Umbrella DNS Security Advantage
DNS protection has reduced phishing risks but endpoint bypass remains a concern
What is our primary use case?
My main use case for Cisco Umbrella is to protect DNS queries that are going outside to the internet. When I open Cisco Umbrella, the first thing I do is watch the dashboard to analyze what the traffic looks like in the last 24 hours, how many malicious queries have been blocked, what the valid usages are, and how many blacklisted URLs have hits.
The scope of monitoring Cisco Umbrella involves two or three people or some people in the SOC team doing the monitoring. Cisco Umbrella is used company-wide.
What is most valuable?
From my experience using Cisco Umbrella, one of the best features is that it provides protection for the endpoints even while off the network, which means that if you are working from home, your DNS queries are protected well enough, with the caveat that it only protects DNS queries but does not work well when accessing something via IP address.
Cisco Umbrella has definitely helped improve some aspects of our security posture, contributing to overall organizational security posture management. I have seen improvements in that it cut down on malicious traffic; if there is a new domain registered by a malicious actor or hacker, it is quickly detected by Cisco Umbrella. For instance, there was a phishing link we discovered, and we blocked it in Cisco Umbrella, ensuring anyone trying to access that domain would be blocked, which is a critical feature even when off the network.
What needs improvement?
The biggest frustration I have encountered with Cisco Umbrella is that people can exit the Cisco Umbrella roaming client to bypass security, and some technically savvy individuals might know how to bypass it by modifying the hosts file to exclude Cisco Umbrella.
If I could change one thing about Cisco Umbrella, it would be to include traffic for DNS resolution even on IP addresses for extra protection and to enhance the analysis capabilities, considering the advancements in AI.
During implementation, there were not really any features that we are not using today, but SSL inspection was something we never enabled due to requiring extensive approval and legality considerations.
For how long have I used the solution?
I have been familiar with Cisco Umbrella for almost one year.
Which solution did I use previously and why did I switch?
Before adopting Cisco Umbrella, we did not have any tool and only used the firewall as a prevention tool, mostly relying on next-generation antivirus focused on behavioral analytics.
What about the implementation team?
In terms of implementation, Cisco Umbrella is more of a SaaS tool, and configuring in the SaaS tool on the cloud is simple and quick; however, to protect the endpoints, deploying the clients on the endpoints is time-consuming. Configuring policies and downloading the client is easy, perhaps a one or two day task, but deploying the clients to all the endpoints definitely takes more time.
What other advice do I have?
When evaluating options, I was not involved in the POC of Cisco Umbrella; I was a part of the engineering team that deployed it.
My team did need a small interaction with team members to explain the use cases implemented in Cisco Umbrella, which was important, and the knowledge base articles available on the Cisco website were good and useful to have handy.
My advice for someone considering Cisco Umbrella, based on my experience over the past year, is to understand your clear business requirements, check all the required features, and note that Cisco Umbrella provides good DNS security, though there are other competitive tools, such as Zscaler, which address the challenges I noticed in Cisco Umbrella. Based on your requirements and budget, analyze the tool during the POC and finalize your choice. I would rate my overall experience with Cisco Umbrella as a seven out of ten.
Straightforward Policy Creation with Templates Across Cloud Proxy and Prisma
Reliable DNS-Level Protection Anywhere, with Windows Agent and Mobile App
Light weight content filter
Proactive Security and Seamless Integration
Powerful Threat Management, Needs Better Search Functionality
Secure browsing has protected users from DNS threats and improves malware defense
What is our primary use case?
In a previous organization at HBL, we were using Cisco Umbrella as well, so it has been a quite long time.
What is most valuable?
Cisco Umbrella is specifically designed for DNS protection, with features including a user-friendly console and the easiest installation. It offers very prominent threat feeding from different Talos sources, securing multiple platforms. Cisco Umbrella helps protect from malware and unsafe sites. It is especially useful in mitigating DNS attacks and ensuring secure browsing for end users.
What needs improvement?
The major issue is that sometimes when you install the client, it shows you protected and displays that it is live with the backend servers and everything. However, in reality, it was not getting any feed from the main client and is just sending your traffic to open DNS, which sometimes causes an issue because the protection you have implemented can be breached by users.
The primary thing that Cisco Umbrella lacked most of the time is their client. Previously, they had a separate Cisco client. Now they have merged everything into the Cisco Secure Endpoint client—one client for everything, for Cisco Endpoint, for Cisco AnyConnect, and for Cisco Umbrella, which they did probably in 2025.
For how long have I used the solution?
I have been using this solution for almost two years.
What do I think about the stability of the solution?
As a customer, I have never been satisfied with any product for a longer period of time, so that is a tricky question to answer.
What do I think about the scalability of the solution?
If you require 10 clients or however many you need or whatever expansion you require, they are just a click away.
