Why is Cisco Umbrella blocking websites?

Cisco Umbrella blocks a website when a DNS request, or a web request in SIG deployments, matches a rule in your organisation’s policy. The block page usually shows which category triggered it.

The most common reasons are:

  • Security category. The domain is classified as malware, phishing, command-and-control or another threat type, based on Cisco Talos intelligence.
  • Content category. Your organisation blocks a category such as social media, gambling, streaming or adult content.
  • Destination list. An administrator has added the domain to a custom block list.
  • Application control. A rule blocks a specific cloud application or activity.
  • A different policy. The device or user matched a stricter policy than expected, for example because of the network it is on or its Active Directory group.
  • False positive. A legitimate site has been miscategorised.

If you see a certificate warning instead of a block page, the site is still being blocked. HTTPS sites using HSTS cannot display the Umbrella block page unless the Cisco root certificate is installed on the device.

If a site is blocked in error, send your IT team the URL and the time it happened. Administrators can use Activity Search to see which policy and category applied, add the domain to an allow list, or ask Cisco to reclassify it.

If you are not on a managed device, Umbrella may be applied by the network you are using, such as school or office Wi-Fi, so the block will disappear on a different connection.

Still have a question?

Cloudbrink’s team can walk through how your current deployment maps across.