<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco umbrella detection in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270427#M1017</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1146484"&gt;@skywalker_007&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, IP Layer Enforcement with the Umbrella Roaming Security client or AnyConnect Roaming Security Module.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.umbrella.com/deployment-umbrella/docs/6-adding-ip-layer-enforcementz" target="_self"&gt;https://docs.umbrella.com/deployment-umbrella/docs/6-adding-ip-layer-enforcementz&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jan 2021 22:25:14 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-01-11T22:25:14Z</dc:date>
    <item>
      <title>Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270426#M1016</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As umbrella is dns security ,if someone access the malicious website by ip address and not the name , will umbrella detect/prevent&amp;nbsp; it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also ,if someone uses a client like command line , filezilla to do ftp&amp;nbsp; etc ,will umbrella prvenet it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client machine has roaming client installed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270426#M1016</guid>
      <dc:creator>skywalker_007</dc:creator>
      <dc:date>2021-01-11T22:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270427#M1017</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1146484"&gt;@skywalker_007&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, IP Layer Enforcement with the Umbrella Roaming Security client or AnyConnect Roaming Security Module.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.umbrella.com/deployment-umbrella/docs/6-adding-ip-layer-enforcementz" target="_self"&gt;https://docs.umbrella.com/deployment-umbrella/docs/6-adding-ip-layer-enforcementz&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270427#M1017</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-11T22:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270435#M1018</link>
      <description>&lt;P&gt;Ok thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a customer with 5 different brnach office and a central location where ASAv is installed . any connect is used as client vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer has purchased umbrella advantage .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With this can we still see the actual ip addrss of client machine sitting in the office .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example I have a user with IP address 10.1.1.1 sitting in head office , can we see this ip on umbrella or is it only the public IP addrrss of ASAv ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no VA&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270435#M1018</guid>
      <dc:creator>skywalker_007</dc:creator>
      <dc:date>2021-01-11T22:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270437#M1019</link>
      <description>&lt;P&gt;If you have the anyconnect roaming client, then yes the private IP address (i.e. 10.1.1.1) will be reported in the umbrella dashboard.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270437#M1019</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-11T22:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270440#M1020</link>
      <description>&lt;P&gt;Even if user is sitting in office and not connected to ASAv via anyconnect , the connection from.user machine having anyconnect (with roaming security module ) shows the actual ip address of the client and we can have different policies based on the internal ip address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here we are not talking about identities for which we need VA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is to have different policies based on Internal Ip address scheme&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270440#M1020</guid>
      <dc:creator>skywalker_007</dc:creator>
      <dc:date>2021-01-11T22:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270442#M1021</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt; &lt;EM&gt;&lt;U&gt;Policy cannot be set/enforced on the LAN IP returned by the roaming client. The inclusion of LAN IP is only for visibility and reporting purposes.&lt;/U&gt;&lt;/EM&gt; By comparison, only with a VA and a ‘site’ and an ‘internal network’ identity can policy be enforced on LAN IP.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270442#M1021</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-11T22:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco umbrella detection</title>
      <link>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270444#M1022</link>
      <description>&lt;P&gt;Ok understood. Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So VA is necessary for internal ip policy enforcement.&lt;/P&gt;&lt;P&gt;Thanks you for quick response.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/cisco-umbrella-detection/m-p/4270444#M1022</guid>
      <dc:creator>skywalker_007</dc:creator>
      <dc:date>2021-01-11T22:57:05Z</dc:date>
    </item>
  </channel>
</rss>

