<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Umbrella /w Decryption in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120787#M1928</link>
    <description>&lt;P&gt;&amp;nbsp;I'm having a tough time understanding Umbrella's decryption capabilities. Since Umbrella is just analyzing the DNS Request, how is it able to utilize file policy when Decryption is enabled? Furthermore, my edge firewall is already providing SSL Decryption for internet capabilities. Do I need to worry about using decryption both on the endpoint and the perimeter?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2024 14:23:22 GMT</pubDate>
    <dc:creator>guacamoley</dc:creator>
    <dc:date>2024-05-30T14:23:22Z</dc:date>
    <item>
      <title>Umbrella /w Decryption</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120787#M1928</link>
      <description>&lt;P&gt;&amp;nbsp;I'm having a tough time understanding Umbrella's decryption capabilities. Since Umbrella is just analyzing the DNS Request, how is it able to utilize file policy when Decryption is enabled? Furthermore, my edge firewall is already providing SSL Decryption for internet capabilities. Do I need to worry about using decryption both on the endpoint and the perimeter?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120787#M1928</guid>
      <dc:creator>guacamoley</dc:creator>
      <dc:date>2024-05-30T14:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella /w Decryption</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120807#M1929</link>
      <description>What level of Umbrella are you using?    Just DNS?  SIG?&lt;BR /&gt;And how are you getting the data there if SIG? Tunnels? Client?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 May 2024 14:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120807#M1929</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-05-30T14:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella /w Decryption</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120821#M1930</link>
      <description>&lt;P&gt;Just DNS. Majority of traffic through secure client.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5120821#M1930</guid>
      <dc:creator>guacamoley</dc:creator>
      <dc:date>2024-05-30T14:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella /w Decryption</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5121501#M1931</link>
      <description>&lt;P&gt;Depending on which DNS tier you are using (Essentials/Advantage):&lt;BR /&gt;Essentials - provides you DNS security&lt;BR /&gt;Advantage - has intelligent proxy capability which proxies requests to those "grey" sites that we call (e.g. reddit).&lt;/P&gt;
&lt;P&gt;So if you are using Essentials, then you will definitely not going to see any web traffic from your activity logs.&lt;/P&gt;
&lt;P&gt;Why use Umbrella if you already have a firewall in the HQ? Few reasons:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Most of the organizations today now has a hybrid workforce which your on-prem firewall cannot protect. Yes you can have them VPN-in, but are they really going to? Especially now that most of the applications we use are in the cloud.&lt;/LI&gt;
&lt;LI&gt;Visibility - application discovery report would give you great visibility about the applications your users were using. This gives you visibility into those unsanctioned applications like pdf/word converters for example that you can then block. (you cannot block what you cannot see)&lt;/LI&gt;
&lt;LI&gt;Alleviate TLS decryption load from the firewall - TLS decryption is resource intensive, you can utilize umbrella to offload these from the firewall.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 23:56:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5121501#M1931</guid>
      <dc:creator>franzd</dc:creator>
      <dc:date>2024-05-30T23:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella /w Decryption</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5121888#M1932</link>
      <description>&lt;P&gt;I'm still finding this confusing. So with DNS Security, intelligent proxy doesn't do anything? But with advantage intelligent proxy will send the actual https traffic to the proxy or will it just send the dns requeste to the proxy?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 12:23:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5121888#M1932</guid>
      <dc:creator>guacamoley</dc:creator>
      <dc:date>2024-05-31T12:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella /w Decryption</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5121903#M1933</link>
      <description>With advanced intelligent proxy SOME traffic, the possibly suspect traffic, goes to the proxy.  The list of sites that are sent isn't published, but you can look at what traffic of yours is going in the Umbrella console.&lt;BR /&gt;&lt;BR /&gt;If you just have DNS Essentials, none of your traffic goes to the proxy.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 31 May 2024 12:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-w-decryption/m-p/5121903#M1933</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-05-31T12:42:26Z</dc:date>
    </item>
  </channel>
</rss>

