Connect to Cisco Umbrella Through Tunnel

To create an IPsec tunnel, you must connect to at least one of the Umbrella head-end IP addresses listed in the tables referenced here. Some data centers support /automatic failover, which provides redundancy for a single tunnel configuration. However, we recommend configuring two tunnels, one to each data center (DC) in a region, with unique IPsec tunnel IDs per tunnel.


The data centers listed here are only for IPsec connections to the Umbrella secure web gateway (SWG) and cloud-delivered firewall (CDFW). Cisco Umbrella has additional data centers for non-IPsec connections to SWG. For a list of Umbrella data centers, see Global data centers.

Table of Contents

Data Centers with Automatic IPsec Failover


IPsec Failover

These Cisco Umbrella data centers implement automatic failover of IPsec tunnels when a data center is unavailable. When this occurs, tunnels automatically move from one data center in a region to the other. A backup tunnel is not required but is still recommended. A backup tunnel allows you to continuously monitor your tunnels and manually move from one data center in the region to the other instead of waiting for Umbrella failover.

In deployment samples in the Network Tunnel Configuration guides, <umbrella_dc_ip> refers to these IP addresses.

Region CodeDC LocationIPFQDN
US-1Los Angeles, CA,
US-1Santa Clara (Palo Alto), CA,
US-2New York, NY,
US-2Ashburn, VA,
US-3Miami, FL,
US-3Atlanta, GA,
US-4Dallas–Fort Worth, TX,
US-4Denver, CO,
US-5Minneapolis, MN,
US-5Chicago, IL,
EU-1London, United
EU-2Prague, Czech
AF-1Johannesburg, South
AF-1Cape Town, South
BR-1Rio de Janeiro,
BR-1São Paulo,
LA-1Miami, FL, US **

** Miami will be replaced by a second Latin America DC with its own IP address in the future. Customers can use Miami for automatic failover, or manually configure another data center for backup tunnels.

Data Centers without Automatic IPsec Failover

IPsec connections to the following data centers must be configured with a backup tunnel. Cisco does not prescribe specific backup locations for these DCs. Backup connection can be made to any IPsec-enabled Umbrella data center (including those DCs with automatic IPsec failover).

DC LocationIP
Dubai, United Arab Emirates146.112.110.8
Dublin, Ireland146.112.99.8
Hong Kong, China146.112.114.8
Marseille, FranceTo be announced.
Manchester, UK146.112.122.8
Reston, VA, USTo be announced.

Tertiary/Disaster Recovery Data Centers

The data centers listed in the following table currently support automatic, tertiary failover or disaster recovery (DR). Previously, Umbrella supported automatic, tertiary failover for all regions. It is no longer available for US, Canada, Brazil, Latin America, Asia-Pacific, or Oceania regions, and will be removed in the future for remaining regions. Customers can optionally set up their own tertiary failover as a third tunnel to another region.

Region CodeFailover (DR) Location
EU-1Amsterdam, NL
EU-2Amsterdam, NL
EU-3Amsterdam, NL
EU-4Amsterdam, NL
AF-1Amsterdam, NL

Supported IPsec Parameters < Connect to Cisco Umbrella Through Tunnel > Monitor Network Tunnel Status