| Compare Umbrella for Government packages | DNS for Government | DNS for Education* | SIG Essentials | SIG Advantage | SIG for Education* |
|---|---|---|---|---|---|
| Security & control | |||||
| DNS-layer security | |||||
| Block domains associated with phishing, malware, botnets, and other high-risk categories (cryptomining, newly seen domains, etc.) | |||||
| Protective DNS (CISA) integration | |||||
| Create custom block/allow lists | |||||
| Block DNS Apps | |||||
| iOS/Android mobile clients | |||||
| Secure web gateway | |||||
| Block URLs based on Cisco Talos and other third-party feeds, block files based on AV engine and Cisco Secure Endpoint data | |||||
| Create custom block/allow lists | |||||
| Decrypt and inspect SSL (HTTPS) traffic | |||||
| Enable web filtering (full URLs, not just domains) | |||||
| Proxy web traffic for inspection | |||||
| SWG for Chromebook: secure Google chromebook devices on/off network | |||||
| Cloud access security broker (CASB) | |||||
| Discover and block shadow IT with Umbrella’s App Discovery report via DNS | |||||
| Discover and block shadow IT with Umbrella’s App Discovery report via SWG and Firewall | |||||
| Block apps with web policy or destination lists | |||||
| Create policies with advanced app controls at the activity level (uploads, attachments, and posts) or tenant controls (corporate vs. personal) | |||||
| Data loss prevention | |||||
| Inspect web and cloud app traffic inline for sensitive data | DLP add on | DLP add on | |||
| Inspect cloud app data-at-rest via API for sensitive data | DLP add on | DLP add on | |||
| Cloud malware detection | |||||
| Scan and remove malware from cloud-based storage applications | |||||
| Cloud-delivered firewall | |||||
| Create layer 3/layer 4 policies to block specific IPs, ports, and protocols | |||||
| Protection using app layer 7 policies with intrusion prevention system (IPS) | |||||
| Use IPSec tunnel termination | |||||
| Remote browser isolation | |||||
| RBI Isolate any: provide safe access to any web destination | RBI add on | RBI add on | RBI add on | ||
| RBI Isolate risky: provide safe access to risky sites (categorized) | RBI add on | RBI add on | RBI add on | ||
| Deployment & management | |||||
| Management | |||||
| Customize block pages and bypass options | |||||
| Reporting & logs | |||||
| Leverage real-time activity search and Umbrella API’s to easily extract key events | |||||
| Access domain request logs in the user interface | |||||
| Access full URL logging and firewall logging in the user interface | |||||
| Export logs to customer’s S3 bucket | |||||
| Traffic proxying | |||||
| Cisco Secure Client (license included) to deploy Umbrella module to redirect traffic | |||||
| Forward external DNS traffic for on-network protection via Cisco and off-network protection | |||||
| Send outbound network traffic via proxy chaining or PAC files | |||||
| Send outbound network traffic by IPSec tunnels | |||||
| User attribution | |||||
| Create policies and view reports by: Network (egress IP), internal subnet [2] –network device, roaming device (March 2024), active directory group membership | |||||
| Create policies and view reports using SAML | |||||
| Identity management | |||||
| PIV-CAC Card support | |||||
| * This is a condensed listing of features. Refer to the product data sheet for specific package details. | |||||
Talk to a government security expert
DNS for Government
Block threats at the DNS layer across your agency in minutes with CISA Protective DNS and Umbrella DNS protection
DNS & SIG for Edu
For Public Educational institutions and Federally funded research institutions
SIG Essentials
Combine multiple security functions into a single solution to protect devices, remote users, and distributed locations anywhere
SIG Advantage
Unlock powerful protection and control with advanced security like layer 7 firewall with IPS, DLP, and more
