How does Cisco Umbrella work?

Cisco Umbrella works by sitting in the path of your internet requests and applying security policy in the cloud, starting with DNS.

Every connection to a website or app begins with a DNS lookup. Organisations send those lookups to Umbrella instead of a standard resolver, by forwarding DNS from the network or firewall, deploying Umbrella virtual appliances, integrating with Cisco and Meraki routers, or installing the Umbrella module in Cisco Secure Client.

When a request arrives, Umbrella:

  1. Matches it to an identity, such as a network, device or Active Directory user.
  2. Checks the domain against that identity’s policy, including security categories, content categories and custom lists.
  3. Compares it with Cisco Talos threat intelligence.
  4. Resolves the domain if it is allowed, or returns the address of a block page if not.

Because this happens at the DNS layer, a device never connects to a blocked destination. Anycast routing sends each request to the nearest of Cisco’s 50+ data centres, which keeps latency low.

Some domains are neither clearly safe nor clearly malicious. In the DNS Advantage tier, these risky domains go through Umbrella’s intelligent proxy, which inspects the specific URL.

The SIG packages go further. Traffic reaches Umbrella through IPsec tunnels, PAC files or Secure Client, then passes through a cloud firewall, a web proxy with optional HTTPS decryption and malware scanning, and data loss prevention.

Still have a question?

Cloudbrink’s team can walk through how your current deployment maps across.