Is Cisco Umbrella a firewall?

Table of Contents

Cisco Umbrella is not a firewall in the traditional sense. At its core it is a cloud-delivered DNS-layer security service: it decides whether a domain is safe before your device ever opens a connection to it. The higher Umbrella packages do add a cloud-delivered firewall, so the accurate answer is “partly, depending on the package you buy”.

What each Umbrella component actually does

Component What it inspects Firewall-like?
DNS-layer security (all packages) DNS queries sent to Umbrella’s resolvers No. It blocks by domain reputation and category, not by port or protocol.
Selective proxy (DNS Advantage) Web traffic to “risky” domains only No. It is a partial web proxy for grey-listed domains.
Secure web gateway (SIG packages) HTTP and HTTPS traffic, with optional TLS decryption Partly. It is a full web proxy, not a network firewall.
Cloud-delivered firewall (SIG packages) Layer 3 and 4 traffic sent over IPsec tunnels, plus layer 7 application rules Yes. This is a true firewall-as-a-service.
Intrusion prevention (SIG Advantage) Traffic passing the cloud firewall, checked against Snort signatures Yes, as an add-on layer to the firewall.

Where the cloud firewall fits

The cloud-delivered firewall only sees traffic that you send to it, usually through an IPsec tunnel from a branch router, SD-WAN appliance or on-premises firewall. It can allow or block by source, destination, port and protocol, and in SIG Advantage it adds application-aware rules and IPS. Users on DNS-only packages never touch it.

What Umbrella does not replace

  • Your perimeter firewall. Umbrella does not handle inbound connections, NAT for published services or internal network segmentation.
  • Site-to-site VPN termination between your own offices and data centres.
  • East-west traffic inside the LAN, which never leaves the building and so never reaches Umbrella.

Most organisations run Umbrella alongside an on-premises or virtual firewall. Umbrella stops users reaching malicious destinations anywhere they work, while the local firewall protects the network edge and internal zones.

A note on the product’s future

In September 2026 Cisco announced end of sale for the Umbrella DNS and SIG packages, with Cisco Secure Access as the successor. Secure Access keeps the firewall-as-a-service capability, so if the cloud firewall is the reason you are looking at Umbrella, evaluate Secure Access or another security service edge (SSE) platform alongside it.