What is Cisco Umbrella

Umbrella is Cisco’s cloud-delivered DNS security offering. It began life as OpenDNS, which Cisco acquired and rebranded.

The product

Cloud-delivered DNS security from Cisco. DNS requests are intercepted and checked against allow and deny rules, with custom allow and block domains, roaming protection and a redirection portal for denied requests.

The origin

Umbrella is the OpenDNS product, branded as Cisco. Deployment requires DNS settings to be changed so that requests are forwarded to the Umbrella service.

The scope

The base licence covers DNS-layer filtering. Broader SSE capability, such as secure web gateway, CASB and AI security, is licensed separately as part of Cisco Secure Access.

In the base offering

  • DNS request interception with allow and deny determination
  • Custom allow and block domain lists
  • Roaming protection for off-network devices
  • Redirection portal for denied requests
  • SIEM integration and API-based management controls

What’s changing

Cisco is directing Umbrella customers toward Cisco Secure Access, a bundle that combines SSE, DNS filtering and AI security across several products and licences. Additional functionality sits outside the original Umbrella licence.

Three areas teams evaluate

These are the points that come up most often when an Umbrella renewal is on the table. Cloudbrink’s position on each is listed for reference.

AreaCisco Secure AccessCloudbrink
ArchitectureBuilt on hardware appliances and established networking product linesBuilt ground-up for AI-native workloads, 100% software
OperationsMultiple products bundled into a package, each with its own configurationSingle unified policy and visibility engine, one config for all use cases
Employee experienceApplication performance is affected by traffic hair-pinningQuality-of-experience layer maintains app performance on unreliable networks

End-of-life notice for legacy Umbrella offers

Cisco has published an end-of-life bulletin covering legacy Umbrella offers, including the affected part numbers. Both documents are worth checking against your current SKUs before renewal.

Cisco Umbrella and Cloudbrink compared

Eleven capabilities, described as each product delivers them.

CapabilityCisco UmbrellaCloudbrink
DNS filteringDNS request interception and determination of allow/deny rulesDNS request interception with app-category and reputation based allow/deny
Custom allow/block domainsSupportedSupported
Roaming protectionSupportedSupported, plus device posture and ZTNA
DNS server changesDNS settings must be changed to forward requests to the Umbrella serviceNo changes needed
Redirection portal for denySupportedSupported
Advanced cloud app usageLimitedDetailed logs and charts, including GenAI apps
SIEM integrationSupportedSupported
API-based management controlsSupportedSupported
SSE capabilitiesAdd-on licencesBuilt in at no additional cost
Points of presenceApproximately 50Approximately 800 globally
Licensing and TCOMultiple add-on licences make total cost harder to forecastSingle SKU, named-user licensing model

Sourced from Cloudbrink product documentation and Cisco’s published Umbrella and Secure Access materials. Cisco packaging changes frequently, so confirm current entitlements with your Cisco account team.

Where Cloudbrink fits

Cloudbrink is an alternative to consider alongside Cisco’s own upgrade path: DNS filtering, ZTNA and SSE delivered as one software service under a single named-user licence.

The platform covers hybrid access and ZTNA, DNS and web filtering, and Veraify for AI visibility and guardrails, all on one agent and one console.