Is Cisco Umbrella a firewall?

Cisco Umbrella is not a traditional firewall, although some packages include a cloud-delivered firewall.

The DNS Essentials and DNS Advantage packages provide DNS-layer security. They decide whether a domain can be resolved, based on threat intelligence and policy. This is sometimes called a “DNS firewall”, but it does not inspect ports, protocols or packets, and it cannot stop a connection made directly to an IP address.

The SIG packages add firewall capabilities:

  • SIG Essentials includes a cloud-delivered firewall with Layer 3 and Layer 4 rules based on IP address, port and protocol.
  • SIG Advantage adds Layer 7 application control and intrusion prevention powered by Snort 3.

Traffic reaches this cloud firewall through IPsec tunnels from branch offices or on-site firewalls. It is designed to control outbound internet traffic from users and branches, not to protect inbound traffic to your servers or segment your internal network.

That means Umbrella complements an on-premises next-generation firewall rather than replacing it. Most organisations keep a perimeter or data centre firewall and use Umbrella to extend consistent internet security to remote users and branches.

Keep lifecycle in mind too. The SIG and DNS packages are scheduled for end of sale on 31 January 2027 as they move into Cisco Secure Access. Cisco’s end-of-life notice lists some firewall items, such as the Layer 7 cloud firewall, without a direct migration path, so check how your current rules will map before you migrate.

Still have a question?

Cloudbrink’s team can walk through how your current deployment maps across.