On the ap content filtering is enabled only with nat mode so works on the edge of network only if ap manage the traffic and nat not as pass through. An MX with deeper controll over this kind of inspection also with vpn to the corporate is a good solution, but i think the use of a solution like Cisco Umbrella is the best protection not only for content but also for malware, botnet and so on... with no small regular update but with live data from cloud at dns/ip layer in real time.
... View more