Cisco Umbrella Packages
Compare our cloud security packages in the summarized list of features below. Download the full package comparison for a more detailed breakdown.
Find the best Umbrella package for your team | DNS Security Essentials | DNS Security Advantage | SIG Essentials | SIG Advantage |
---|---|---|---|---|
Security and controls | ||||
DNS-layer security | ||||
Block domains with malware, phishing, botnet, or other high risk items | ||||
Secure web gateway | ||||
Proxy and inspect web traffic (incl. decryption of SSL (HTTPS) traffic) | Partial | |||
Enable web filtering by domain or category (SIG filtering by URL) | ||||
Create custom block/allow lists of domains | ||||
Create custom block/allow lists of URLs | ||||
Block URLs based on Cisco Talos and other third party feeds, and block files based on AV engine and Cisco Advanced Malware Protection (AMP) data | Partial | |||
Use retrospective security to identify previously-benign files that became malicious | ||||
Remote browser isolation (RBI) | ||||
Provide safe access to risky sites, web apps and all web destinations | Add-on | Add-on | ||
Cloud delivered firewall | ||||
Create layer 3/layer 4 policies to block specific IPs, ports, and protocols | ||||
Deepen protection for outbound traffic using application layer 7 policies with intrusion prevention system (IPS) | Add-on | |||
Data loss prevention | ||||
Enable in-line DLP inspection and blocking capabilities to protect sensitive data | Add-on | |||
Cloud access security broker | ||||
Discover and block shadow IT with App Discovery report | Partial | Partial | ||
Scan and remove malware from cloud-based file storage apps | Partial | |||
XDR and threat intelligence | ||||
Utilize SecureX cross product security data and automated response actions | ||||
Access Umbrella’s deep domain, IP, and ASN data for rapid investigations | ||||
Deployment and management | ||||
Traffic forwarding | ||||
Forward external DNS for on-network coverage and off-network devices | ||||
Cisco AnyConnect client to deploy Umbrella module to forward traffic | ||||
User attribution | ||||
Create policies and view reports by network, device, and user* | ||||
Create policies and view reports using SAML | ||||
Management | ||||
Customize block pages and bypass options | ||||
Use our multi-org console to centrally manage decentralized orgs | ||||
Management API to create, read, update, and delete IDs child orgs | ||||
Reporting and logs | ||||
Real-time activity search, plus reporting API to easily extract key events | ||||
Choose North America or Europe log storage | ||||
Use customer AWS S3 bucket to export and retain logs as long as needed, or a Cisco-managed S3 bucket to export and retain logs for 30 days** | ||||
* by network (egress IP), internal subnet, network device (including VLAN & SSID), roaming device, and Active Directory group (including specific users) | ||||
** No Amazon account required when using the Cisco-managed S3 bucket | ||||
This is a condensed listing of features. Refer to the product data sheets for specific package details. |
Talk to a security expert
Block threats at the DNS layer across your enterprise in minutes without added latency
Get DNS protection plus additional web security and threat insights to speed up investigations
Deploy advanced security functions and simplify management with the most effective security in the industry
Unlock the highest levels of protection and control with advanced security functions like layer 7 firewall with IPS, DLP, and more
Cisco Umbrella Product Package Comparison
This video will walk you through each package option. Find the right Umbrella package for your team.
Looking for Cisco Umbrella for schools or universities?
We provide several packages and special prices for our education customers. The DNS Security for Education package, which is licensed by number of faculty and staff, protects students at no additional charge. Compare education packages in the datasheet.
Robust offerings that meet SOC 2 compliance standards
Read the SOC 3 report for details