Cisco Umbrella vs. FireMon

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Umbrella
Score 8.7 out of 10
N/A
Cisco now offers OpenDNS Umbrella Web Filtering. Cisco acquired OpenDNS in August 2015, and rebranded the product as Cisco Umbrella.N/A
FireMon
Score 7.9 out of 10
Enterprise companies (1,001+ employees)
FireMon is a real-time security policy management solution built for today’s complex multi-vendor, enterprise environments. Supporting the latest firewall and policy enforcement technologies spanning on-premises networks to the cloud, FireMon delivers visibility and control across the entire IT landscape to automate policy changes, meet compliance standards, to minimize policy-related risk. Since creating their policy management solution in 2004, FireMon states they've helped…N/A
Pricing
Cisco UmbrellaFireMon
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco UmbrellaFireMon
Free Trial
YesYes
Free/Freemium Version
YesNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
Cisco UmbrellaFireMon
Considered Both Products
Cisco Umbrella
Chose Cisco Umbrella
Cisco Umbrella better integrated into our Cisco environment.
Chose Cisco Umbrella
I reviewed it, but the minor differences were outweighed by the seamless integration with our existing Cisco infrastructure.
Chose Cisco Umbrella
I have used several different solutions over the years. The Cisco Umbrella solution is by far a way better solution than anything I have used. IT is easy to easy with basic implementations vs. others. Cisco Umbrella is more accurate than other solutions (though not as deeper …
Chose Cisco Umbrella
Palo Alto Networks Prisma Cloud
Chose Cisco Umbrella
Different products in different spaces. The Z3 was more of a VPN endpoint so that users didn't have to worry about a client. If they are at home, they are on their corporate network and able to access resources. Cisco Umbrella can be used then to serve corporate DNS across the …
Chose Cisco Umbrella
Cisco Umbrella have the biggest brainpower behind their products and is also from one of the biggest and best players in the Network market.
Chose Cisco Umbrella
Cisco has more options in configuring monitoring/blocking.
Chose Cisco Umbrella
Cisco Umbrella did what we needed it to do far more than the other apps that we tried out. For mobile work on MacBook and iPads, Cisco Umbrella was the best option for our district. The cost was lower as well and did not lower the level of security we received because of lower …
Chose Cisco Umbrella
Have not used similar products
Chose Cisco Umbrella
I really like it for this price point.
Chose Cisco Umbrella
We evaluated a lot of products. The good part is that we didn't go outside. So Ineos grew by acquisition and therefore we inherited a lot of products there. So we looked at the Netskope and Fortinet because they were within our sphere of product portfolios that we had in the …
Chose Cisco Umbrella
Price and integration to Meraki MX, plus ability to protect endpoints with roaming module. Umbrella also came with DLP and evolved to Cisco Secure Connect (special offering for Meraki)
Chose Cisco Umbrella
We just trust Cisco provides a solid reliable solution in Cisco Umbrella, so no other was really needed to be considered.
Chose Cisco Umbrella
Better integration with other Cisco portfolio of products.
We have an enterprise subscription and Cisco Umbrella dns was already included as part of the offering.
Also we are looking into integration with sd-wan in sites where it is hard to provide full spectrum of services that …
Chose Cisco Umbrella
Webex calls are protected by Cisco Umbrella
Chose Cisco Umbrella
Auto SIG Tunnels is a feature that helps in provisioning tunnels automatically using Cisco Umbrella APIs and so this is one win for choosing Cisco Umbrella over others. With Cisco SD-WAN Viptela, the Cisco Umbrella stacks up well because its the same vendor so less …
Chose Cisco Umbrella
Legacy implementation, which was unscalable.
Chose Cisco Umbrella
I am evaluating Cisco umbrella against forcepoint we proxy to consolidate two solutions into one
Chose Cisco Umbrella
Curated filtering lists make Umbrella much easier to maintain than running your own DNS-based filtering
Chose Cisco Umbrella
Barracuda has some additional feature sets in its physical Web Security Gateway hardware, however Umbrella has been more reliable for what we are doing in our environment.
FireMon
Chose FireMon
FireMon gives us more flexibility when deploying the solution. Integrates with cutting-edge security solutions
Chose FireMon
We have only used firemon and there hasn't been a need to consider other products as we are satisfied with what Firemon can do.
Chose FireMon
Firewall Rule analyzer was used before I joined the company, but I have no experience with it.
Chose FireMon
OSSEC is open source and FM is much better from GUI and supportability stand points. Tufin and FireMon are very comparable
Chose FireMon
Best Compliance and Auditing tool to to identify the traffic that is hitting this rule.
Chose FireMon
I was not involved on the decision but having multiple brands in the company make sense to use a tool such as Firemon because it integrates easily with multiple vendors.
Chose FireMon
Infoblox DDI (BloxOne), Palo Alto Networks Prisma Cloud, Palo Alto Panorama, Palo Alto Networks Threat Protection, Palo Alto Networks WildFire, Palo Alto Networks Next-Generation Firewalls - PA Series and Fortinet FortiGate
Chose FireMon
Algosec and Tufin both are good tools but the cost involved for what they offer as services led us to go with Firemon.
Chose FireMon
i was not involved in the selection however i am quite happy with FireMon as the replacement of our aging product.
Chose FireMon
We have stuck with FireMon, and there is no reason to leave.
Chose FireMon
The Dell product ran on its own hardware, which failed often. The reports were not available to us in real-time, we had to request them. Many false detections of issues.
Chose FireMon
Both perform admirably with regards to providing that single pane of glass and visibility in a normalized view. They both provide great insight into where your organization stands in terms of compliance controls. In terms of upgrading and scalability, I would have to give the …
Chose FireMon
I has worked with Algosec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can …
Chose FireMon
FireMon has the most supported devices.
The UI is easy to use and intuitive.
There is a comprehensive list of built in compliance controls that are missing in the competition.
Chose FireMon
To be blunt, at the time of purchase most of these products appeared to do the same things in the same ways. What really brought us to the table with FireMon six years ago was their willingness to earn our business, and to this day they remain just as committed to keeping our …
Chose FireMon
FireMon is way more flexible and the interface is tremendously better than any existing ones.
Chose FireMon
Algosec is a great tool, lower in cost as well.

