The Umbrella Documentation Hub

Welcome to the Umbrella documentation hub. Here you'll find access to all of our Cisco Umbrella user guides.

Get Started    

Sites and Internal Networks

Before You Begin

If you intend to implement Active Directory integration, in addition to the virtual appliances (VAs), see Appendix B – Multiple Active Directory and Umbrella Site as the use cases and guidelines differ slightly.

In the context of virtual appliances (VAs), Umbrella sites represent the physical location of your network, and specifically the internet egress point—the DNS egress point.

Each egress requires separate VAs. For more information, see Deploy Virtual Appliances.

Having separate Umbrella sites is important for identifying the physical location of the VAs, the association of network traffic, and logical automatic updating of the VAs.

Manage Umbrella Sites


If you are only deploying VAs at a single location, you may skip this section.

If you are deploying VAs at multiple locations and if the internal IP space of each site location overlaps or is shared, you must set up multiple Umbrella sites. For each office with VAs, a separate Umbrella site can be added to group VAs together with a label. Note that you must do this when the IP space overlaps.

  1. Existing VAs and Umbrella site configurations can be accessed in the Umbrella dashboard at Deployments > Configuration > Sites and Active Directory.
  2. Expand a deployed VA by clicking its name.
  3. From here, you can add a new Umbrella site, or assign a VA to an existing site by selecting a site and clicking Save.

Introduction to Internal Networks

The IP address is utilized in Umbrella reports and analytics, and is used when creating policies for security and category filtering. For more information about policies, see Manage Policies.

Manage Internal Networks

The Internal Networks list is found in the Umbrella dashboard at Deployments > Configuration > Internal Networks.

Adding a single IP address or range of IP addresses in the dashboard creates a new "Identity" under which the traffic can be identified and filtered.

Reroute DNS < Sites and Internal Networks > Configure Dual-NIC Support

Updated 9 months ago

Sites and Internal Networks

Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.