<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point vs Cisco Umbrella in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250500#M41902</link>
    <description>&lt;P&gt;This clears up a lot of thing. Thank You.&amp;nbsp; I understand, If I want to replace Umbrella then I would have to use our DC as a DNS server and Public DNS server for recursion and also for FWs. On top of that, segregation of DC and network will be required as well to make FWs inline.&amp;nbsp; I am worried about using Public DNS for the purpose as I am not sure how much it will impact regarding the security of the network or may be I should use DC as a conditional forwarder for top destinations like google and use Public DNS for those to limit the risk at least and continue with Cisco Umbrella for remaining requests to reduce its licensing cost.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jun 2025 16:29:16 GMT</pubDate>
    <dc:creator>Zee</dc:creator>
    <dc:date>2025-06-03T16:29:16Z</dc:date>
    <item>
      <title>Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250374#M41852</link>
      <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;I am just curious about a network change in our environment. Currently we are using Cisco Umbrella as our DNS server and security layer for all external/public requests. Do you think BIND + Checkpoint can give the same functionality in terms&amp;nbsp; of DNS security for a comparatively large, spread environment?&amp;nbsp;&lt;BR /&gt;And what do you suggest for a short and quick alternate to decrease the number of requests being handled by Cisco Umbrella, using Checkpoint blades with DC (as a cache for external domains/requests) keeping in mind the trade off with logging and security issues like TTL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 16:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250374#M41852</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-02T16:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250391#M41855</link>
      <description>&lt;P&gt;Check Point DNS Security is handled through Anti-Bot and Anti-Virus Blades.&lt;BR /&gt;There is some &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ThreatPrevention_AdminGuide/Content/Topics-TPG/Configuring-Anti-Bot-Settings.htm" target="_self"&gt;additional functionality&lt;/A&gt; incorporated in the gateways starting from R82.&lt;BR /&gt;I assume if you route the requests to Umbrella through a Check Point device that has Anti-Bot and Anti-Virus enabled, you'll see less requests sent there.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 21:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250391#M41855</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-02T21:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250424#M41865</link>
      <description>&lt;P&gt;Thank You for your response and Yes, I am exploring Check Point DNS security but I just wanted to discuss if replacing Cisco Umbrella with BIND and Checkpoint Blades will give me the same functionality as currently being given by Cisco Umbrella, we are trying to minimize the license cost of Umbrella and also number of requests have increased than allowed, so kind of in a pickle right now.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 06:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250424#M41865</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-03T06:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250493#M41897</link>
      <description>&lt;P&gt;In terms of actually preventing potential threats via DNS, I'd say both are similar in this regard.&lt;BR /&gt;However, I haven't seen any head-to-head comparisons that (dis)prove this.&lt;/P&gt;
&lt;P&gt;Remember that Cisco Umbrella is, itself, a DNS server.&lt;BR /&gt;We are not a DNS server, though with &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Hosts-and-DNS-DNS-Proxy-Forwarding-Domains.htm" target="_self"&gt;dnsmasq being officially supported in R82&lt;/A&gt; (it's also available in earlier releases, &lt;A href="https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/" target="_self"&gt;albeit through an unsupported process&lt;/A&gt;), that isn't entirely true any longer.&lt;BR /&gt;Our enforcement for DNS-related protections require us to be inline with the DNS server (i.e. so we can see requests).&lt;BR /&gt;This also changes some of the functions needed (for example, to see DNS over HTTPS, this must be handled inline via HTTPS Inspection, which we do in R82).&lt;/P&gt;
&lt;P&gt;Which means, if you're looking to replace Umbrella, you need to understand how it's being used in your environment.&lt;BR /&gt;Another thing to consider is, if you're using any FDQN Domain objects or Updatable Objects in your policy is that DNS server used by the clients should be exactly the same as that of the gateway.&lt;BR /&gt;Otherwise, the IPs for, say, cdn.example.com might resolve to a different IP, which creates enforcement issues.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 17:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250493#M41897</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-03T17:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250500#M41902</link>
      <description>&lt;P&gt;This clears up a lot of thing. Thank You.&amp;nbsp; I understand, If I want to replace Umbrella then I would have to use our DC as a DNS server and Public DNS server for recursion and also for FWs. On top of that, segregation of DC and network will be required as well to make FWs inline.&amp;nbsp; I am worried about using Public DNS for the purpose as I am not sure how much it will impact regarding the security of the network or may be I should use DC as a conditional forwarder for top destinations like google and use Public DNS for those to limit the risk at least and continue with Cisco Umbrella for remaining requests to reduce its licensing cost.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 16:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250500#M41902</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-03T16:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250502#M41903</link>
      <description>&lt;P&gt;For what its worth, I know few customers who use below public dns servers and so far, I heard no complaints.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://quad9.net/" target="_blank"&gt;https://quad9.net/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 16:41:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250502#M41903</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-03T16:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250503#M41904</link>
