cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1662
Views
1
Helpful
0
Comments
Meddane
VIP
VIP

Cisco Umbrella is one of the most interesting cisco security solutions. Basically, Umbrella is a cloud based solution and a big DNS Services It all starts with DNS and Precedes file execution and IP connection. Which means that Umbrella blocks malicious websites at the DNS level before establishing an IP connection with the malicious web server. If the Website is categorized as clean, the Cisco Umbrella as a regular DNS server returns the IP address of the web server then the PC establishes direct IP connection to the web server.
 
Cisco Umbrella was launched as a replacement of Cisco Cloud Web Security which operates as a proxy server for HTTP and HTTPS traffic.
 
When the Cisco Umbrella returns the IP address of the legitimate web server and we want to inspect the legitimate traffic web traffic. How to intercept this direct IP connection with the legitimate web server? especially the HTTPS traffic which needs to be decrypted in order to inspect if a malicious file is embedded.
 
The solution is the "Intelligent Proxy" with "SSL Decryption" features. The intelligent proxy is the ability for Cisco Umbrella to intercept and proxy web requests to inspect the content of the web traffic. We can classify by categories which type of web traffic we want to proxy and apply SSL decryption. When Intelligent Proxy is enabled, instead of returning the IP address of the Web Server, Cisco Umbrella returns the IP address of the Intelligent Proxy server.
 
Basically, Intelligent Proxy in Cisco Umbrella inherits the function of the old solution CWS Cloud Web Security.
 
In the attached document I shown how to enable and configure Intelligent Proxy and SSL Decryption, finally how to download the Cisco Umbrella Root-CA to avoid the warning certificate error from the end users's perspective.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: