rep...Yes my company has over 18 Palo devices from 5060s down to PA200s) Cisco just has a better solution for cloud based filtering.
... View more