Umbrella DNS Security Advantage logo

    Umbrella DNS Security Advantage

    The leader in DNS-layer security As a trusted partner of over 24,000 companies, Cisco Umbrella provides the quickest, most effective way to improve your security stack. Gain a new layer of breach protection in minutes, with internet-wide visibility on and off your network, no matter your company size.

    Ratings and reviews

    4.4
    311 ratings
    66%
    28%
    5%
    1%
    0%
    2 AWS reviews
    |
    309 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (311)
    reviewer2846889

    Dns protection has improved off-network security but still needs stronger bypass controls

    Reviewed on May 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main use case for Cisco Umbrella in my work is to protect the DNS queries going outside to the internet.

    What is most valuable?

    One of the best things I appreciate about Cisco Umbrella is that it provides protection for endpoints even while you are off the network and not behind the firewall. If you are working from home, your DNS queries are protected effectively, though there is one caveat: it only protects DNS queries. If you are accessing something via IP address, it does not work as well. IP protection is not blocked by Cisco Umbrella, but DNS queries are, and it works well for endpoints protected even from a public network.

    Cisco Umbrella has definitely improved the security posture and the overall organization security posture management.

    What needs improvement?

    The only frustration I have with Cisco Umbrella is that people can exit the Umbrella roaming client to bypass the security. Some people who are technical can bypass it by putting the IP address into the host file. These are a few things which sometimes become frustrating when people try to bypass the Umbrella protection.

    If I could change one thing about Cisco Umbrella to improve that situation, I would include traffic for DNS resolution even on IP addresses to give extra protection on that layer and conduct deeper analysis. Considering AI, which is evolving rapidly, I would suggest including AI as an integration into Cisco Umbrella.

    For how long have I used the solution?

    I have been familiar with Cisco Umbrella for almost one year.

    Which solution did I use previously and why did I switch?

    Before we adopted Cisco Umbrella, we did not have any tool. We only used the firewall as a prevention tool and mostly relied on next-generation antivirus which looks at behavioral analytics.

    How was the initial setup?

    When I first implemented Cisco Umbrella, it took a simple and quick configuration in the SaaS tool on the cloud. To protect the endpoints, we need to deploy the clients on the endpoints, which is time-consuming. Configuring policies and downloading the client is easy, perhaps a one or two-day task, but deploying the clients to all the endpoints definitely takes time.

    What about the implementation team?

    I was not involved in the POC of Cisco Umbrella, but I was part of the engineering team who deployed it.

    Which other solutions did I evaluate?

    My advice for someone considering Cisco Umbrella, based on my experience over the past year, is to understand your clear business requirements. Definitely check for all the required features. Cisco Umbrella is good for DNS security, but there are many other competitive tools in the market such as Zscaler that overcome the challenges I saw in Cisco Umbrella. Based on your requirements, cost, and budget, analyze the tool during the POC and finalize it.

    What other advice do I have?

    The first thing that we do when we open Cisco Umbrella is watch the dashboard, which shows the traffic analysis, what traffic looked like in the last 24 hours, how many malicious queries have been blocked, what the valid usages are, how many blacklisted items there are, and how many URLs that we have blocked have hits. That is how we conduct day-to-day analysis of it.

    The scope of monitoring Cisco Umbrella involves two or three people or some people in the SOC team who do the monitoring.

    My team needed a small interaction just to explain how the use cases that we implemented in Cisco Umbrella work, which was something important. The knowledge base article available on the Cisco website was good enough and useful to have on hand.

    Cisco Umbrella was used company-wide.

    The only feature I think about is SSL inspection, which we never enabled because it requires lots of approval and legality.

    I have seen improvement in that Cisco Umbrella has cut down on malicious traffic. If there is any new domain registered by a malicious actor or hacker, it was quickly detected by Cisco Umbrella. There was some phishing link that we got to know about and blocked in Cisco Umbrella, so anyone getting that phishing link and trying to reach that domain would be blocked. This feature is especially effective even when you are off the network. I would rate this review seven out of ten.

    reviewer2015976

    DNS protection has reduced phishing risks but endpoint bypass remains a concern

    Reviewed on May 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Cisco Umbrella is to protect DNS queries that are going outside to the internet. When I open Cisco Umbrella, the first thing I do is watch the dashboard to analyze what the traffic looks like in the last 24 hours, how many malicious queries have been blocked, what the valid usages are, and how many blacklisted URLs have hits.

    The scope of monitoring Cisco Umbrella involves two or three people or some people in the SOC team doing the monitoring. Cisco Umbrella is used company-wide.

    What is most valuable?

    From my experience using Cisco Umbrella, one of the best features is that it provides protection for the endpoints even while off the network, which means that if you are working from home, your DNS queries are protected well enough, with the caveat that it only protects DNS queries but does not work well when accessing something via IP address.

    Cisco Umbrella has definitely helped improve some aspects of our security posture, contributing to overall organizational security posture management. I have seen improvements in that it cut down on malicious traffic; if there is a new domain registered by a malicious actor or hacker, it is quickly detected by Cisco Umbrella. For instance, there was a phishing link we discovered, and we blocked it in Cisco Umbrella, ensuring anyone trying to access that domain would be blocked, which is a critical feature even when off the network.

    What needs improvement?

    The biggest frustration I have encountered with Cisco Umbrella is that people can exit the Cisco Umbrella roaming client to bypass security, and some technically savvy individuals might know how to bypass it by modifying the hosts file to exclude Cisco Umbrella.

    If I could change one thing about Cisco Umbrella, it would be to include traffic for DNS resolution even on IP addresses for extra protection and to enhance the analysis capabilities, considering the advancements in AI.

    During implementation, there were not really any features that we are not using today, but SSL inspection was something we never enabled due to requiring extensive approval and legality considerations.

    For how long have I used the solution?

    I have been familiar with Cisco Umbrella for almost one year.

    Which solution did I use previously and why did I switch?

    Before adopting Cisco Umbrella, we did not have any tool and only used the firewall as a prevention tool, mostly relying on next-generation antivirus focused on behavioral analytics.

    What about the implementation team?

    In terms of implementation, Cisco Umbrella is more of a SaaS tool, and configuring in the SaaS tool on the cloud is simple and quick; however, to protect the endpoints, deploying the clients on the endpoints is time-consuming. Configuring policies and downloading the client is easy, perhaps a one or two day task, but deploying the clients to all the endpoints definitely takes more time.

    What other advice do I have?

    When evaluating options, I was not involved in the POC of Cisco Umbrella; I was a part of the engineering team that deployed it.

    My team did need a small interaction with team members to explain the use cases implemented in Cisco Umbrella, which was important, and the knowledge base articles available on the Cisco website were good and useful to have handy.

    My advice for someone considering Cisco Umbrella, based on my experience over the past year, is to understand your clear business requirements, check all the required features, and note that Cisco Umbrella provides good DNS security, though there are other competitive tools, such as Zscaler, which address the challenges I noticed in Cisco Umbrella. Based on your requirements and budget, analyze the tool during the POC and finalize your choice. I would rate my overall experience with Cisco Umbrella as a seven out of ten.

    Subhajji S.

    Straightforward Policy Creation with Templates Across Cloud Proxy and Prisma

    Reviewed on May 09, 2026
    Review provided by G2
    What do you like best about the product?
    Creating policies using templates is straightforward. You can create user-based policies that apply on the cloud proxy, and you can do the same on Prisma as well.
    What do you dislike about the product?
    The Umbrella selected proxy feature felt unreliable. It sometimes allows URL access, but other times it blocks the same URLs, and we couldn’t whitelist them. We got stuck in that situation.
    What problems is the product solving and how is that benefiting you?
    Cloud proxy with URL blocking and whitelisting, helping safeguard the environment over a VPN network.
    Aman A.

    Reliable DNS-Level Protection Anywhere, with Windows Agent and Mobile App

    Reviewed on Apr 23, 2026
    Review provided by G2
    What do you like best about the product?
    It does what it states. Protection at a DNS level, it has its own agent for Windows and app for mobile. Where you are connected to office network or not, you are still protected. A great layer of defense on top of AV systems.
    What do you dislike about the product?
    Cannot thick of anything. Just because you are working at a DNS layer. You need to know what you are configuring to avoid any service disruption.
    What problems is the product solving and how is that benefiting you?
    It adds defense in depth in our environment. This way we are not just relying on AV. It also adds great visibility in the AI world where everyone wants to access all the AI websites out there. Also they are pretty fast in updating their database about new websites.
    Information Technology and Services

    Light weight content filter

    Reviewed on Apr 09, 2026
    Review provided by G2
    What do you like best about the product?
    Creating policies and testing policies is a breeze
    What do you dislike about the product?
    Mostly cost, and its proxying behavior did negatively impact some traffic.
    What problems is the product solving and how is that benefiting you?
    URL filtering on the corporate network and outside of it.
    Dnyanesh M.

