Why is Cisco Umbrella inactive?

Table of Contents

“Inactive” can appear in two places: against a network in the Umbrella dashboard, or on a user’s device in Cisco Secure Client. The causes and fixes are different, so start by working out which one you are seeing.

Network shows “Inactive” in the dashboard

Umbrella marks a network as Inactive when it has received no DNS queries from that network’s public IP address in the past 24 hours. A newly added network will show Inactive until traffic arrives, which normally takes up to two hours.

Cause Fix
DNS is not pointed at Umbrella Set the router, DHCP scope or DNS forwarders to 208.67.222.222 and 208.67.220.220.
The public IP has changed Update the registered IP, use a dynamic IP updater, or register a static IP with your ISP.
Traffic goes via virtual appliances or Secure Client instead This is expected. Those identities report activity on their own, not against the network.
Logging is set to “Don’t log any requests” Change the policy’s logging setting if you need the network to show activity.

To test, browse to welcome.umbrella.com from a device on that network. You should see “Welcome to Umbrella!”

Umbrella module inactive in Cisco Secure Client

Status shown What it means
Disabled (Trusted Network) The device is on a network already protected by Umbrella, for example behind a virtual appliance. This is usually by design.
Disabled (VPN Connection) A full-tunnel VPN is connected, so web protection pauses and the VPN path handles security.
Unprotected The local agent service is not running.
Cloud Service Unavailable The device cannot reach the Umbrella proxy or resolvers.
Config Error A configuration file, such as the web security configuration, contains an incorrect value.

Fixes for the Secure Client module

  1. Check OrgInfo.json. The module needs this file to know which Umbrella organisation it belongs to. If you replace it, delete the module’s data folder or reinstall.
  2. Exclude Umbrella from TLS inspection. If a corporate firewall decrypts traffic to Umbrella, OpenDNS or certificate validation domains, the module often goes inactive. This is one of the most common causes.
  3. Allow connectivity. Make sure outbound DNS and HTTPS to Umbrella’s resolvers and service endpoints are not blocked.
  4. Look for conflicting software. Other DNS filters, VPN clients or endpoint agents can take over the DNS settings.
  5. Restart or reinstall the Secure Client services, then check the status again.