Why is Cisco Umbrella blocking websites?

Table of Contents

When Cisco Umbrella blocks a website, it is applying a policy your administrator configured, a security verdict from Cisco’s threat intelligence, or both. The first job is to find out which rule fired.

The most common reasons

Reason What is happening Typical fix
Security category The domain is classed as malware, phishing, command and control, cryptomining or similar. Leave it blocked unless you are certain it is a false positive.
Newly seen domain The domain has only just appeared in Umbrella’s global DNS data. Many brand-new sites are caught by this. Add it to an allow destination list if it is legitimate.
Content category Your policy blocks a category such as social networking, gambling or file sharing. Ask the administrator to change the policy or allow the domain.
Destination list Someone has added the domain to a custom block list. Remove it from the list.
Miscategorisation The site is in the wrong content category. Submit a categorisation review request to Cisco.
Secure web gateway rule On SIG packages, a URL, file type, application or tenant control blocked the request. Check the web policy rule set and its rule order.

How to find the rule that blocked the site

  1. Note the exact domain from the block page or the browser address bar.
  2. In the Umbrella dashboard, open Reporting > Activity Search and filter by that domain and the user, device or network identity.
  3. Read the Categories and Policy columns. They tell you whether a security category, content category or destination list caused the block, and which policy was applied.
  4. Umbrella applies the first policy that matches an identity, so a user may be hitting a stricter policy than you expect.
  5. Look up the domain in Umbrella Investigate or Cisco Talos to check its reputation before you allow it.

Blocks that are not really blocks

Sometimes a site “does not load” without showing a block page at all. Common causes include:

  • Certificate warnings when the Cisco Umbrella root certificate is not installed on the device. Umbrella cannot present its block page for HTTPS sites cleanly without it.
  • Apps that use certificate pinning and fail under secure web gateway decryption. Add them to the selective decryption list.
  • Internal domains that are being sent to Umbrella instead of your local DNS servers. Add them to the Internal Domains list.

End users should send IT the domain and the time of the block.