Guides
ProductDeveloperPartnerPersonal

Cisco Catalyst 9200 and Catalyst 9300 Switches

The Cisco Umbrella integration enables a cloud-based security service by inspecting the Domain Name System (DNS) query that is sent to the enterprise DNS server through the Cisco Catalyst 9200 or Catalyst 9300 network switch. The security administrator configures Umbrella policies to either allow or deny traffic towards the fully qualified domain name (FQDN). The Cisco Catalyst 9200 or Catalyst 9300 switch acts as a DNS forwarder, transparently intercepts DNS traffic, and forwards the DNS queries to the Cisco Umbrella cloud. This feature is available on Cisco IOS XE Amsterdam 17.1.x and later releases.

Prerequisites

Before you configure the Cisco Umbrella integration feature on the Cisco Catalyst 9200 or Catalyst 9300 switch, ensure that you have the following:

  • The Cisco Catalyst 9200 or Catalyst 9300 switch runs the Cisco IOS XE Amsterdam 17.1.x software image or later.
  • The Cisco Catalyst 9200 or Catalyst 9300 switch must have a DNA Advantage or higher license to enable Umbrella.
  • A valid Cisco Umbrella subscription license.

The following network requirements must be met:

  • For initial registration, the interface configured as “umbrella out” must be able to access api.opendns.com over port 443 in order to complete initial registration.
  • TCP and UDP on port 53 (DNS) to 208.67.220.220 and 208.67.222.222—the Cisco Umbrella public DNS resolvers.

The 17.1 and later releases include support for internal IP visibility for DNS queries. Active directory integration with Umbrella is supported with the 17.3 and later releases.

For Active Directory integration on the Catalyst 9200 and 9300 switch:

  • An active Umbrella Active Directory connector for provisioning AD user and group identities to Umbrella. See Provision Identities from Active Directory.
  • 802.1x Port-Based Authentication on the Catalyst switch should be done using the User Principal Name only (sAMAccountName is not supported).
  • User Principal Name of end-users should not contain non-English characters.

For more information, see:


Integration for RV-series Routers < Cisco Catalyst 9200 and Catalyst 9300 Switches > Cisco DNA Center