Yes, Cisco Umbrella blocks websites, and it is one of the main reasons organisations deploy it. Blocking happens in the cloud, so it applies wherever a device’s DNS or web traffic is routed through Umbrella.
At the DNS layer, when a user tries to reach a blocked domain, Umbrella returns the address of a block page instead of the real site, so the connection never reaches the destination. Administrators can block by:
- Security categories, such as malware, phishing and command-and-control
- Content categories, such as gambling, social media or adult content
- Destination lists of specific domains
- Applications, where application settings are available
Block pages can carry your organisation’s branding and message. Administrators can also set up bypass codes or bypass users so specific people can reach a blocked site when needed.
DNS blocking works on whole domains. To block a single page while allowing the rest of a site, you need the intelligent proxy in the DNS Advantage tier or the SIG secure web gateway, which inspects full URLs.
Umbrella can also block threats that are not websites at all, such as malware calling home over non-web protocols, because those connections rely on DNS too.
DNS blocking can be bypassed if a browser uses its own DNS-over-HTTPS provider or a user connects through a personal VPN. That is why many organisations pair Umbrella with endpoint controls or a secure web gateway.