User Tools

Site Tools


infoblox_threat_defense:cisco_umbrella

Cisco Umbrella

From Cisco's page here and here.

Cisco Umbrella has a Monthly DNS Query Average - more data. More info in product description

With regards to blocked security domains, please note that Cisco Umbrella blocks A, AAAA, ANY, CNAME, PTR, SRV, PRIVATE, SPF/DNS, NULL, SIG, and TXT records, so queries for other record types (MX, SOA, and NS) will be allowed, even though the category is blocked. However, requests for MX records of domains that have been categorized as “DNS Tunneling VPN” will be refused.

Cisco Umbrella won't block TXT records for “content filtering” but will for “threat filtering”. This makes sense as content filtering is for web page access which is A/AAAA/HTTPS records and not TXT.

Cisco Umbrella DNS Servers

Provider IPv4 A IPV4 B IPv6 A IPv6 B Notes DoH DoT DoQ
OpenDNS 208.67.222.222 208.67.220.220
OpenDNS 208.67.220.222 208.67.222.220
OpenDNS Family Shield 208.67.222.123 208.67.220.123 adult

Test Domains

Umbrella Block Page IP Addresses

You will see these IP addresses in responses when Umbrella is blocking the connection

Name IPv4 Address IPv6 Address Example
Domain List Block Page 146.112.61.104 ::ffff:146.112.61.104
Command and Control Callback Block Page 146.112.61.105 ::ffff:146.112.61.105
Content Category Block Page 146.112.61.106 ::ffff:146.112.61.106 www.exampleadultsite.com
Malware Block Page 146.112.61.107 ::ffff:146.112.61.107
Phishing Block Page 146.112.61.108 ::ffff:146.112.61.108 www.internetbadguys.com
Suspicious Response Block Page 146.112.61.109 ::ffff:146.112.61.109
Security Integrations Block Page 146.112.61.110 ::ffff:146.112.61.110
infoblox_threat_defense/cisco_umbrella.txt · Last modified: by bstafford