What are some common issues with Cisco Umbrella?

Most Cisco Umbrella issues trace back to how DNS filtering and HTTPS inspection interact with other software.

  • Internal domains not resolving. If internal hostnames are not added to the Internal Domains list, Umbrella tries to resolve them publicly and they fail.
  • VPN conflicts. Cisco lists several VPN clients, including OpenVPN, F5, SonicWall NetExtender, Zscaler, Azure VPN and Pritunl, as incompatible with the legacy roaming client.
  • Certificate errors. Blocked HTTPS sites can show a browser certificate warning instead of a block page, especially sites using HSTS, unless the Cisco root certificate is installed.
  • Broken apps under HTTPS inspection. Apps that use certificate pinning may fail when the web proxy decrypts their connections.
  • DNS-over-HTTPS bypass. Browsers set to use their own encrypted DNS provider can skip Umbrella’s DNS-layer protection.
  • Software conflicts. Local DNS tools such as DNSMasq, some VoIP clients and certain USB network adapters can interfere with the client.
  • False positives. Legitimate sites occasionally land in a security category and need allowlisting or reclassification.

Beyond technical issues, reviewers often mention cost, features limited to higher tiers, a slow dashboard and complex policy setup.

A newer issue is lifecycle. The legacy roaming client reached end of support in April 2025, and Cisco has announced end of sale for Umbrella DNS and SIG on 31 January 2027. Running unsupported components is a growing risk, so it is worth confirming every device is on Cisco Secure Client and planning the move to Secure Access.

Still have a question?

Cloudbrink’s team can walk through how your current deployment maps across.