
I installed the Cisco Umbrella solution in a healthcare environment to protect their endpoint from both DNS attacks and web attacks. The cloud dashboard provided a comprehensive view of all policies and endpoint visibility, enabling us to understand the various ways an attacker could compromise the company.
The Cisco Umbrella is well suited for all companies that need a scalable and easy-to-manage cloud solution. It is particularly recommended for roaming clients and it targets both the enterprise and small to medium business markets, such as the Italian market. It is less appropriate where there is already a firewall solution deployed.
Cisco Umbrella helps act as a proxy to filter malicious domains and URLs, all the while providing DDoS protection and an extra layer of security, so that Cisco Umbrella is making the internet queries on behalf of our company. Umbrella also provides forensics so we can trace any malicious attacks.
Cisco umbrella is well suited for a our company which is predominately a Cisco show so it can integrate well with other Cisco systems. We use anyconnect so it is was easy to deploy the umbrella module on top of the Cisco secure access agent. Umbrella helped secure most of our https traffic.
Cisco Umbrella provides us with DNS protection as part of our security suite. We use it in addition to other products to provide an overall security umbrella.
We occasionally run into sites being blocked by Cisco Umbrella but they do not show in the dashboard as blocked or receive the blocked page. It would be nice to have that information on the block page or the logs to better troubleshoot.
In our organization, we use Cisco Umbrella to Protect internet traffic for the org
I think I am likely to recommend Cisco Umbrella to a colleague to Block traffic for computers
My
organization uses Cisco Umbrella as a layer of protection for users accessing
Internet. We used the native embedded classification of malicious URLs but also
to monitor who is attempting to connect to theses URLs. In addition, we use our
internal threat Intel feeds to enrich the umbrella URL classification. To identify
affected endpoints and users. The solution is integrated with our AD solution
and our DDI platform
Positive:
The business case is clear, and it fits perfectly. Avoid users connecting to
malicious URLs and if so early detect and stop. Integration with Cisco Secure
Endpoint and Cisco XDR works smoothly
Positive:
It feeds from intelligence sources all over the Internet
Positive:
Performance is amazing as it cops with huge amount of Data
You
do not have to worry to patch a platform as it is a SaaS
Neutral:
Integration with third party solutions is feasible but not so straight forward
Our business needs a reliable security solution to ensure business continuity. We use Cisco Umbrella primarily to secure our staff's web browsing and prevent them from going to malicious sites. We need to be able to protect company workstations against malware. We also use other tools to maintain a high level of security by creating a multi-layered firewall.
Cisco Umbrella is a cloud-based service, so there is no need to invest in maintaining it, everything is done automatically. This allows us to focus primarily on monitoring malicious sites, leaving us more time for security and other IT tasks. To date, we have not identified anything that could affect our continued use of the service.
We are using it to protect our entire organization. We use it to deny access to mal-domains CNC fishing, etc. Filter non business related sites, I especially like that fact we can block newly registered domains that although it might catch a legit site, most new domains are high risk for malware, or CNC. I have used this in its free form at home as OpenDNS. With proper MS Active directory you can track requests by user. We have the option to integrate into our AnyConnect VPN client as well still working on that.
It is good for whole network protection, and individual PCs with the client. Provide good reporting on where your network is going on the net. One thing I would like is a longer history with the logs 14 and 30 days are too short some times.
The business problem and scope was how my company protect the organization from DNS related malware. We were looking for a proven and trusted product by a company that had years of experience in the field. We use Cisco in many areas and decided that this product was best for us.
In my opinion Cisco Umbrella is excellent for medium to large scale deployments. The Cisco Umbrella solution does a great job in DNS related malware control, URL filtering (even though a bit limited) and reporting to just name a few. If you are a smaller company with limited budget, this is probably not the solution for you due to cost.
We use Cisco Umbrella SIG to secure our Mobile Workers.
Because of Covid we had an huge increase in mobile workers and had to allow split tunneling because our infrastructure could not handle the load.
The "always on" Web Filter gives us an extra level of security even when the traffic is not routed through our central firewall.
It is a good and stable Secure Internet Gateway.
But it does not work in China and needs more local breakouts.
Our web traffic is not terminating in neighbor country.
We use it to get all the users, so we can block sites they don't need to access, so I don't know if we have different kind of websites we don't want them to access, we can block the access through there.
Well, on a daily basis for all our users, we have a lot of people just go into different websites and stuff and it's good to block all of these websites. We don't want our users to access, so we don't get any malicious things from those websites.