The Umbrella Documentation Hub

Welcome to the Umbrella documentation hub. Here you'll find access to all of our Cisco Umbrella user guides.

Get Started    

Test the Intelligent Proxy

Once you've applied the policy to an identity, such as your laptop or mobile device, go to the test site:

http://proxy.opendnstest.com/

Follow the instructions on the page to see how Umbrella can block an image within an otherwise good website, or block entire websites using the intelligent proxy.

If you find that the test site indicates you're not using the intelligent proxy, check to make sure the identity you're using has intelligent proxy capabilities enabled in the policy that's applicable to it.

To determine if a domain is being resolved to the intelligent proxy, and then being proxied, perform a lookup of the domain from an identity using the proxy.

If the IP address of "domain.com" comes back with an IP address within the range 146.112 / 16 (for example, 146.112.0.0 / 255.255.0.0), then it's being directed through the intelligent proxy. To avoid this from happening, specifically add this domain to an allow list or the global allow list for your organization.

Note: We also do not proxy traffic on non-standard ports for web traffic. This means that traffic to a proxied domain that is on a port other than 80 or 443 will be dropped when it reaches the proxy. If you wish to prevent this, add the domain to a global allow list.

Test Selective Decryption

To create a test that the website or other destination you want to visit will not be inspected by the intelligent proxy when the intelligent proxy is enabled:

  1. Within a test policy, enable the intelligent proxy, including enabling SSL decryption, and installing the Cisco root certificate.
    Do not enable selective decryption.
  2. Create a destination block list and add a destination that is a member of the content category you will later add to the selective decryption site for this test.
    For example, the content category we will use for this example is News/ Media. Add www.cnn.com to the block list.
  3. Navigate to www.cnn.com.
  4. View the browser certificate. It should be the Cisco root certificate.
  5. Create a selective decryption list and add the News/ Media content category to it.
  6. Navigate to www.cnn.com.
  7. View the browser certificate. It should be CNN's certificate.

Enable the Intelligent Proxy < Testing the Intelligent Proxy > Reporting and the Intelligent Proxy

Updated 2 years ago

Test the Intelligent Proxy


Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.