How are customer service and support?
Cisco is always known for their best technical support, so there is no doubt about it.
Which solution did I use previously and why did I switch?
At that time I was working in HBL on the Symantec DLP product.
How was the initial setup?
Cisco Umbrella is specifically designed for DNS protection, and the features they have include a user-friendly console and probably the easiest installation.
Which other solutions did I evaluate?
If you go with the main competitor product, there is no doubt that Infoblox is the best product.
What other advice do I have?
There are a couple of products we are working on. We use Cisco EDR and XDR, for DLP we have Forcepoint, and for cyber threat intelligence, we have EPP.
We focus on DLP and the classification tool, which is for data visibility and DLP. It is kind of data protection that is used for classification.
For Cisco, we use FTDs. It is the Cisco Secure Endpoint, which is known as Cisco EDR, Endpoint Detection and Response.
We use Cisco Umbrella for DNS protection. In the current environment, cyber security resolves your addresses securely and protects from threats from outside. Most attacks happen over DNS, so those DNS queries can be mitigated if you have a secure way for browsing for your end users.
We are not using Cisco Umbrella for the proxy. We are using it from our DNS perspective. As a strategy, we are using it for outside communication through the DNS resolver. However, Cisco Umbrella has now combined with Secure Access, which comes with different features. Previously, Cisco had WSA for the proxy. Now they have come up with a proxy solution that gives Cisco Umbrella protection with remote proxy and cloud proxy solution, which is known as Secure Access.
As I mentioned earlier, they have very prominent threat feeding from different Talos sources, securing us on multiple platforms where, as an enterprise, you might not have those features and the feed to protect yourself. Cisco Umbrella is definitely a good product from that perspective and is going to help you protect from malware and from sites which are reputedly not marked as safe for the user. I would rate this review an eight out of ten.
Great product for DNS Security and intrinsic component for Cisco's Zero Trust - SASE infrastructure.
Reliable Cloud Security and DNS Protection with Easy Deployment
Has required extensive customization for non-technical users and still needs better simplification
What is our primary use case?
The main use case for Cisco Umbrella is to protect our clients from various threats as it works on the DNS layer while firewalls and other security appliances work differently. We trust that no client should access any unverified website since it protects on the DNS layer to ensure their safety from malware and unknown sites. The Cisco Umbrella denies requests to untrusted websites, ensuring our clients are protected; we use it along with Hunters and firewalls for three layers of protection.
Cisco Umbrella is the first layer of security that protects me while surfing the net, identifying untrusted websites to prevent access. It guards against inside threats, while firewalls provide broader protection; Cisco Umbrella is especially useful for non-technical users who may not understand the risks.
What is most valuable?
Cisco Umbrella provides main benefits by not being too costly compared to other products, making it accessible for all clients, and I think it is essential for those who want complete safety.
The Intelligent Proxy feature of Cisco Umbrella is useful, though we do not elaborate much on this proxy feature.
The reporting and analytics capabilities in Cisco Umbrella are helpful, but since we have many clients, we cannot fully analyze everything. If any client objects to a website being protected, we analyze it and suggest whether they should proceed or not.
What needs improvement?
Customization for basic users can be complex, as it is targeted toward only technical users.
It would be beneficial if Cisco simplifies the customization process while still ensuring strong security to prevent unauthorized access.
Simplifying the customization part could enhance Cisco Umbrella, but overall, it is a good solution for me.
For how long have I used the solution?
I have been working with Cisco Umbrella for the last year, not more than a year.
What do I think about the stability of the solution?
I would rate the stability of Cisco Umbrella nine out of ten.
What do I think about the scalability of the solution?
For scalability, I would rate it nine out of ten, as the product is good.
The solution cannot be scaled because it serves primarily as endpoint security.
For enterprise-level companies, it is easy to expand the number of users as they provide a dashboard that allows monitoring and solution delivery for all clients in one place.
How are customer service and support?
Whenever we ask Cisco for support, they definitely provide it, and we create a ticket for any threats we encounter that bypass their system.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup for Cisco Umbrella is simple; you just download the application, input the license, and use it without needing complex servers.
What about the implementation team?
For clients who do not know how to set up Cisco Umbrella, we do the setup for them, and they trust us.
Which other solutions did I evaluate?
I still have not found a main competitor for Cisco Umbrella.
Once I find a better solution among prices, I may switch over, but I currently do not think its price is too much.
What other advice do I have?
Cisco Umbrella is a supportive solution I provide separately, depending on the requirements of the customer, and we ask them what they require first.
Cisco is continuously improving Cisco Umbrella, experimenting with better versions while keeping us informed about changes and upgrades at no cost.
Cisco Umbrella should be available on desktop or laptop to ensure trust and security for non-technical users.
I rate Cisco Umbrella nine out of ten.