Introduction
Welcome to Introduction to Cisco Umbrella. In this skill we will be covering the following topics:
- What is Cisco Umbrella?
- Understand Umbrella Traffic Flow
- Understand Cisco's SASE Architecture
- Integrating SD-WAN and SASE
- Cloud OnRamp for SaaS with Umbrella
Resources:
Anki Deck:
What is Cisco Umbrella?
Let's begin by looking at a general overview of what Cisco Umbrella is and the features it offers to your enterprise specifically in the context of SaaS connectivity.
Cisco Umbrella product page:
Note: "Shadow IT" refers to information technology (IT) systems, devices, software, applications, and services that are managed and utilized without the knowledge or approval of an organization's formal IT department. This phenomenon often occurs when employees use new technologies or cloud services to meet their work requirements without waiting for official corporate approval or oversight.
Knowledge Check
What is the primary function of Cisco Umbrella?
Understand Umbrella Traffic Flow
It's critical to understand the traffic flow through Umbrella which is directly related to the policy implementation workload. Let's take a closer look.
Knowledge Check
What is the correct order of operations when Cisco Umbrella processes a web request with all policies enabled?
Understand Cisco's SASE Architecture
Cisco's Secure Access Service Edge (SASE) architecture is a comprehensive framework that combines networking and security functions into a single, cloud-delivered service model. This approach is designed to support the dynamic secure access needs of organizations, particularly in environments where users, applications, and data are distributed across multiple locations and cloud platforms.
Knowledge Check
Which of the following best describes the primary purpose of Cisco's Secure Access Service Edge (SASE) architecture?
Integrating SD-WAN and SASE
SD-WAN and SASE integration represents the ease with which we can connect SD-WAN to Umbrella SIG. Let's take a closer look.
Knowledge Check
Where in vManage would you go to configure Umbrella or Zscaler?
Cloud OnRamp for SaaS with Umbrella
We can also use Cloud OnRamp for SaaS in conjunction with Umbrella. In this design, Umbrella SIG and/or Zscaler Internet Access (ZIA) is treated as an Internet Gateway Site. Let's look at the details.
Knowledge Check
Which of the following is required for Cloud OnRamp for SaaS to work properly through a SIG?
Challenge
To ensure your clear understanding of the concepts in Cisco Umbrella, answer the following questions to the best of your ability. If you have any trouble with a given question, you can then review the correct section above. Good Luck!
Knowledge Check
What unique method does Cisco Umbrella use to provide the first line of defense against threats on the internet?
Knowledge Check
Which Cisco Umbrella feature offers full visibility into internet activity across all locations and users?
Knowledge Check
How does Cisco Umbrella enhance its threat intelligence?
Knowledge Check
Which deployment feature makes Cisco Umbrella quick and easy to implement across an organization?
Answer Explanation:
Anki Deck for Challenge:
Just for fun:
Knowledge Check
How familiar are you with Cisco Umbrella?
This interactive assessment is available in the full learning experience.
View Transcript
Introduction
0:00Hello, and welcome to Introduction to Cisco Umbrella.
0:06In this skill, we're going to take a look at Cisco's cloud-based security
0:11offering,
0:13which is called Umbrella.
0:15We'll start by answering the question, "What is Umbrella?"
0:19and "How can it benefit our enterprise networks?"
0:23Then we'll take a look at the logic behind the traffic flow as Umbrella is
0:28trying to make
0:29a decision as to whether it should permit or deny specific traffic.
0:35Now all of this is part of what's called the SASE architecture.
0:40That is an architecture that Cisco has built Umbrella to fit into.
0:46So we'll see how the different components fall in from Cisco's perspective into
0:51the
0:51SASE architecture.
0:54Then we'll take a look at how to integrate this into SDWAN, because this is a
0:59feature
1:00that we're going to want to tie together with our SDWAN product.
1:04Finally, we'll wrap up with looking at how this integrates with cloud on-ramp
1:11for SaaS
1:12so that we can use this together with Umbrella to choose the best possible exit
1:17for applications
1:18from our network.
1:20So as you can hear, we have quite a bit to cover here, so let's go ahead and
1:24get started.
1:25I'll see you in the next video.
1:27[BLANK_AUDIO]
What is Cisco Umbrella?
0:00So exciting news here, especially for those rainy days, Cisco has now joined
0:08other companies
0:09like Tots in making umbrellas.
0:12Wait, no, that's not right.
0:15No.
0:16Cisco now makes a product called Umbrella.
0:19Now joking aside, this is a cloud-based security product that we can use as a
0:25secure internet
0:27gateway for our SD-WAN environment when going out to cloud providers,
0:32particularly for features
0:34such as software as a service or SaaS.
