Here is a synopsis taken from BITGLASS
As cloud-based SWG vendors add more capabilities, they are starting to look more and more promising as a direct replacement for a firewall. By that, I mean that for the same use case (network/perimeter protection), you can use either a firewall or cloud-SWG – they are simply delivering network security services via the cloud.
What’s different about CASB is that CASBs come into play for a different use case, one that makes the firewall (and any notion of perimeter protection) obsolete. As a pre-requisite for protection, both SWGs and the firewalls require traffic to transit through them. They are deployed either on the corporate network, or as a cloud-based extension of the corporate network.
When an outside user connects to a cloud app, that traffic doesn’t transit through the corporate network, which is what lead to the rise of CASBs, which are architected for exactly this “beyond the firewall” scenario. Every % increase in the amount of off-network cloud traffic translates into a CASB gain at the expense of the SWG/FW.
In short, SWGs and CASBs are both taking share from NGFWs, and both may be necessary in your enterprise