cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4597
Views
0
Helpful
0
Comments
Meddane
VIP
VIP

Cisco Umbrella is one of the most interesting cisco security solutions. Basically, Umbrella is a cloud based solution and a big DNS Services It all starts with DNS and Precedes file execution and IP connection. Which means that Umbrella blocks malicious websites at the DNS level before establishing an IP connection with the malicious web server. If the Website is categorized as clean, the Cisco Umbrella as a regular DNS server returns the IP address of the web server then the PC establishes direct IP connection to the web server.

Cisco Umbrella was launched as a replacement of Cisco Cloud Web Security which operates as a proxy server for HTTP and HTTPS traffic.

When the Cisco Umbrella returns the IP address of the legitimate web server and we want to inspect the legitimate traffic web traffic. How to intercept this direct IP connection with the legitimate web server? especially the HTTPS traffic which needs to be decrypted in order to inspect if a malicious file is embedded.

The solution is the "Intelligent Proxy" with "SSL Decryption" features. The intelligent proxy is the ability for Cisco Umbrella to intercept and proxy web requests to inspect the content of the web traffic. We can classify by categories which type of web traffic we want to proxy and apply SSL decryption. When Intelligent Proxy is enabled, instead of returning the IP address of the Web Server, Cisco Umbrella returns the IP address of the Intelligent Proxy server.

Basically, Intelligent Proxy in Cisco Umbrella inherits the function of the old solution CWS Cloud Web Security.

Meddane_0-1658250086077.png

Go to the Client PC

Open Firefox and browse to www.eicar.com.

The European Institute for Computer Antivirus Research (EICAR) developed the EICAR test file. This

EICAR test file can be used to test the response of antivirus and antimalware programs.

Click DOWNLOAD ANTI MALWARE TESTFILE.

Under Download area using standard protocol http. Click eicar.com.

You should be able to download the Malware File as shown below.

Meddane_1-1658250086089.png

Meddane_2-1658250086101.png

From the Client PC try another test by clicking eicar.com under Download area using the secure, SSL enabled protocol https.

You should be able to download the Malware File as shown below.

Meddane_3-1658250086113.png

Meddane_4-1658250086119.png

Navigate to Policies > Management > All Policies and click edit the policy Demo-Policy.

Enable File Inspection.

Meddane_5-1658250086126.png

Meddane_6-1658250086134.png

Navigate to Advanced Settings.

Select SSL Decryption to allow the intelligent proxy to inspect traffic over HTTPS

Meddane_7-1658250086141.png

When selected, the Root Certificate is available, download and install the Cisco Umbrella root certificate to Client PC. Without this certificate, HTTPS connections will break.

Edit Root Certificate and click Download Certificate.

Install the certificate on the Client PC.

Meddane_8-1658250086151.png

Once enabled, it's a interesting to test whether it's working as expected. Access the URL https://ssl-proxy.opendnstest.com .

Meddane_9-1658250086152.png

You should a message that confirms that the SSL Decryption in the Intelligent Proxy is working.

Meddane_10-1658250086157.png

Try to access the URL www.eicar.org once again, this time the access is blocked as shown below.

Meddane_11-1658250086160.png

Navigate to Reporting > Core Reports > Activity Search, you should see the eicar website is not accessible to download a malware file.

Meddane_12-1658250086173.png

Meddane_13-1658250086184.png

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: