CiscoSecure Access & SASE

    Umbrella

    DNS-layer security and cloud-delivered protection as the first line of defence.

    Cisco Umbrella delivers cloud-native security at the DNS layer and beyond — blocking malware, phishing, ransomware, and command-and-control before a connection is ever made. As the first line of defence for users on and off the network, it requires no hardware and deploys in minutes, and it forms the DNS-layer foundation of Cisco’s SASE and SSE architecture. Faltrox deploys, configures, and operates it.

    Overview

    What Umbrella is

    Umbrella provides security at the DNS layer, the earliest and broadest point to enforce policy — because virtually every connection starts with a DNS request. By resolving requests in Cisco’s global cloud and applying threat intelligence from Talos, it blocks connections to malicious domains before they are established, stopping malware, phishing, and ransomware upstream of the endpoint and network.

    Beyond DNS, Umbrella adds a secure web gateway, cloud-delivered firewall, cloud access security broker functionality, and remote browser isolation, making it both a standalone first line of defence and the DNS-layer foundation of Cisco Secure Access and the wider SASE architecture. It protects users on-network and roaming, deploys with no hardware in minutes, and integrates with SD-WAN and the Cisco security stack. Faltrox configures the policy, integrates it with your network, and operates it as managed defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    DNS Layer

    Enforces security at the DNS layer, the earliest and broadest point to block a connection.

    02

    On & Off Network

    Protects users both on the corporate network and roaming anywhere.

    03

    Malware & Ransomware

    Blocks connections to malicious domains before malware and ransomware can reach the endpoint.

    04

    Phishing & C2

    Stops phishing sites and command-and-control callbacks at the DNS and web layers.

    05

    SaaS & Web

    Secure web gateway and CASB inspect and control web and SaaS usage.

    06

    SASE Foundation

    Forms the DNS-layer foundation of Cisco Secure Access and the SASE architecture.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Resolve

      DNS requests are resolved in Cisco’s global cloud, where Talos threat intelligence is applied to every domain.

    2. 02

      Block Upstream

      Connections to malicious or policy-violating domains are blocked before they are ever established.

    3. 03

      Inspect

      Risky traffic is routed through the secure web gateway and cloud firewall for deeper inspection and CASB control.

    4. 04

      Isolate

      Remote browser isolation renders risky sites away from the endpoint when full blocking is too blunt.

    5. 05

      Operate

      Faltrox configures policy, integrates Umbrella with your network and SD-WAN, and monitors it as managed defence.

    Capabilities

    Key capabilities

    DNS-Layer Security

    Blocks malicious domains at the DNS layer before a connection is made, stopping threats upstream.

    Talos Threat Intelligence

    Domain and IP reputation from Cisco Talos, one of the largest commercial threat intelligence teams.

    Roaming Protection

    Protects users off the corporate network without backhauling traffic, via a lightweight client.

    Secure Web Gateway

    Full URL and content inspection with SSL decryption for deeper web traffic control.

    Cloud-Delivered Firewall

    Layer 3/4 firewalling in the cloud for traffic that does not need an on-site appliance.

    CASB & App Discovery

    Discovers and controls SaaS usage, surfacing shadow IT and risky applications.

    Remote Browser Isolation

    Renders risky sites in an isolated cloud browser to protect the endpoint.

    Rapid, Hardware-Free Deploy

    Deploys in minutes with no hardware, and integrates natively with Cisco SD-WAN.

    Works with

    Part of the platform

    Cisco products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Cisco Umbrella for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why enforce security at the DNS layer?

    Because virtually every connection begins with a DNS request, the DNS layer is the earliest and broadest place to enforce policy — Umbrella blocks connections to malicious domains before they are ever established, stopping threats upstream of the endpoint and network rather than after they arrive.

    02Does it protect users off the network?

    Yes — a lightweight roaming client protects users wherever they work, without backhauling traffic to a data centre, which is what makes it effective for a hybrid and remote workforce.

    03How does it relate to Cisco Secure Access?

    Umbrella provides the DNS-layer foundation of Cisco’s SSE/SASE architecture, and Cisco Secure Access DNS Defense builds on it. Many organisations start with Umbrella for DNS-layer security and expand into full Secure Access SSE. Faltrox scopes the right path.

    04What does it need to deploy?

    No hardware — it is cloud-delivered and can be deployed in minutes, enforced via DNS settings, a roaming client, or native integration with Cisco SD-WAN. That speed and simplicity is a core reason it is often the first line of defence.

    05How does Faltrox operate it?

    We configure the DNS, web, and firewall policy, integrate Umbrella with your network and SD-WAN, and monitor its detections — delivering DNS-layer and cloud security as a managed service and, where appropriate, a stepping stone to full SSE.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us