In the case of on-site guests accessing the Internet from ???isolated??? network segments, guest users at internal locations are granted access to the Internet via a dedicated outbound pathway 1220, which proceeds through an HTTP proxy 1230 at the Trusted-Transitional boundary and a deep packet inspection filter 1080 at the Transitional-Untrusted boundary.