Why is Cisco Umbrella inactive?

Cisco Umbrella often shows as inactive or disabled on purpose. The Umbrella module in Cisco Secure Client, like the older roaming client it replaced, is designed to step back when another layer is already protecting the device.

The most common reasons are:

  • Protected network. On a network already sending DNS to Umbrella, or behind an Umbrella virtual appliance, the client disables itself to avoid double filtering and turns back on when the device leaves.
  • Trusted network. The web security module can show “Disabled (Trusted Network)” on a network defined as trusted.
  • VPN connection. On a full-tunnel VPN, Umbrella may show “Disabled (VPN Connection)” and let the VPN’s DNS take over.
  • Blocked DNS. If a firewall stops traffic to 208.67.222.222 and 208.67.220.220 on ports 53 or 443, the client cannot reach Umbrella and shows as unprotected or unencrypted.
  • Registration problems. A missing or incorrect OrgInfo.json file, or a fingerprint mismatch, prevents the device registering with your organisation.
  • Corrupted configuration. A damaged local config file can leave the module stuck in a disabled state.

To troubleshoot, check the module status in Secure Client, confirm which network the device is on, and test DNS reachability with nslookup. If registration looks wrong, deploying a fresh OrgInfo.json and clearing the Umbrella data folder usually fixes it. Administrators can also check the device’s last sync time in the Umbrella dashboard.

Still have a question?

Cloudbrink’s team can walk through how your current deployment maps across.