Cisco now offers OpenDNS Umbrella Web Filtering. Cisco acquired OpenDNS in August 2015, and rebranded the product as Cisco Umbrella.
N/A
NETSCOUT Arbor DDoS Protection
Score 8.0 out of 10
N/A
NETSCOUT Arbor DDoS Protection security software offers protection across multiple layers of the OSI model. It provides security measures for Layer 2 (Data Link layer) through Layer 7 (Application layer), ensuring complete protection for network infrastructure.
It’s very well suited. From what I’ve seen where it’s installed and tested, it’s actually very well suited in accommodation businesses because people still use VPNs or similar tools when going to hotels, but it helps keep the hotel network itself secure, so malicious actors aren’t doing something there. I’m also thinking for smaller companies—as I mentioned—they have firewalls but don’t want to use them because they’re expensive and hard to configure. So it simplifies the process, and there are smaller licenses where you can protect only access points or only specific users. The flexibility is actually quite good because you can define it for different needs, like specific licenses, add-ons, APIs, and integrations, and so on.
Arbor has the propensity to deal with even the larger firms. I have been using it for a year span and I don’t have any such complaint which is affecting us in a bad way. I can recommend this to all the companies who want to have a good network behavior analysis and to monitor the problems if there is any chance of it to occur and which has the potential to affect the whole working environment of the company.
So for example, we had the problem in the past. We are connecting users to our own managed data centers. We had seven locations around the world, put them with Cisco, any connect to our on-prem data center and let them out to the internet. So that's causing some high latency bad experiences with teams and so on. And with Umbrella we can directly connect the user to the cloud and to the internet so the users have a good experience with speed with latency and it's much better than back hauling the traffic to their own company and then processing them there.
Arbor's layer 7 countermeasures are very good out of the box, but it is very easy to reconfigure values and see the impact in real-time.
Peakflow SP provides fairly detailed traffic analysis and breakdown for top-N data such as top talkers, top ASNs, top ports and so on. They offer "SP Insight" as a product to build in more powerful reporting on the already-collected metrics with an interface very similar to Kibana or one of its many forks. We are not licensed for that so I can't speak to its capabilities.
Arbor allows for a good amount of automation. Fast flood detection ensures that if pre-determined thresholds are quickly exceeded, preconfigured mitigations can be started or in the event of an extremely large volumetric attack you can trigger an Arbor Cloud (sold separately) mitigation or a remotely-triggered blackhole announcement to drop traffic to the attacked destination IP address(es) upstream.
ATAC (Arbor support) is very helpful. The level of support our organization maintains covers ATAC performing all update functions to all Arbor appliances - SP and TMS.
The smart search feature in Cisco Umbrella is great addition for sure which helps us to identify malicious domain just by searching the URL and there is scoring system of Cisco Umbrella which mark the URL in low, medium and high risk. Sometimes Cisco Umbrella mark well known and good domain as malicious whether sometimes they mark malicious sites/domain as low risk. So, it's something that they should focus on, I think.
The live activity search is great for checking internet activities, but the filtering options could be improved. It would be helpful if we could filter by multiple parameters at once like combining username, destination IP and time range.
Arbor is a highly expensive company. this was the major reason behind not going for the Arbor sightline in the first place. Although its features are good but the cost is unjustifiable.
The implementation and the understanding of this tool are full of complexity and perplexity.
I am looking forward to having a new update on it. They used to update their versions quite frequently but it's been a long time they haven’t updated or maybe it is not in their priority lists right now.
First off I never give anything a "10" unless it's perfect. LOL - I grade on the curve. I think OpenDNS/Umbrella is a very good product. I think that fact that Cisco absorbed them is one of the proofs of that. I have used the product back when it was free for companies our size. I have not always appreciated the cost - but in the post pandemic cyber chaos, I believe the cost benefit ratio is still very high. I have honestly not looked at other products because Umbrella continues to work to my satisfaction. I consider Umbrella to be one of the key layers in my cyber security strategy.
Better features and easy to manage system with great customer support and overall usability is great as it works for hybrid environment with ease as it is having features for on prem users as wells as cloud users with great customer support and great team of trained engineers to support our opeartions.
Cisco umbrella services in the cloud are always available. However, the weakness is the VM installed in the data center that are the first resolvers. If the VMs become unavailable for any reason or the vSphere goes down, then all DNS is affected
our experience with cisco products has always been awesome and same is the case with cisco umbrella .Under umbrella cisco provides flexible and scalable software solution to use across different dept and sites . These softwares are very user friendly ,pages load quickly as these applications are designed for minimum latency and reports are also provided quickely
Whilst the support is good once you get through to them, it's email only and the response is slow. This is a issue, because its a core system that needs to work. We have had issues in the past where several of our companies have gone down due to Umbrella and support is nowhere to be seen. It is very difficult to know whether Umbrella is having service issues, since they do not regularly update customers on the status of their services, such as is seen by providers such as Microsoft (status.umbrella.com just seems to show up all of the time, I'm not sure it's even updated)
Quite easy to understand training modules prepared by knowledgeable trainers. Training modules have included all the desired features of these softwares and the content delivery is very good from the respective module trainers and it explains in details the features and apart from that further training material support is also provided if needed.
At the time we were forced to move from Cloud Web Security to Cisco Umbrella, Cisco Umbrella was far from being a direct replacement. It was frustrating and difficult to migrate due to the lack of functionality. This has since been addressed, however we now have legacy rulesets that were built as bandaids that cannot be removed. Hopefully the migration to Secure Access will address this.
Umbrella checked all the boxes for us (at the time) because it supported multiple domains and multiple IPs to protect (we have 20+ offices), and its configuration and policies cover a lot of different options for us. We used another product prior, and it worked well, but it didn't have all the features we needed at the time.
We evaluated Corero and a number of external scrubbing services. In the POC, we found Corero's mitigation capabilities to extremely limited beyond blocking common traffic types at preconfigured rates. It's not impossible to configure custom mitigation methods and countermeasures, but it requires a deep understanding of BPF and bytecode, where Arbor is checkboxes, radio buttons, and dialog buttons that all sit next to a graph showing traffic dropped and permitted by the current settings. I'm not going to enumerate each of the cloud services evaluated because the decision came down to the same reasoning. The amount of traffic we receive is enough that it would be prohibitively expensive for our use case.
Cisco umbrella provides fleaxible and scalable software solutions which are easy deploy across multiple departments and sites wherever needed and this softwares are very easy to use and provides the best interface along with cisco support for other devices apart from cisco infrastructure but still there is scope for improvement on the inclusion of latest features