0:38So let's spend just a moment getting acquainted with what Umbrella actually is
0:43and what features
0:44it brings to the table.
0:48So let's try to answer the question, what is Cisco Umbrella?
0:52Well, to start with, it is part of the Cisco Secure Access Service Edge or SaaS
1:02e.
1:03If you're not familiar with SaaSe, this is actually a term that was coined by a
1:08company
1:08called Gartner in 2019, and the way they define it is it's a network
1:15architecture that combines
1:17particularly security functions along with our WAN or wide area network
1:23capabilities
1:24and the goal is to support dynamic and secure access for the organization.
1:31And that's exactly what Cisco Umbrella does.
1:35Its job is to make it very difficult for attackers to gain access and
1:41infiltrate an organization.
1:44So of course, the real question comes in, how does it do that and how does this
1:49fit into
1:50our whole picture of connecting our Cisco devices into the cloud?
1:56Well it probably helps that Umbrella is itself a cloud delivered secure
2:02internet gateway
2:03or SIG.
2:06So what does all that really mean?
2:08Well what it means is we're going to provide our first line of defense.
2:13In other words, this is effectively going to be our firewall.
2:17And that is certainly one of its features.
2:20But it's a little bit more than that and we'll talk about that as we move
2:23through here.
2:25What's also cool is that this can actually protect users that are both inside
2:31and outside
2:32of the corporate network.
2:34It does this in several different ways.
2:37The first and of course probably the most important is it blocks any malicious
2:42internet
2:43destinations before a connection is established.
2:48So it actually prevents the connection from being established to begin with.
2:53It can do this by blocking unwanted domains, by blocking IP addresses that are
3:00known bad
3:00actors.
3:02So sites that you know are malicious or you don't want people to go to and it
3:06can even
3:07do it based on specific cloud applications.
3:11So there's a lot of different options here.
3:14Let's go ahead and take a look at some of its biggest key features.
3:19Basically how does it accomplish the things we just listed above?
3:23The first is probably its biggest feature, the DNS layer security.
3:29What exactly does that mean?
3:32Essentially it uses DNS.
3:35This is how it's actually preventing those connections from happening.
3:39If I don't resolve DNS requests to well known malicious sites, I can actually
3:46stop the traffic
3:47and of course if I stop it completely, that's going to stop it for all ports,
3:53protocols
3:53and again even direct to IP connections because we're not allowing the name
3:59lookup to begin
4:00with.
4:01Now the way we put Cisco umbrella in the middle of the path so to speak is we
4:07're going to
4:08point the organization's DNS traffic to the Cisco umbrella global network.
4:15This then protects all your devices against threats because it's acting as your
4:20DNS server
4:22and this is how it's going to prevent those connections from occurring to begin
4:26with.
4:26Again, that's the final point here is that it actually blocks those requests to
4:32known
4:33malicious, unwanted or again bad acting domains and the key is before the
4:40connection is even
4:41established.
4:42So there's literally no chance for the bad actors to try to sneak in malicious
4:47traffic
4:48we never connect to begin with.
4:51So this is sort of that first layer of security.
4:54It also provides a secure web gateway.
4:58This is a pretty cool feature because it offers full visibility into all of the
5:03internet traffic
5:05across all your locations, your devices, your users, all of the devices in your
5:11SD WAN and
5:12really in your enterprise network because you're going to send all your traffic
5:17out
5:17to Cisco umbrella.
5:19And what's really cool about this feature is it's multi layered meaning it
5:24includes things
5:25like SSL inspection, URL filtering.
5:29It can even do sandboxing.
5:31So there's a lot of really cool features here.
5:33And again, we'll be digging into some of these more in the upcoming videos.
5:37This again is just our introduction.
5:39Now we already mentioned of course that this also includes a firewall.
5:44It's referred to as the CDFW or the cloud delivered firewall.
5:50This of course functions much like other firewalls where it will log and block
5:55all the traffic.
5:56And of course, like any other firewall, this can block based on the IP address,
6:02the port
6:03number, what protocols being used, and we can have rules to permit or deny any
6:08particular
6:09type of traffic we want.
6:12There's also a piece here called the cloud access security broker or CASB.
6:19Its job is to keep an eye on those SaaS applications specifically.
6:26Again it gives us visibility and control over those SaaS applications that we
6:32're trying
6:32to access from inside of our enterprise.
6:36Another part of this feature is it helps manage and hopefully prevent the use
6:42of shadow IT.
6:44If you're not familiar with the term shadow IT, there's a definition given
6:48below this
6:48video for more complete answer.
6:51But essentially what it means is devices or cloud services that are being
6:56implemented
6:56by your users without necessarily the approval of the IT department.
7:02This is usually going to be for newer technologies that maybe your company hasn
7:07't approved yet,
7:09but the users have decided that it's a cool feature and they want to use it.
