cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1477
Views
1
Helpful
11
Replies

Ftd integration with Umbrella

Vishal6
Level 3
Level 3

Please find attached diagram and let me know can i integrate my Ftd with Cisco Umbrella
Note-: Here my Ftd will act as a internal firewall and Cisco umbrella will not integrate with Meraki MX due to license limitation.

Cisco Umbrella has dns advantage license.

 

Vishal6_0-1755774763928.png

 

 

11 Replies 11

@Vishal6 you want to configure Umbrella SIG tunnel from FTD? If so here is the cisco guide

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/220661-secure-firewall-configure-umbrella-sec.html

Else, provide more information on how you wish to integrate.

 

Vishal6
Level 3
Level 3

Will integrate ftd for dns inspection following below link.

https://secure.cisco.com/secure-firewall/docs/umbrella-connector

Vishal6
Level 3
Level 3

pls help

@Vishal6 what is the issue exactly? why is the link you provided not sufficient?

Vishal6
Level 3
Level 3

My concern would i get the required output integrating FTD with Umbrella, where my perimeter firewall Meraki would not be integrated with Umbrella due to license issue.

Attached image in very first post.

@Vishal6 thats fine, just follow the guide. The traffic would be routed from the FTD to the Umbrella cloud. You'd just need to allow that communication on the Meraki's in front of the FTDs.

 

Vishal6
Level 3
Level 3

Thank you for reply. How meraki mx act on dns filter restriction made with ftd and umbrella integration. Would it be any false positive ?

@Vishal6 the Meraki MX devices are not going to see the traffic is DNS traffic, the FTD is going to encrypt the traffic to the Umbrella cloud, so as mentioned before you'd need to permit the traffic from the FTD to the Umbrella Cloud networks. I recommend avoiding performing any SSL inspection on the meraki and just allow the communication from the FTD to the Umbrella cloud.

Vishal6
Level 3
Level 3

any help people

Help is always here' 

I read post and reply' ftd is behind metaki' so it not direct connect to internet?

MHM

Vishal6
Level 3
Level 3

yes

Review Cisco Networking for a $25 gift card