    Proactive Security and Seamless Integration

    Reviewed on Apr 05, 2026
    Review provided by G2
    What do you like best about the product?
    I really appreciate Cisco Umbrella for its proactive nature in blocking DNS hits to malicious websites. It does a wonderful job by maintaining a list of malicious links and promptly blocking them when an unaware employee clicks on such links. This feature is very proactive and helps safeguard our organization from malicious exposure. I also find the DNS management aspect impressive, as Cisco handles all the technical parts, making it easy for us to just plug the solution into our endpoints and ensure everything is safeguarded. The onboarding process was pretty straightforward with neat documentation, and using the cloud-based solution made it perfect and easy to deploy. I must say, I rate it 10 out of 10 for recommendations.
    What do you dislike about the product?
    There was a lack of AI innovation in Cisco Umbrella. When I was using it, there was no AI in that solution. That's something they can improve on. FYI I used cisco unbrella from 2021 to early 2025. They may have improved in this space in last 2 year.
    What problems is the product solving and how is that benefiting you?
    Cisco Umbrella secures DNS by managing blacklist and malicious website lists, saving us the complexity and cost of doing it manually. It proactively blocks threats, safeguarding our employees from malicious exposure with ease of setup and integration into our systems.
    MANI CHANDRA T.

    Powerful Threat Management, Needs Better Search Functionality

    Reviewed on Mar 24, 2026
    Review provided by G2
    What do you like best about the product?
    I like Cisco Umbrella because its interface is neat and makes finding options easy. It's also straightforward to block things globally. Plus, it's easy to set up.
    What do you dislike about the product?
    Search options need to be improved since I can't search the required URLs easily. Smarter filtering options like user + device + location together would help.
    What problems is the product solving and how is that benefiting you?
    I use Cisco Umbrella to block malicious domains and URLs, check on malicious URL clicks, and access reports on high phishing links, enhancing our cyber team's security.
    KamranJameel

    Secure browsing has protected users from DNS threats and improves malware defense

    Reviewed on Feb 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    In a previous organization at HBL, we were using Cisco Umbrella as well, so it has been a quite long time.

    What is most valuable?

    Cisco Umbrella is specifically designed for DNS protection, with features including a user-friendly console and the easiest installation. It offers very prominent threat feeding from different Talos sources, securing multiple platforms. Cisco Umbrella helps protect from malware and unsafe sites. It is especially useful in mitigating DNS attacks and ensuring secure browsing for end users.

    What needs improvement?

    The major issue is that sometimes when you install the client, it shows you protected and displays that it is live with the backend servers and everything. However, in reality, it was not getting any feed from the main client and is just sending your traffic to open DNS, which sometimes causes an issue because the protection you have implemented can be breached by users.

    The primary thing that Cisco Umbrella lacked most of the time is their client. Previously, they had a separate Cisco client. Now they have merged everything into the Cisco Secure Endpoint client—one client for everything, for Cisco Endpoint, for Cisco AnyConnect, and for Cisco Umbrella, which they did probably in 2025.

    For how long have I used the solution?

    I have been using this solution for almost two years.

    What do I think about the stability of the solution?

    As a customer, I have never been satisfied with any product for a longer period of time, so that is a tricky question to answer.

    What do I think about the scalability of the solution?

    If you require 10 clients or however many you need or whatever expansion you require, they are just a click away.

    How are customer service and support?

    Cisco is always known for their best technical support, so there is no doubt about it.

    Which solution did I use previously and why did I switch?

    At that time I was working in HBL on the Symantec DLP product.

    How was the initial setup?

    Cisco Umbrella is specifically designed for DNS protection, and the features they have include a user-friendly console and probably the easiest installation.

    Which other solutions did I evaluate?

    If you go with the main competitor product, there is no doubt that Infoblox is the best product.

    What other advice do I have?

    There are a couple of products we are working on. We use Cisco EDR and XDR, for DLP we have Forcepoint, and for cyber threat intelligence, we have EPP.

