Skip to content

Datasheets

Cisco Umbrella + DNS Guardian Integration

November 7, 2022 |

The Cisco Umbrella and EfficientIP alliance delivers advanced DNS security by combining cloud-based threat intelligence with real-time DNS Transaction Inspection (DTI). This integration strengthens enterprise security perimeters, protects on and off-network users, and ensures internal DNS service continuity. Discover how DNS Guardian enhances visibility, prevents phishing and data exfiltration, and supports resilient hybrid deployments. Download the full technical datasheet to explore architecture details and deployment models.

Extend Enterprise Security Perimeters & Strengthen Network Defenses

In a security context where the threat landscape is constantly evolving and attacks becoming more and more sophisticated, DNS has become a primary target and assault vector for hackers, damaging brand reputation, revenue and operational efficiency of companies in all sectors.

The combination of Cisco Umbrella and EfficientIP technologies extends the enterprise security perimeter and strengthens network defenses. By integrating advanced DNS security solutions with cloud-based threat intelligence, this alliance delivers comprehensive protection against malicious domains, behavioral attacks and zero-day threats

It offers a best-of-breed market solution to defend against the widest range of DNS threats, protecting on and off-network users, safeguarding data confidentiality and ensuring both internal and external service continuity.

Best-of-Breed DNS Security Against the Widest Range of DNS Threats (On & Off-Network)

The joint solution offers an unprecedented level of in-depth visibility and security of DNS services for comprehensive threat protection.

On-premise, the DNS Guardian security appliance โ€” part of the SOLIDserverโ„ข DDI platform โ€” is a purpose-built security solution enabling DNS Transaction Inspection (DTI) technology for real-time advanced analytics and context-aware behavioral attack detection over client traffic, at ultra-high speed (up to 10M Queries per Second).

Patented adaptive countermeasures (block, quarantine, or rescue mode) ensure service continuity and data confidentiality while mitigating risk of false positives.

When internet recursive DNS queries are identified as trustworthy, DNS Guardian tags, encrypts (DNSCrypt) and forwards them to the Cisco Umbrella platform to leverage the secure cloud-based gateway. Cisco Umbrella checks filtering policies and resolves or denies the queries, offering a complementary layer of defense based on destination domain reputation using Internet-wide big data analytics and machine learning.

This combination of complementary security technologies extends the enterprise security perimeter by protecting both on/off-network users and internal DNS services availability (resolver and authoritative).

Thanks to on-the-fly traffic tagging with Cisco IDs, DNS Guardian enables detailed visibility of the client behind each query via the Cisco Umbrella portal. Additionally, DNS-DHCP-IPAM data provides key information on associated devices such as location or name, improving network control, reporting capacity and remediation efficiency across modern network automation environments and DDI solutions for DevOps environments.

Key Solution Features

Ease of Use and Deployment

  • Plug & play solution thanks to native integration
  • Encrypted flow with DNSCrypt
  • Detailed visibility over enterprise-wide internet traffic via Cisco Umbrella portal (IP source, DNS server, destination domain, category, action)
  • Faster remediation with DDI data (port connection, device name)
  • Strengthened network security ecosystem with SIEM integration

Full Coverage of the DNS Threat Landscape

  • Prevent initial infection and phishing and stop communication with CnC servers using threat intelligence on reputation domains
  • Detect data exfiltration beyond domain reputation by combining requested domains with context-aware client behavior analysis
  • Enhance predictive security with contextual traffic analytics
  • Strengthen resiliency and mitigate zero-day attacks with hybrid deployment
  • Ensure continuity of internal DNS services by applying adaptive countermeasures

Flexible Deployment Models

The solution supports hybrid deployment models covering:

  • Recursive DNS queries
  • Domain filtering management policies
  • Authoritative and secured cache/recursive services
  • Cisco Umbrella agents (on-site and off-site devices)
  • Integration with Umbrella Threat Intelligence

This flexibility simplifies network design while enhancing DNS views, sort lists, and forwarding policies.

Strengthen Your DNS Security Today

Learn how to extend your enterprise security perimeter and prevent phishing, data exfiltration, and zero-day DNS threats. Access the full technical overview of the Cisco Umbrella & EfficientIP integration.

Key Resources

Datasheets

SOLIDserver for the Cloud

Explore
Ddi Observability Center
Datasheets

DDI Observability Center

Explore
Dns Intelligence Center
Datasheets

DNS Intelligence Center

Explore
Dns Threat Pulse
Datasheets

DNS Threat Pulse: Leverage DNS Threat Intelligence for a Proactive Defense

Explore
Network Object Manager
Datasheets

Network Object Manager: Trusted Network Objects Repository for IT Design and Automation

Explore
Datasheets

Cloud Observer: Cloud Instances Discovery and Management

Explore
Solidserver Ddi Suite of Appliances
Datasheets

SOLIDserver DDI Suite of Appliances

Explore
Dns Blast
Datasheets

DNS Blast: High Performing DNS Cache Against DDoS Attacks

Explore
Datasheets

DNS Cloud: Powered By AWS Route 53 and Azure DNS Zones

Explore
Datasheets

DNSSEC Management

Explore