7:13So again, maybe some sort of software as a service offering that you haven't
7:17approved
7:18yet, but your users have decided it would help them with their job and they
7:22just start
7:22using it.
7:23Well again, this can help discover that and manage, in other words, stop it
7:29from happening.
7:30So that's another pretty cool feature.
7:33There's another feature, interactive threat intelligence, which is Cisco
7:38umbrella investigate.
7:40And what this does is it gives us historical and real time view of different
7:46domains and
7:47IPs across the internet.
7:49And the cool thing is this allows us to predict, which is always an important
7:54feature, and
7:55prevent attacks.
7:58This is coming from insights.
8:00And what's really important about that is to understand where these insights
8:04are coming
8:05from.
8:06Since umbrella is a cloud service and it's being offered by Cisco, it can
8:12actually leverage
8:14Cisco's global network.
8:17And what does that give us an advantage of?
8:19Well, it gives us fast and reliable protection without sacrificing performance.
8:25The way it's able to do this is by using this global network to be more
8:30predictive and have
8:32a larger array of signatures of different types of attacks because it's using
8:38Cisco's
8:38global network, which of course has visibility into millions of different nodes
8:44and traffic
8:44types.
8:46And one final note here on the umbrella product, there are actually several
8:50different packages
8:52or bundles that are available for umbrella.
8:56There's a link down below to umbrella's product page so you can look at the
9:00different offerings
9:01and such that Cisco has with the umbrella product.
9:06So in this video, we jumped in and just got an introduction to Cisco's cloud
9:11based security
9:13offering umbrella.
9:15Now, over the next couple of videos, we'll spend some time digging into these
9:19features
9:20a little bit more and taking a closer look at how this fits into the rest of
9:25our model.
9:26Part of that is also going to be understanding how the traffic flow through the
9:31umbrella cloud
9:33offering actually works.
9:35So let's start by taking a look at that in the next video.
Understand Umbrella Traffic Flow
0:00So now that we've got a baseline knowledge down for Cisco umbrella, we know
0:08that it's
0:08far more than just the firewall.
0:11We know that it has several different components, including our DNS layer
0:15security, the secure
0:16web gateway, the cloud delivery firewall, which of course is still part of it.
0:21But the question then becomes, how does the traffic actually flow between these
0:26different
0:27components and make decisions as far as whether the traffic should be forwarded
0:31or not?
0:32Well, that's the purpose of this video.
0:34We're going to jump in and we're going to talk about how the traffic gets
0:38flowed logically
0:39between these different components and make the decision as to whether we're
0:42actually
0:43going to send the traffic or if it's going to be denied.
0:46So let's go ahead and take a look at that logical process.
0:52So of course, the very first thing that has to happen is the end user traffic
0:57has to actually
0:57get to umbrella umbrella.
1:00Umbrella of course can't do anything until the traffic arrives.
1:04Well, how's it going to do that?
1:06So it's going to do that through IP sec tunnels that are actually coming from
1:12the SD
1:12WAN devices that are connecting them to umbrella or through end point
1:18connectors, which are
1:20basically end workstations connecting directly into umbrella.
1:25Now once this traffic actually arrives at umbrella, umbrella has to identify it
1:30.
1:31And for the umbrella identities, we have several different things that can use
1:34for classification.
1:36It can classify based on the networks that the traffic is either coming from or
1:42going
1:42to.
1:43It can also identify traffic based on the users, so traffic coming from a
1:49particular user or
1:50from groups.
1:52So we don't have to do everything based on individual users.
1:55We can use groups.
1:57Once we've actually identified that traffic, that is then matched with
2:02destinations that
2:04the traffic is going to.
2:06Once that's determined, of course, we have to figure out what to do with the
2:10traffic.
2:11So we know what the traffic is.
2:13We know where the traffic's going.
2:15Then what we have to do is actually apply the proper policies.
2:20We have to look and see is this traffic supposed to be allowed or is it
2:25supposed to be denied?
2:26And this is sort of where the logic comes in, where we have to look at how the
2:31traffic
2:31is passed between the components.
2:34So let's take a closer look at that actual process.
2:38So as we mentioned in the previous video, the very first thing is we get a DNS
2:44request.
2:45This is where we hit our DNS layer security first.
2:49So of course, the first thing that has to happen is when we look at that
2:52identity and
2:53the destination, we have to figure out which DNS policy is going to actually
3:00apply.
3:01Then we're going to enforce the action either permit or deny that request.
3:07If we permit the request, we're going to send a DNS reply back to the requester
3:12.
3:12If we deny it, then we simply don't answer and the client can't initiate a
3:17connection
3:18because it has no name resolution.
3:20So if the action here is deny, that's essentially the end of the processing.
