Cisco Umbrella is not a firewall in the traditional sense. At its core it is a cloud-delivered DNS-layer security service: it decides whether a domain is safe before your device ever opens a connection to it. The higher Umbrella packages do add a cloud-delivered firewall, so the accurate answer is “partly, depending on the package you buy”.
What each Umbrella component actually does
| Component | What it inspects | Firewall-like? |
|---|---|---|
| DNS-layer security (all packages) | DNS queries sent to Umbrella’s resolvers | No. It blocks by domain reputation and category, not by port or protocol. |
| Selective proxy (DNS Advantage) | Web traffic to “risky” domains only | No. It is a partial web proxy for grey-listed domains. |
| Secure web gateway (SIG packages) | HTTP and HTTPS traffic, with optional TLS decryption | Partly. It is a full web proxy, not a network firewall. |
| Cloud-delivered firewall (SIG packages) | Layer 3 and 4 traffic sent over IPsec tunnels, plus layer 7 application rules | Yes. This is a true firewall-as-a-service. |
| Intrusion prevention (SIG Advantage) | Traffic passing the cloud firewall, checked against Snort signatures | Yes, as an add-on layer to the firewall. |
Where the cloud firewall fits
The cloud-delivered firewall only sees traffic that you send to it, usually through an IPsec tunnel from a branch router, SD-WAN appliance or on-premises firewall. It can allow or block by source, destination, port and protocol, and in SIG Advantage it adds application-aware rules and IPS. Users on DNS-only packages never touch it.
What Umbrella does not replace
- Your perimeter firewall. Umbrella does not handle inbound connections, NAT for published services or internal network segmentation.
- Site-to-site VPN termination between your own offices and data centres.
- East-west traffic inside the LAN, which never leaves the building and so never reaches Umbrella.
Most organisations run Umbrella alongside an on-premises or virtual firewall. Umbrella stops users reaching malicious destinations anywhere they work, while the local firewall protects the network edge and internal zones.
A note on the product’s future
In September 2026 Cisco announced end of sale for the Umbrella DNS and SIG packages, with Cisco Secure Access as the successor. Secure Access keeps the firewall-as-a-service capability, so if the cloud firewall is the reason you are looking at Umbrella, evaluate Secure Access or another security service edge (SSE) platform alongside it.