Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Network Topology

Updated: February 5, 2026

Overview

Describes a sample network topology for Cisco Umbrella SASE auto tunnel where a branch Threat Defense device forwards all DNS and web traffic through a SIG tunnel to Umbrella for inspection before internet access.

In this topology, a Threat Defense device is deployed at a branch location. In the figure below, the internal client or branch workstation is labelled WKST BR and the branch threat defense is labelled NGFWBR1. A SIG auto tunnel is configured between NGFWBR1 and Cisco Umbrella.

Figure 1. Network Topology for Umbrella Auto Tunnel Configuration
Topology for the Umbrella auto tunnel configuration.

All DNS and web traffic is sent through the SIG tunnel to Cisco Umbrella to be validated and allowed or blocked based on the Umbrella DNS and web policy. This provides two layers of protection, one locally enforced by the Threat Defense and the other cloud-delivered by Cisco Umbrella.

In the case of DNS traffic:

  1. If Cisco Umbrella detects a DNS request for a domain that has not been classified, it will query the domain's reputation.

  2. If the domain is classified as malicious, the DNS request is blocked, and the end user is prevented from accessing the website.

  3. If the domain is classified as safe, the DNS request is resolved, and the website is accessible to the end user.