Overview
Provides an overview of Secure Firewall and Umbrella integration to help network administrators plan and secure cloud and internet traffic.
In this chapter, we delve into the practical application of the Umbrella auto tunnel. The use case details the scenario, network topology, best practices, and prerequisites. It also provides a comprehensive end-to-end procedure for seamless implementation.
Cisco Umbrella Auto Tunnel
Learn about securing branch internet traffic using Cisco Umbrella SASE auto tunnel to forward DNS and web traffic to the nearest Cisco Umbrella cloud gateway for inspection and protection.
Benefits
Is This Use Case For You?
Identifies the intended audience for implementing Cisco Umbrella SASE auto tunnel, including IT professionals, network administrators, and security staff managing and securing network infrastructure.
Scenario
Describes a use case where an IT administrator implements Cisco Umbrella auto tunnel with a branch firewall to block malicious domains and protect internet traffic, improving security for branch and remote users.
Network Topology
Describes a sample network topology for Cisco Umbrella SASE auto tunnel where a branch Threat Defense device forwards all DNS and web traffic through a SIG tunnel to Umbrella for inspection before internet access.
Best Practices for SASE Umbrella Tunnels
Lists the best practices for deploying Cisco Umbrella SASE auto tunnel with Secure Firewall to enhance branch internet security.
Prerequisites for Configuring Umbrella SASE Tunnels
Lists the prerequisites for deploying Cisco Umbrella SASE auto tunnel with Secure Firewall.
Workflow for Configuring Umbrella Auto Tunnel
Illustrates the end‑to‑end workflow for deploying Cisco Umbrella SASE auto tunnel with Secure Firewall.
Configure a SASE Tunnel for Umbrella
Provides instructions to configure a Cisco Umbrella SASE auto tunnel in Firewall Management Center (FMC) to forward branch DNS and web traffic through a Secure Internet Gateway (SIG) tunnel for cloud security inspection.
Configure a Static Route
Provides instructions to configure a static route in Firewall Management Center (FMC) to steer Threat Defense (FTD) device's DNS and web traffic through the Cisco Umbrella SIG tunnel.
Configure an Extended ACL for DNS and Web Traffic
Provides instructions to configure an extended access control list (ACL) to match DNS and web traffic and steer Threat Defense (FTD) internet-bound traffic through the intended egress path.
Configure a PBR Policy for DNS and Web Traffic
Provides instructions to configure a policy-based routing policy in Firewall Management Center (FMC) to steer Threat Defense (FTD) DNS and web traffic to the Cisco Umbrella SIG tunnel.
Deploy Configuration
Provides instructions to deploy all the configurations to the Threat Defense (FTD) devices in Firewall Management Center (FMC).
Verify SASE Umbrella Tunnel Deployment
Provides instructions to verify correct forwarding of traffic to Cisco Umbrella and if SIG tunnels are active.
Troubleshoot Umbrella Auto Tunnels
Provides troubleshooting information for Cisco Umbrella SASE auto tunnel issues, including verifying DNS resolution, SIG tunnel status, routing, and traffic forwarding to restore secure internet access.
Additional Resources
Lists additional resources to learn about Cisco Secure Firewall features, configuration, verification, and troubleshooting.