3:25However, if the action is to permit the traffic, the next thing we did was look
3:31to see if there's
3:32a firewall policy actually enabled.
3:35If there is, we're of course then going to route all of the permitted requests
3:40to the
3:41firewall.
3:43Once it gets to the firewall, of course, the firewall is going to do one of two
3:47things.
3:47That's sort of what firewalls do.
3:49First, it's either going to filter the request if we identify the traffic and
3:54see that it's
3:55going to be denied or we're going to forward that traffic and we forward it to
4:01the secure
4:02web gateway, which is the next component that the traffic is going to go to.
4:07And it's either going to use port 80 or port 443 depending on configuration.
4:14So to get to this point, the traffic has to be permitted by DNS layer security
4:19by the
4:20CDFW and then it gets passed to the secure web gateway.
4:26This is of course assuming that we have a web policy enabled as well.
4:30But if we do, it's going to go to that secure web gateway.
4:34Of course, it's going to receive that from either port 80 or port 443 one of
4:40the two.
4:41But either way, this traffic arrives at the secure web gateway, which just like
4:46the DNS
4:47policy and the firewall policy, we have to look at what the policy actions are.
4:53Once again, it's either going to be permit or deny.
4:57And just like our other policies, of course, if any of these are denied, that's
5:02the end
5:03of the process right there.
5:04The traffic is dropped.
5:06This whole thing stops and the client's been protected.
5:10However, if we have gotten to permit from the DNS request and we've gotten to
5:14permit
5:15from the firewall policy and we've gotten to permit from the web policy, the
5:20final step
5:21here is going to be actually allowing that traffic.
5:25And that traffic is then going to exit umbrella through network address
5:30translation or NAT.
5:32So as is common practice in most environments, we're of course going to be
5:36hiding the internal
5:37addresses behind an outside public address, which actually belongs to umbrella.
5:45So in this video, we just took a look at how the traffic flow logic works
5:50through the different
5:51components in Cisco umbrella.
5:54We saw how it first goes into our DNS layer security.
5:58And if that permits it, it then flows into the firewall.
6:02If it's permitted there, it then flows into the secure web gateway.
6:07And finally, if it's permitted by all three of those components, it then exits
6:12umbrella
6:12through the network address translation component.
6:16Now the next thing we want to look at is to take a closer look at that Saa
6:21architecture
6:22that we mentioned in the first video.
Understand Cisco's SASE Architecture
0:00So now that we've discussed the different umbrella components and how the
0:06traffic is
0:07passed between those components, let's focus in a little bit here on the Cisco
0:12Secure Access
0:13Service Edge or SASE architecture.
0:18This is important to understand, both from the standpoint of what is the
0:21architecture
0:22itself and how do the Cisco components fit into that architecture and then we
0:28'll talk
0:28about the different advantages that the architecture brings to the enterprise
0:33network.
0:34So let's go ahead and jump in and take a closer look at the SASE architecture.
0:41So to begin, let's talk about how Cisco themselves actually define their
0:47architecture.
0:48And the way they describe it is it's combining our VPNs, our SD-WAN services,
0:55and our cloud-based
0:56security services into one common architecture.
1:01Of course, the cloud-based security services we're referring to here is
1:06umbrella.
1:07But before we actually get into all of the different Cisco components, let's
1:10talk about
1:12the SASE architecture itself.
1:15And this has been built around three major principles.
1:19We'll break these down one by one.
1:21The first one is the ability to connect.
1:24And connect, just like it sounds, is simply referring to connecting your
1:29networks to the
1:30various SAS applications out there on the web.
1:35Of course, connecting basically involves your networking.
1:39So this is going to be things like your LAN and WAN, SD-WAN itself, which of
1:44course is
1:45part of WAN.
1:47So remote access for remote users and ZTN or Zero Trust networking, all
1:55different ways
1:56that we can connect our enterprise out to these applications.
2:02Of course, we don't want to allow that connection to just happen without having
2:07control over
2:08it.
2:09So the second principle is to have control.
2:12And this is sort of right out of the definition for SASE, which is we want that
2:17control to
2:18be simplified and we're going to be doing it through policy enforcement.
2:24How?
2:25Well, we're going to do things like segmentation to keep traffic separate and
2:29isolated only
2:30with the components it needs to speak with.
2:32We already talked about DNS security.
2:35That's going to be part of this as well.
2:37Of course, the firewall.
2:39Also, the cloud access security broker.
2:44Remember we talked about that back during the introduction.
2:47This is what provides that visibility over SASE usage.
2:53And remember, it also helps stop that usage of shadow IT or unauthorized
2:59devices and services.
3:01This also includes the secure web gateway and possibly the use of encryption.
3:08All of this together, controlling what is allowed to talk to what in a very,
3:13very secure
3:13fashion using all of these different components.
3:18And our final principle is to converge.
3:21This is sort of going with this concept of combining here.
3:25The idea is we want to take our network and security, connect it all to a multi
3:30-cloud environment
3:32and be able to do it to a scale large enough to handle enterprise networks.
3:38Part of the simplification and advantage of this is being able to do this
3:42through a single
3:43vendor.
3:44Of course, in this instance, we're clearly talking about Cisco.
3:49We also want it to be able to be cloud managed.
3:52That's going to add to the simplification as well.
3:54We can do all of the management through a web interface, which we will see a
3:58little bit
3:59later.
4:00It's being offered as a service, of course, as a service from Cisco, but SaaC
4:06itself is
4:07offered as a cloud-based service.
4:11This is part of what allows umbrella to leverage Cisco's global network to get
4:16all of those
4:16different signatures and basically do its job in a much more effective manner
4:21because
4:21of the information available to umbrella.
4:25So here we did give some specific examples of each of these, however,
4:29understand that
4:30the three major principles are the connect, the control, and the convergence.
4:37So let's take a look at how Cisco implemented this into their architecture.
4:41Cisco's architecture actually has the following components.
4:45First, we have networking, which again is following right along with connecting
4:51.
4:51This is where we're going to include things such as SD-WAN, doing site-to-site
4:56VPNs, zero
4:57trust networking, four remote users, and various other components that connect
5:02all of this
5:03together.
5:05Also of course, we have the security component.
5:08And we've already talked about several of these pieces.
5:10Of course, we have the cloud-delivered firewall, we have intrusion prevention,
5:16we've spoken
5:16about our DNS security, the cloud access security gateway, the secure web
5:22gateway, and
5:23of course, many other components, some of which we've already talked about.
5:28And finally, visibility.
5:30We need to be able to see what's going on in our network.
5:33So part of the solution is going to be to offer end-to-end visibility, both
5:39into performance
5:40and security metrics.
5:42So we need to be able to see what's going on from the network perspective as
5:46well as security.
5:47We need to see if breaches are being attempted, if everything's being protected
5:51.
5:51We need to have reporting and metrics to be able to see what's happening.
5:56So to summarize some of the advantages here, what does SASE actually provide to
6:02the enterprise
6:03network?
6:04First, it provides a cloud networking and security stack that's actually
6:09delivered as
6:11a service in the cloud itself.
6:13Again, in this case, Umbrella being delivered by Cisco.
6:18And the other cool thing is this doesn't have to act as a replacement for more
6:23traditional
6:24enterprise-grade solutions for things like security and overall networking.
6:30It's going to work on top of those to add even more security to our network.
6:35So what are the things that it actually brings to the table that possibly we
6:39didn't have
6:40before?
6:41First, it establishes secure connections for accessing applications, data, and
6:48the internet
6:49for both remote workers, fixed locations, internet-facing devices, really any
6:55sort of
6:55workload that we have on our network.
6:59We also gain end-to-end observability to applications over any network or cloud
7:07.
7:07It also offers optimized performance to ensure the fastest, most reliable, and
7:13secure connection
7:15to the cloud.
7:16It also implements Zero Trust Network Access by verifying user identities and
7:22checking
7:23device health to secure application access on a per-session basis.
7:29And finally, it's going to increase your organization's agility.
7:34It leverages the cloud to simplify your infrastructure and to achieve scal
7:40ability, which is what's
7:41going to give us that agility.
7:44So overall, SASE brings a lot of things to the table.
7:49And again, Umbrella is Cisco's overall product family that fits into this
7:54architecture to
7:56be our secure internet gateway.
7:59So in this video, we simply talked about the SASE architecture, what it's meant
8:05to do,
8:06what it's meant to provide to the enterprise network, the advantages that it
8:10brings to
8:10the enterprise.
8:12And of course, we talked about some of the Cisco components that fit into this
8:16architecture
8:17as part of the Cisco Secure Access Service Edge.
8:21Next, let's take a look at how Umbrella, as a secure internet gateway, fits in
8:27to our SD
8:28WAN architecture.
8:30So let's take a look at how we bring these features together in SD WAN.
8:34[BLANK_AUDIO]
Integrating SD-WAN and SASE
0:00So now that we've talked about what umbrella actually is, how it fits into
0:07Cisco's architecture,
0:09let's take a look at how we actually integrate this with SDWAN.
0:14Now depending on exactly your version of code, this can be either a little bit
0:19tricky or
0:20it can be really easy.
0:22So we're running fairly new code.
0:24We'll talk about the versions here in just a minute, but as long as you're
0:27running fairly
0:28modern code, this is going to be a very easy process.
0:32However, we still have to know how to do it.
0:35So let's go ahead and jump in.
0:37We'll take a look.
0:40So the way that we're going to be connecting SDWAN to our SASE, of course,
0:45specifically
0:46we're talking about umbrella, security on that gateway is we're going to be
0:50connecting
0:51using IP sec tunnels, the same way that we discussed in previous skills, how we
0:57would
0:57connect to any other gateway site that we're going to be using for our internet
1:03gateway.
1:04Now the cool thing is we actually support automatic tunneling to umbrella.
1:09However, in order to do this, we have to have V manage 20 dot five dot one or
1:17higher.
1:18Now remember in newer versions of code, it's actually SDWAN manager, but
1:24regardless of
1:25the name, we need to have at least version 20 dot five dot one or up.
1:31And for iOS X, it has to be 17 dot two dot one are.
1:37So as long as our code is newer than these, which in all honesty are a bit old
1:42at this
1:42point.
1:43So hopefully at the time you're watching this video, you have newer versions of
1:48code
1:48than this.
1:50The other cool thing is they added some other neat features in this code.
1:54First, it gives us a way to connect directly and easily to umbrella DNS
2:01security.
2:02So they added a quick, easy way to do that.
2:05And not only can we connect to umbrella, but they actually gave us the ability
2:11to support
2:11automatic tunneling also to Z scalar.
2:16Z scalar is another company that also offers S a S e services and they have the
2:23equivalent
2:24of a secure internet gateway along with several other products.
2:29But what's cool about this is Cisco added not just support for umbrella, but
2:34also for
2:35Z scalar.
2:36So you can actually use whichever one works best for your company.
2:41Now a couple cool features we support with these tunnels, we can actually
2:44configure a
2:45tracker to keep track if that interface is up or down so we can verify reach
2:52ability.
2:52And not that you necessarily need to, but just be aware, we already discussed
2:57the fact
2:57that these can be automatically configured tunnels, but you can manually
3:02configure them
3:02as well.
3:04And this would actually be required, of course, if you were using older
3:08versions of code.
3:09Now you can still do it on today's code, but we generally prefer to go with the
3:13automatic
3:14option these days since their systems already set up to do it.
3:19This integration also supports high availability.
3:22We do this very simply by configuring a pair of tunnels so that if one tunnel
3:28fails, the
3:29other one will hopefully keep operating.
3:32Some of the attributes of these tunnels by default, these support up to 250 meg
3:39abits
3:39per second and you can have up to 50 tunnels per customer.
3:47And of course, one advantage of having these multiple tunnels is we can either
3:51load share
3:52these with equal cost multipath thing.
3:54We can do that based on applications or we can just use them for failover like
4:00we mentioned
4:01up above with the high availability.
4:05And the final option, if 250 megabits per second is not enough, you can
4:10actually expand
4:11this capacity up to 500 megabits per second per tunnel.
4:17So now that we've talked about some of the attributes and features of these
4:21tunnels,
4:21let's jump into SD-WAN manager and take a look at where we would go to actually
4:26configure
4:27this.
4:28So starting off here on the monitor overview page of SD-WAN manager, where we
4:34're going
4:34to go to configure this, we're going to go to configuration, then we're going
4:38to go to
4:39templates under templates, we're going to go to feature templates.
4:45Then what we're going to want to do is add a new template under the select
4:50device.
4:51Since we're going to create this for the catalyst 8000 V, I'm just going to
4:54type this
4:55in to sort of shorten the list up.
4:58And then we'll go ahead and choose that box.
5:00As soon as we tell it what device it's for, it's going to give us these choices
5:05of which
5:06template type we want to create.
5:08But if we scroll down here a bit to VPN, notice of course there's a bunch of
5:13different choices
5:14here for the templates, but notice the very first one, the Cisco secure
5:19internet gateway
5:21or the SIG.
5:23If we click on this one, it's going to tell us that in order to do this, we
5:28need to create
5:29a SIG credentials template.
5:32Now there's actually two ways is telling us that.
5:35First, there's this big banner that comes up right away at the top, telling us
5:38that we
5:39need the credentials template.
5:40Plus, there's a link right down here that we can click on to create it.
5:45Now we need this because notice that currently the SIG provider is set to be
5:50umbrella.
5:51But also remember we mentioned you can do Z scalar.
5:54If I click Z scalar here, it doesn't really change anything in that it still
5:58wants the
5:58credentials template.
6:00Now if we click generic, this doesn't actually use the credentials template
6:04because you're
6:05going to have to configure that down below.
6:08Now this isn't exactly what we're here to look at right now, but just be aware
6:11this is
6:12an option to look at umbrella.
6:14We need to click back on umbrella.
6:17And then we're going to have to create this template.
6:19Now I don't actually have this set up.
6:21So I'm just going to put in my organization ID.
6:24And then for the registration key and secret, I'm just going to put in some
6:28numbers for now.
6:30Obviously this isn't going to work.
6:32So at this point, we're of course not going to actually be able to connect out
6:36to umbrella.
6:37But let's just go ahead and say save.
6:40So even though that's not actually a valid credential, it doesn't know that.
6:44So it lets us come in here and see what the rest of this would look like.
6:48Now like most things in SD when at this point, we would have to give the
6:52template a name so
6:53we could call it something like umbrella, give it a description.
6:59And if we scroll down and look at the rest of these settings, this is where we
7:02can set
7:03up things like our tracker.
7:05We can actually add a tunnel configuration.
7:09This is where we can configure the high availability.
7:12And there's some advanced settings here at the bottom where we can configure
7:16the umbrella,
7:17primary and secondary data centers.
7:20So as you can see, there's not really a whole lot to configure here.
7:23But this is where we would go to configure our feature template for umbrella to
7:28be used
7:29as our secure internet gateway.
7:32So in this video, we talked about how we can tie umbrella into our SD WAN
7:38environment.
7:40And as we saw, it's as simple as going in and adding a new feature template for
7:45our device.
7:47And then we choose which type of secure internet gateway we want to connect to
7:52either umbrella
7:53or zscaler, or of course, there was also a generic option that we would have to
7:58completely
7:59configure on our own.
8:01Next, let's take a look at how we can tie all this together with on RAM for Saa
8:08S.
Cloud OnRamp for SaaS with Umbrella
0:00Now that we've seen how we can use our feature templates to configure these
0:06tunnels out to
0:08a secure internet gateway such as either Umbrella or Zscaler or maybe another
0:14option, what happens
0:16if we want to provide some sort of load sharing here?
0:20What if we have a connection to both and we would like our applications to
0:24choose the
0:24best path to get out to that particular provider?
0:28Well, the good news is, in a previous skill, we've already looked at a feature
0:33that does
0:34exactly that.
0:36Cloud on RAM for SaaS.
0:39And we can use that here to also choose the best path to go out to the internet
0:45through
0:45a secure internet gateway.
0:48There's just one little thing we have to change and that's what we're going to
0:51talk
0:51about in this video.
0:54So let's go ahead and take a look at how we can combine these two features of
0:58connecting
0:58doors to secure internet gateway and still using Cloud on RAM for SaaS.
1:07So let's just get a couple things out of the way before we get into combining
1:11these
1:11services.
1:12One of the requirements for this to really work properly is the STWAN edge
1:17routers should
1:18be configured to send all of the user traffic over to the secure internet
1:23gateway.
1:24Now when you do that, that's of course going to include all that SaaS traffic.
1:31This is why we want to get Cloud on RAM for SaaS involved in the process.
1:38When we get it involved, we can then use that automatic path selection that we
1:43've talked
1:44about previously to be able to choose the best gateway tunnel to forward that
1:49application
1:51traffic on.
1:52That's our goal here.
1:54And another advantage is these tunnels could then also be used by our branch
2:00offices if
2:01that turns out to be their best path.
2:04So again, the overall idea behind this design is first we're still using the
2:11secure internet
2:12gateway, so we're going to be getting secure access to our applications.
2:18So we're still getting all the advantages of using something like umbrella.
2:24But then we're going to get the best path performance because we're using Cloud
2:30on RAM
2:31for SaaS.
2:33So essentially what we're saying is we're going to get all of the benefits of
2:38Cloud
2:38on RAM for SaaS while still using our secure internet gateway providers.
2:45And again, that could be umbrella or Zscaler or one of the generic solutions.
2:52And there's really only one caveat to this because we've been over this
2:56conversation
2:57before talking about Cloud on RAM for SaaS.
3:02The caveat is how we're actually going to monitor this tunnel.
3:07In order for this to work, you're going to have to enable layer seven health
3:13checks on
3:14this tunnel.
3:16And the way we do that is to simply configure the tracker source address and a
3:23tunnel tracker.
3:24And where we configure that is in the security template or the feature template
3:29that we're
3:29using for our secure internet gateway.
3:33So let's just jump back over to SDWAN and take a look at where that actually
3:37gets configured
3:39in our feature template.
3:41So here we are in our feature template for the Cisco secure internet gateway.
3:46And what we need to do to complete this is first we need to put in a source IP
3:52address.
3:52So here in the source address, we'll put in one of our inside addresses that we
3:57want
3:57to use for the source.
3:59Then we click new tracker and here we have to provide some information.
4:04So first we have to give it some sort of a name.
4:07We could just call it something like tunnel one.
4:10And then you also have to provide some sort of an end point.
4:14And here is where you would put the API URL of the end point that you're trying
4:19to check
4:20with this tracker.
4:22So this is how we would enable those layer seven health checks.
4:27In this video, we talked about combining two of our really cool features.
4:33First using a secure internet gateway such as umbrella.
4:37And second using that together with cloud on ramp for SaaS to then dynamically
4:43choose
4:44the best path exit.
4:46Just remember, in order to do that, you do have to enable the layer seven
4:51health checks
4:52for the tunnel, which we do here with a tunnel tracker.
4:57So that covers everything that we need to discuss in this skill that leaves us
5:02with just
5:03the challenge.
5:04So go ahead and tackle that challenge.
5:07I'll see you in the solution video on the other side.
5:10[BLANK_AUDIO]
Challenge
0:00In this challenge, we're asked to answer a series of questions to verify our
0:07understanding
0:08of the concepts of Cisco umbrella.
0:11So let's go ahead and get started.
0:14Here in our first question, what unique method does Cisco umbrella use to
0:20provide the first
0:21line of defense against threats on the internet?
0:26So let's go down through the answers here.
0:28The first one is behavioral analysis.
0:31This is not going to be a correct answer.
0:35Next is manual URL blocking, which although it can do that, that's not exactly
0:41a unique
0:41method for Cisco umbrella.
0:44Many other products do that.
0:46So I would say that's probably an incorrect answer.
0:49If nothing else is better, we can come back and change this DNS layer security.
0:55Now that is a unique method for Cisco umbrella.
0:58So that's probably a good answer, but let's verify the last one signature based
1:03anti virus.
1:05This is actually not a feature offered by Cisco umbrella.
1:08So this is going to leave our correct answer as DNS layer security.
1:14That is a feature that's available through Cisco umbrella.
1:18That's not a very common feature among security devices.
1:22Next question, which Cisco umbrella feature offers full visibility into
1:28internet activity
1:29across all locations and users.
1:33So going down our answers, first we have the secure web gateway.
1:38That actually sounds like a good answer.
1:40We know that's one of the components of umbrella and that it does in fact offer
1:44full visibility.
1:46But let's verify our other answers before we say that that's our correct answer
1:51.
1:51Next is VPN service.
1:54This is not going to be one of the answers as far as visibility into internet
1:58activity.
1:59Same with data loss protection.
2:02This is not something that's going to offer visibility and the intrusion
2:07prevention system.
2:09These are designed to stop certain types of attacks.
2:12And although they may offer some visibility, I don't think that's what we're
2:15looking for
2:16here.
2:17We're going to say that our best answer is going to be the secure web gateway
2:22because
2:22the way the question is worded, that is exactly what the secure web gateway
2:27does.
2:28Next question, how does Cisco umbrella enhance its threat intelligence?
2:34So our first answer is through partnerships with local ISPs only.
2:40That's not a correct answer.
2:42That is not how they get their intelligence utilizing a global network to
2:48analyze and
2:49learn from internet activity.
2:52That sounds like a good answer.
2:53But again, let's check the rest first by relying solely on user reported data.
3:00That would actually be a pretty poor way to do it.
3:03User provided data is often unreliable using historical data without real time
3:09analysis.
3:10Well, of course, historical data isn't necessarily bad, but we would want real
3:15time analysis.
3:17So in this case, again, our best answer is going to be utilizing a global
3:22network specifically
3:24Cisco's to analyze and learn from internet activity.
3:28And again, that's part of why umbrella is so powerful because Cisco being a
3:32large networking
3:34company sees a lot of traffic to build this threat intelligence off of.
3:40Final question, which deployment feature makes Cisco umbrella quick and easy to
3:47implement
3:48across an organization?
3:51So our first answer is manual configuration of each endpoint.
3:55Well, that would not make it quick and easy.
3:58So that's definitely not going to be a correct answer.
4:01The use of proprietary Cisco hardware.
4:05Well, this doesn't use any form of specific Cisco proprietary hardware.
4:10So that's not going to be correct.
4:12The need for complex onsite configurations.
4:16Well, when the question says quick and easy, somehow I don't think any answer
4:20with the word
4:21complex in it is going to be the correct answer.
4:25So clearly, we're going to be looking for the answer DNS redirection.
4:29As we stated at the beginning of the conversation about umbrella, all we have
4:34to do to implement
4:35this into our environment is to point our DNS servers to Cisco umbrella.
4:41That's the DNS redirection.
4:43So that concludes this quiz.
4:46If you find that you were unable to answer any of these questions, I would
4:50encourage
4:50you to go back and review those sections in the skill above.
4:55Otherwise, congratulations on completing introduction to Cisco umbrella.
5:00I hope this has been informative for you and I'd like to thank you for viewing.
5:04[BLANK_AUDIO]
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year