09-05-2017 09:53 PM - edited 02-20-2020 09:04 PM
Anyone knows if Firesight security intelligence feeds from talos are the same maliciuos dns/url/ip lists used by umbrella?
In other words, can we say that a user under umbrella and a user under a firesight sensors with security intelligence applied have the same level of backlisting protection?
04-15-2018 07:06 PM
If the firesight is configured with a dns policy (default one has no blacklists in it) and firesight is configured with URL filtering then yes.
But if the user goes off site, they'd have to vpn into the network to maintain the firesight protection.
The umbrella option would also require 'Insight' not 'professional' in order to receive Proxy protection and not just dns.
04-16-2018 04:31 AM
I believe Firepower's URL categorization is still using the Brightcloud backend data source and not Talos intelligence.
Blacklists etc. should both be from Talos.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide