“Inactive” can appear in two places: against a network in the Umbrella dashboard, or on a user’s device in Cisco Secure Client. The causes and fixes are different, so start by working out which one you are seeing.
Network shows “Inactive” in the dashboard
Umbrella marks a network as Inactive when it has received no DNS queries from that network’s public IP address in the past 24 hours. A newly added network will show Inactive until traffic arrives, which normally takes up to two hours.
| Cause | Fix |
|---|---|
| DNS is not pointed at Umbrella | Set the router, DHCP scope or DNS forwarders to 208.67.222.222 and 208.67.220.220. |
| The public IP has changed | Update the registered IP, use a dynamic IP updater, or register a static IP with your ISP. |
| Traffic goes via virtual appliances or Secure Client instead | This is expected. Those identities report activity on their own, not against the network. |
| Logging is set to “Don’t log any requests” | Change the policy’s logging setting if you need the network to show activity. |
To test, browse to welcome.umbrella.com from a device on that network. You should see “Welcome to Umbrella!”
Umbrella module inactive in Cisco Secure Client
| Status shown | What it means |
|---|---|
| Disabled (Trusted Network) | The device is on a network already protected by Umbrella, for example behind a virtual appliance. This is usually by design. |
| Disabled (VPN Connection) | A full-tunnel VPN is connected, so web protection pauses and the VPN path handles security. |
| Unprotected | The local agent service is not running. |
| Cloud Service Unavailable | The device cannot reach the Umbrella proxy or resolvers. |
| Config Error | A configuration file, such as the web security configuration, contains an incorrect value. |
Fixes for the Secure Client module
- Check OrgInfo.json. The module needs this file to know which Umbrella organisation it belongs to. If you replace it, delete the module’s data folder or reinstall.
- Exclude Umbrella from TLS inspection. If a corporate firewall decrypts traffic to Umbrella, OpenDNS or certificate validation domains, the module often goes inactive. This is one of the most common causes.
- Allow connectivity. Make sure outbound DNS and HTTPS to Umbrella’s resolvers and service endpoints are not blocked.
- Look for conflicting software. Other DNS filters, VPN clients or endpoint agents can take over the DNS settings.
- Restart or reinstall the Secure Client services, then check the status again.