A plain reference for teams running Cisco Umbrella: what the product does, how Cisco’s packaging is changing, and how its capabilities line up against Cloudbrink. No opinions, just the details in one place.
01
The DNS-layer product, its origins, and what sits inside the base licence.
02
The move toward Cisco Secure Access, and the three areas teams evaluate.
03
Umbrella and Cloudbrink side by side across eleven capabilities.
04
Sixteen common questions about Umbrella, Secure Access and Cloudbrink.
Umbrella is Cisco’s cloud-delivered DNS security offering. It began life as OpenDNS, which Cisco acquired and rebranded.
Cloud-delivered DNS security from Cisco. DNS requests are intercepted and checked against allow and deny rules, with custom allow and block domains, roaming protection and a redirection portal for denied requests.
Umbrella is the OpenDNS product, branded as Cisco. Deployment requires DNS settings to be changed so that requests are forwarded to the Umbrella service.
The base licence covers DNS-layer filtering. Broader SSE capability, such as secure web gateway, CASB and AI security, is licensed separately as part of Cisco Secure Access.
Cisco is directing Umbrella customers toward Cisco Secure Access, a bundle that combines SSE, DNS filtering and AI security across several products and licences. Additional functionality sits outside the original Umbrella licence.
These are the points that come up most often when an Umbrella renewal is on the table. Cloudbrink’s position on each is listed for reference.
| Area | Cisco Secure Access | Cloudbrink |
|---|---|---|
| Architecture | Built on hardware appliances and established networking product lines | Built ground-up for AI-native workloads, 100% software |
| Operations | Multiple products bundled into a package, each with its own configuration | Single unified policy and visibility engine, one config for all use cases |
| Employee experience | Application performance is affected by traffic hair-pinning | Quality-of-experience layer maintains app performance on unreliable networks |
Cisco has published an end-of-life bulletin covering legacy Umbrella offers, including the affected part numbers. Both documents are worth checking against your current SKUs before renewal.
Eleven capabilities, described as each product delivers them.
| Capability | Cisco Umbrella | Cloudbrink |
|---|---|---|
| DNS filtering | DNS request interception and determination of allow/deny rules | DNS request interception with app-category and reputation based allow/deny |
| Custom allow/block domains | Supported | Supported |
| Roaming protection | Supported | Supported, plus device posture and ZTNA |
| DNS server changes | DNS settings must be changed to forward requests to the Umbrella service | No changes needed |
| Redirection portal for deny | Supported | Supported |
| Advanced cloud app usage | Limited | Detailed logs and charts, including GenAI apps |
| SIEM integration | Supported | Supported |
| API-based management controls | Supported | Supported |
| SSE capabilities | Add-on licences | Built in at no additional cost |
| Points of presence | Approximately 50 | Approximately 800 globally |
| Licensing and TCO | Multiple add-on licences make total cost harder to forecast | Single SKU, named-user licensing model |
Sourced from Cloudbrink product documentation and Cisco’s published Umbrella and Secure Access materials. Cisco packaging changes frequently, so confirm current entitlements with your Cisco account team.
Cloudbrink is an alternative to consider alongside Cisco’s own upgrade path: DNS filtering, ZTNA and SSE delivered as one software service under a single named-user licence.
The platform covers hybrid access and ZTNA, DNS and web filtering, and Veraify for AI visibility and guardrails, all on one agent and one console.