      <description>&lt;P&gt;In larger environments, it's typical to have internal DNS servers (can be Active Directory, BIND, or something else) that forward requests to public DNS servers for anything that it can't resolve.&lt;BR /&gt;There is also two different versions of DNS for a given domain (internal, which has everything, and external, which only has externally accessible servers).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While forwarding requests for some domains directly to public DNS might help in your quest to reduce overall usage of Cisco Umbrella, I'd be careful with certain domains:&lt;BR /&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/azure-domains-and-google-abused-to-spread-disinformation-and-malware/" target="_blank" rel="noopener"&gt;https://www.bleepingcomputer.com/news/security/azure-domains-and-google-abused-to-spread-disinformation-and-malware/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 17:10:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250503#M41904</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-03T17:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250515#M41907</link>
      <description>&lt;P&gt;Yes, I agree quad9 is better among others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:11:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250515#M41907</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-03T19:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250516#M41908</link>
      <description>&lt;P&gt;Thats my experience as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:13:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250516#M41908</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-03T19:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250517#M41909</link>
      <description>&lt;P&gt;Microsoft and Google will probably be the domains for which DC along with Public DNS will be used to reduce the usage as a quick fix I guess, and to use Checkpoint with Bind makes a persistent solution instead of just Checkpoint I suppose.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:15:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250517#M41909</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-03T19:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250518#M41910</link>
      <description>&lt;P&gt;Yes,&amp;nbsp; I might need to use quad9 in future and explore Checkpoint more before making this change.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:18:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250518#M41910</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-03T19:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250549#M41912</link>
      <description>&lt;P&gt;One more thing, I can work around with dnsmasq as well, right? If I use conditional forwarding in DC for some public domains and forward it to checkpoint instead of public dns and use dnsmasq and forward it to public dns from there, checkpoint will log the traffic then and I won't have to change my network so that checkpoint can be configured inline. I am not sure about https inspection. Do you think it is a good option?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:24:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250549#M41912</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-04T09:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250563#M41913</link>
      <description>&lt;P&gt;I know it works in R82 as well, though not supported officially.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250563#M41913</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-04T10:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250588#M41915</link>
      <description>&lt;P&gt;Yes, but I am not sure about it's reliability as it is not supported officially but I need a quick fix somehow this week to minimize the requests going to Cisco Umbrella.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:53:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250588#M41915</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-04T12:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250589#M41916</link>
      <description>&lt;P&gt;I know this link is 11 years old, but commands do work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/" target="_blank"&gt;https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:55:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250589#M41916</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-04T12:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250596#M41918</link>
      <description>&lt;P&gt;And after all those years, checkpoint is still not giving official support to it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Any specifics to keep in consideration while testing all blades related to DNS and Web filtering as we were not using them in our environment due to Cisco Umbrella.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250596#M41918</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-04T13:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250598#M41920</link>
      <description>&lt;P&gt;Maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;can confirm, but dont believe it was ever officially supported, so use at your own risk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250598#M41920</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-04T13:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250601#M41922</link>
      <description>&lt;P&gt;Agreed, and I would like to hear your thoughts about the blades and checkpoint performance incomparable to Cisco Umbrella, if you have used in a similar way. I could not find a subtle and well documented thing till now which can increase my confidence that Cisco Umbrella can be replaced by Checkpoint and not impacting the security and reliability of the services. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250601#M41922</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-06-04T13:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250603#M41923</link>
      <description>&lt;P&gt;I cant say for sure when it comes to Cisco Umbrealla, as I had never used it myself, but one customer I work with often, they have used it for some time and they seem happy with it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:47:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250603#M41923</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-04T13:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point vs Cisco Umbrella</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250612#M41924</link>
      <description>&lt;P&gt;We've used dnsmasq on our SMB appliances for quite some time (since the transition from the legacy &lt;A href="mailto:Safe@/Sofaware" target="_blank"&gt;Safe@/Sofaware&lt;/A&gt;&amp;nbsp;appliances).&lt;BR /&gt;As near as I can tell, we've been including dnsmasq in regular, non-Embedded Gaia for a number of years now (at least as far back as R77.x).&lt;BR /&gt;However, R82 is the first time dnsmasq has actually appeared in product documentation.&lt;BR /&gt;That would suggest it is supported in R82, at the very least.&lt;/P&gt;
&lt;P&gt;While it definitely works in versions prior to R82, I'm fairly certain it's not officially supported.&lt;BR /&gt;Having said that, it's best to engage with your local Check Point office here.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-vs-Cisco-Umbrella/m-p/250612#M41924</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-04T14:38:09Z</dc:date>
    </item>
  </channel>
</rss>

