Cisco Secure Access
Cloud-delivered SSE platform with ZTNA, SWG, CASB, and DLP for securing hybrid workforces from a single console.
Cisco Umbrella Cloud-Delivered Firewall
Cisco Umbrella’s cloud-delivered firewall extends security beyond web traffic to cover all TCP and UDP connections — delivering visibility, Layer 7 application control, and IPS enforcement for non-web traffic from any location, without appliances.
Application Intelligence
Layer 3/4 firewall rules control traffic by IP and port. But many modern applications use common ports like 443 or 80, making it impossible to distinguish them without deeper inspection. Umbrella’s cloud firewall recognizes 2,800+ non-web applications using network-based application recognition (NBAR) at Layer 7, giving you the ability to allow, block, or rate-limit specific applications regardless of the port they use.
Identify and manage traffic from cloud applications sharing common ports.
Block or allow specific applications regardless of the port they use.
Deep packet inspection identifies apps by behavior, not just port numbers.
Application logs feed into the same dashboard as DNS and web security events.
Cisco’s Anycast network spans data centers worldwide, routing traffic to the nearest enforcement point. Users experience low-latency firewall inspection regardless of their location or the time of day.
Traffic spikes, acquisitions, or rapid workforce growth don’t require hardware upgrades or capacity planning. The cloud firewall scales instantly to handle any volume of connections without performance degradation.
Manage all firewall rules, application controls, and IPS policies from the same Umbrella dashboard used for DNS and web security. One platform, one policy engine, one place to investigate threats.
Intrusion Prevention
The Umbrella cloud firewall includes an integrated intrusion prevention system based on SNORT 3 technology and powered by Cisco Talos intelligence. With 40,000+ signatures from Cisco Talos, IPS rules inspect all forwarded traffic for known attack signatures, exploit attempts, and suspicious network behavior — blocking threats that pass DNS and web controls by operating on non-HTTP traffic.
SASE Architecture
Cisco Umbrella’s cloud firewall is one of five integrated cloud security services that form the foundation of Cisco’s SASE architecture. Combined with SD-WAN, organizations get full network security enforcement at the cloud edge — replacing the traditional hub-and-spoke model with direct, secure cloud connectivity from every location.
Explore Cisco SASEAll-port, all-protocol inspection with Layer 7 app control and IPS.
Full proxy inspection for web traffic with URL filtering and malware scanning.
Block threats at the DNS layer before a connection is ever established.
Direct cloud connectivity from every branch with unified policy enforcement.
The Next Evolution
Our Cisco-certified team will help you deploy Umbrella cloud firewall across your organization, configure IPS policies, and integrate with your existing SD-WAN or routing infrastructure for full traffic coverage.