Umbrella is mainly used for DNS security, and since we are in a hybrid model, we use Umbrella to protect remote users from malicious websites and for web traffic control.
Generally, Umbrella helps us protect those remote users by working on an agent-based system, and we install it on end-user computers. Once we install the agent, all the traffic from the computer routes through DNS Umbrella. Therefore, everyone is protected, whether in the office or at home. We create specific rules for what traffic to allow and what to block. Generally, we allow only productivity and legitimate traffic and block all malicious content and unwanted traffic.
Also, for particular features that are hosted locally, we can add those as our internal domains to resolve them quickly and have no issues in the future.
The best features Umbrella offers are web DNS filtering, website filtering, and it has better insight and visibility of what applications users are working on. It gives an insight and a list of applications being used by the users, and it also provides the category of the applications. For example, if they are using a VPN, it shows the VPN category. If it is any document sharing, it shows the document sharing. Based on that category rating, we can block the sites and applications.
We use these insights for a weekly review on those application insights, so we will be blocking unproductive or malicious content or document-sharing websites that people are using. Based on those weekly reviews, we will be blocking the categories.
Umbrella has positively impacted our organization by blocking some of the traffic, including some of the domains that were usually being generated. We saw 10 to 15 of the domains were malicious, and we have blocked them immediately. We have also correlated the web logs with our Sophos XDR solution, which really helped.
Umbrella can be improved because whenever a VPN connection is established, Umbrella may or may not work properly, and in this case, we face a challenge. They have to improve this part.
If they have a dedicated feature where, even after connecting to a VPN, the Umbrella roaming client should be online and it should be able to detect and follow whatever policy is applied, that would make for no confusion, and we can prepare a whitelisting after connecting to the VPN.
We have been using Umbrella for about three years now.
That was the main challenge Umbrella helped us overcome for remote users, and it works fine. Our review rating for this product is 8.