



When the client is connected to a web proxy, the DNS query does not pass through the Cisco 1000 Series ISR. If an application or host uses IP address directly instead of DNS to query domain names, policy enforcement is not applied. Restrictions for Cisco Umbrella Integration Additional References for Cisco Umbrella Integration.Deploying Cisco Umbrella Integration Using Cisco Prime CLI Templates.Troubleshooting Cisco Umbrella Integration.Verifying the Cisco Umbrella Connector Configuration.Benefits of Cisco Umbrella Integration on Cisco 4000 Series ISRs.Cloud-based Security Service Using Cisco Umbrella Integration.Prerequisites for Cisco Umbrella Integration.Restrictions for Cisco Umbrella Integration.This feature is available on Cisco IOS XE Denali 16.3 and later releases. Cisco 4000 Series ISR acts as a DNS forwarder on the network edge, transparently intercepts DNS traffic, and forwards the DNS queries to the Cisco Umbrella portal. The security administrator configures policies on the Cisco Umbrella portal to either allow or deny traffic towards the fully qualified domain name (FQDN). The Cisco Umbrella Integration feature enables cloud-based security service by inspecting the Domain Name System (DNS) query that is sent to the DNS server through the Cisco 4000 Series Integrated Services Routers (ISRs). Cisco Umbrella Integration on Cisco 4000 Series ISRs
