We used to access list remote login to the switches for only network admin from specific vlan. And allow some vendor server to connect for snmp messages. This has allowed us to monitor with external vendor while keeping security tight and audit for users. In other hand we had to use external solution for NAC
It is good for whole network protection, and individual PCs with the client. Provide good reporting on where your network is going on the net. One thing I would like is a longer history with the logs 14 and 30 days are too short some times.
So for example, we had the problem in the past. We are connecting users to our own managed data centers. We had seven locations around the world, put them with Cisco, any connect to our on-prem data center and let them out to the internet. So that's causing some high latency bad experiences with teams and so on. And with Umbrella we can directly connect the user to the cloud and to the internet so the users have a good experience with speed with latency and it's much better than back hauling the traffic to their own company and then processing them there.
Cisco could provide an initial set up script for those are not used to the CLI (Command Line Interface). With that initial script, people could easily deploy the security features instead of having to learn how to use the commands.
The web interface that Cisco provides with the routers, although it’s useful to set up the security features, it could also have some sort of tutorials to help people understand the main concepts of iOS security.
You have to license iOS security separately from the main OS. For that reason, sometimes it tends to be a little expensive if you have a small business.
The smart search feature in Cisco Umbrella is great addition for sure which helps us to identify malicious domain just by searching the URL and there is scoring system of Cisco Umbrella which mark the URL in low, medium and high risk. Sometimes Cisco Umbrella mark well known and good domain as malicious whether sometimes they mark malicious sites/domain as low risk. So, it's something that they should focus on, I think.
The live activity search is great for checking internet activities, but the filtering options could be improved. It would be helpful if we could filter by multiple parameters at once like combining username, destination IP and time range.
First off I never give anything a "10" unless it's perfect. LOL - I grade on the curve. I think OpenDNS/Umbrella is a very good product. I think that fact that Cisco absorbed them is one of the proofs of that. I have used the product back when it was free for companies our size. I have not always appreciated the cost - but in the post pandemic cyber chaos, I believe the cost benefit ratio is still very high. I have honestly not looked at other products because Umbrella continues to work to my satisfaction. I consider Umbrella to be one of the key layers in my cyber security strategy.
Cisco IOS Security usibility require a network administrator or an engineer with CCNA knowledge to know how to handle and configure Cisco IOS Security. The Cisco IOS Security usability once you know your way is smooth and very helpful. Even for new commands you can just type question mark and the new commands will pop on the screen.
Better features and easy to manage system with great customer support and overall usability is great as it works for hybrid environment with ease as it is having features for on prem users as wells as cloud users with great customer support and great team of trained engineers to support our opeartions.
Cisco umbrella services in the cloud are always available. However, the weakness is the VM installed in the data center that are the first resolvers. If the VMs become unavailable for any reason or the vSphere goes down, then all DNS is affected
our experience with cisco products has always been awesome and same is the case with cisco umbrella .Under umbrella cisco provides flexible and scalable software solution to use across different dept and sites . These softwares are very user friendly ,pages load quickly as these applications are designed for minimum latency and reports are also provided quickely
Cisco has the best Support team that gives us 24/7 support as we need. Cisco has huge detailed documentation for design, implementation, and troubleshooting all areas of the IOS security. There are many communities discussing all Cisco devices and solutions for studying groups and for customers to share their stories, technical problem and solutions.
Whilst the support is good once you get through to them, it's email only and the response is slow. This is a issue, because its a core system that needs to work. We have had issues in the past where several of our companies have gone down due to Umbrella and support is nowhere to be seen. It is very difficult to know whether Umbrella is having service issues, since they do not regularly update customers on the status of their services, such as is seen by providers such as Microsoft (status.umbrella.com just seems to show up all of the time, I'm not sure it's even updated)
Quite easy to understand training modules prepared by knowledgeable trainers. Training modules have included all the desired features of these softwares and the content delivery is very good from the respective module trainers and it explains in details the features and apart from that further training material support is also provided if needed.
At the time we were forced to move from Cloud Web Security to Cisco Umbrella, Cisco Umbrella was far from being a direct replacement. It was frustrating and difficult to migrate due to the lack of functionality. This has since been addressed, however we now have legacy rulesets that were built as bandaids that cannot be removed. Hopefully the migration to Secure Access will address this.
IOS Security is a bonus feature when you purchase Cisco devices. It is great to have a vendor provide equipment to go above and beyond the minimal needs for business operation. Having security at the downstream edge of our organization provides a sense of ease from potential attacks.
Different products in different spaces. The Z3 was more of a VPN endpoint so that users didn't have to worry about a client. If they are at home, they are on their corporate network and able to access resources. Cisco Umbrella can be used then to serve corporate DNS across the VPN tunnel to the Z3 device and extend the capabilities of Cisco Umbrella.
Cisco umbrella provides fleaxible and scalable software solutions which are easy deploy across multiple departments and sites wherever needed and this softwares are very easy to use and provides the best interface along with cisco support for other devices apart from cisco infrastructure but still there is scope for improvement on the inclusion of latest features
So it's always very hard to calculate return on investment, especially on security and especially in a physical product. So it's not like I'm going to be selling a lot more plastic or a lot more aviation fuel because I implemented Cisco Umbrella. What I know is that definitely, the return on investment is on the ability of the business to continue to run and give the assurance that our users are safe.