    We focus on DLP and the classification tool, which is for data visibility and DLP. It is kind of data protection that is used for classification.

    For Cisco, we use FTDs. It is the Cisco Secure Endpoint, which is known as Cisco EDR, Endpoint Detection and Response.

    We use Cisco Umbrella for DNS protection. In the current environment, cyber security resolves your addresses securely and protects from threats from outside. Most attacks happen over DNS, so those DNS queries can be mitigated if you have a secure way for browsing for your end users.

    We are not using Cisco Umbrella for the proxy. We are using it from our DNS perspective. As a strategy, we are using it for outside communication through the DNS resolver. However, Cisco Umbrella has now combined with Secure Access, which comes with different features. Previously, Cisco had WSA for the proxy. Now they have come up with a proxy solution that gives Cisco Umbrella protection with remote proxy and cloud proxy solution, which is known as Secure Access.

    As I mentioned earlier, they have very prominent threat feeding from different Talos sources, securing us on multiple platforms where, as an enterprise, you might not have those features and the feed to protect yourself. Cisco Umbrella is definitely a good product from that perspective and is going to help you protect from malware and from sites which are reputedly not marked as safe for the user. I would rate this review an eight out of ten.

    Tejas J.

    Great product for DNS Security and intrinsic component for Cisco's Zero Trust - SASE infrastructure.

    Reviewed on Oct 11, 2025
    Review provided by G2
    What do you like best about the product?
    Implemented Cisco Umbrella as our de-facto DNS security solution for outbound internet traffic. Saw immediate wins, by seeing drastic reduction in number of the DNS requests towards crypto mining sites, CnC sites. Helped enforce domain based filtering, providing domain reputation scores (which fed into TPRM assessments) for partners. Ease of use (all you need to do is configure Cisco Umbrella as DNS forwarder) .Easy to implement as all you need to do is configure the Cisco Umbrella anycast IPs as DNS forwarder. Cisco's customer support is proactive, however there are typically no issues considering the platform is fairly stable. The domain whitelisting / re-categorization turn around time is typically quick between 24-36 hours, for most of the cases we had. Easy to integrate with Cisco SIG, easy to implement the Cisco VAs, on different form factors - vSphere / AWS cloud, etc.
    What do you dislike about the product?
    There is no integration between Cisco Umbrella with third party next generation firewalls such as Palo Alto firewalls / Prisma Access or Fortinet firewalls, which implies that the encrypted channel established between Cisco Virtual Appliances (VAs) and Umbrella cloud cannot be decrypted if SSL decryption is enabled on the perimeter firewall.
    What problems is the product solving and how is that benefiting you?
    Securing DNS for both data center, cloud workloads and users in the corporate offices and remote users - roaming clients. Helped implement a uniform security posture for users and workloads irrespective of the location. Integrated with Cisco Talos which ensures real time threat intel feeds.
    Anthony Manuel B.

    Reliable Cloud Security and DNS Protection with Easy Deployment

    Reviewed on Sep 24, 2025
    Review provided by G2
    What do you like best about the product?
    Cisco Umbrella is very effective at providing DNS-layer protection, blocking malicious domains before threats can reach users or devices. The cloud-based approach makes deployment and scaling extremely simple, with minimal infrastructure overhead. The reporting dashboards are intuitive and provide valuable insights into threat activity, allowing administrators to act quickly. Integration with other Cisco products also strengthens the overall security ecosystem and enhances visibility across the network.
    What do you dislike about the product?
    While Cisco Umbrella is powerful, the pricing can be a barrier for smaller organizations, as costs increase with scale. Some advanced policy configurations require additional expertise to fine-tune properly. In addition, reporting customization could be more flexible to allow deeper drill-downs. Despite these points, the platform remains highly effective for enterprise-level protection.
    What problems is the product solving and how is that benefiting you?
    Cisco Umbrella helps our organization block malicious domains at the DNS layer, reducing the risk of phishing, malware, and ransomware attacks before they ever reach users or endpoints. It also provides secure web gateway capabilities, ensuring that all internet-bound traffic is inspected and controlled, even for remote or roaming users. This has improved our overall security posture, minimized incidents, and simplified policy enforcement across distributed teams. The centralized dashboard also provides valuable insights and reporting, which saves time during investigations and compliance audits.