We did not evaluate any other products as Cisco Umbrella was perfect and already part of the Cisco eco system, so things like native API integration made it a easy decision.
Well suited to networks that include Active directory, as you can hook it into the directory to allow you to target specific users and computers. Not particularly well suited to personal users due to the price point, and also not well suited to organisations with disorganised IT, since the system can be bypassed simply by changing the DNS server of the device. You need a dedicated IT department to ensure these sorts of settings are locked down
FortiGuard Web Filtering Service is well-suited for an organisation that is able to funnel all its Internet connectivity through one device, i.e., the office environment - or perhaps where WFH workers are using a remote desktop or VPN. It allows management/IT to minimise risk by blocking websites that may be harmful, as well as websites that may enable data leakage, or even are websites that people ought not to be visiting in the workplace.
Umbrella Virtual Appliances have been buggy in resolving local domain hosts.
Integration between other Cisco and Meraki products is complicated.
Reporting is not always accurate; for example, if you configure a Meraki access point to use an Umbrella Virtual Appliance, you lose device reporting. All reporting shows up under the AP's IP.
Some websites are classified as Meaningless content, especially links used in emails to unsubscribe from lists. Luckily FortiGuard Web Filtering Service is responsive about reclassifying those quickly.
First off I never give anything a "10" unless it's perfect. LOL - I grade on the curve. I think OpenDNS/Umbrella is a very good product. I think that fact that Cisco absorbed them is one of the proofs of that. I have used the product back when it was free for companies our size. I have not always appreciated the cost - but in the post pandemic cyber chaos, I believe the cost benefit ratio is still very high. I have honestly not looked at other products because Umbrella continues to work to my satisfaction. I consider Umbrella to be one of the key layers in my cyber security strategy.
Better features and easy to manage system with great customer support and overall usability is great as it works for hybrid environment with ease as it is having features for on prem users as wells as cloud users with great customer support and great team of trained engineers to support our opeartions.
Cisco Umbrella's availability was great, they got back to me in less than an hour to get my problem solved.
We needed to get our Meraki AP's hooked up to Cisco Umbrella to monitor that specific traffic and they got back to me promptly, they guided me and explained every question I had.
We have not had a chance to use Cisco support frequently, but when we needed to troubleshoot some issues that we were having with the agent installation, the support was very responsive and the solution that they offered worked. The only reason I give it one less point is that the turnaround time for non-critical issues is very long.
At the time we were forced to move from Cloud Web Security to Cisco Umbrella, Cisco Umbrella was far from being a direct replacement. It was frustrating and difficult to migrate due to the lack of functionality. This has since been addressed, however we now have legacy rulesets that were built as bandaids that cannot be removed. Hopefully the migration to Secure Access will address this.
We used a product before this called iPrism by EdgeWave and also briefly tried Barracuda Web Security in the cloud. We were having such a large influx of service desk calls about proxy-based layer 7 web filters that we wanted to step back and pick something more at the DNS level, to protect our employees but not hover over their social media use, etc. Cisco will also employ a layer 7 proxy if a site is suspicious, which does require us to push a certificate out should we want that feature. For most policies we have it enabled.
We selected FortiGuard Web Filtering because it came in the service bundle with our FortiGate unit. After testing the service for a couple of months, we disabled the web filtering that was running on our client machines and have not looked back. It's been easy to manage, effective, and fast. There isn't much more you can ask for from a filtering solution.
Positive ROI when the service keeps users from going to malicious websites.
We had it deployed while users were internal and external with the AnyConnect Umbrella module so our protection was both on and off the corporate network.