FireMon has alot of capabilites, but our organization is not ready or have a use case yet for those features.
Chose FireMon
Tufin works much better with CheckPoint.
Chose FireMon
They are two very well done tools, FireMon is better suited for firewall rules evaluation, configuration and review, Tenable.io is better suited for CIS benchmarking. We ended up using both of them in the end, it really depends of your needs and what you are looking for, the …
Chose FireMon
Nothing like FireMon. We have other tools but 99% of them are looking at specific areas and not the enterprise security on a dashboard.
Chose FireMon
We performed a head-to-head PoC between FireMon and AlgoSec several years ago. Both platforms were well developed, but FireMon had the upper hand in three areas:
  1. Its UI was more unified and intuitive across the different components and products
  2. The reporting was better suited …
Chose FireMon
AlgoSec and Tufin both have initial issues during the POC stage, and FireMon even though with the changes they have made still works better and is more user friendly.
Best Alternatives
Cisco UmbrellaFireMon
Small Businesses

No answers on this topic

NinjaOne
NinjaOne
Score 9.0 out of 10
Medium-sized Companies

No answers on this topic

NinjaOne
NinjaOne
Score 9.0 out of 10
Enterprises
Zscaler Internet Access
Zscaler Internet Access
Score 8.8 out of 10
Cisco Meraki MX
Cisco Meraki MX
Score 9.1 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco UmbrellaFireMon
Likelihood to Recommend
8.3
(0 ratings)
7.9
(0 ratings)
Likelihood to Renew
8.0
(0 ratings)
6.8
(0 ratings)
Usability
8.0
(0 ratings)
7.3
(0 ratings)
Availability
8.7
(0 ratings)
7.3
(0 ratings)
Performance
8.0
(0 ratings)
9.1
(0 ratings)
Support Rating
7.0
(0 ratings)
7.7
(0 ratings)
Online Training
8.0
(0 ratings)
-
(0 ratings)
Implementation Rating
9.5
(0 ratings)
9.1
(0 ratings)
Ease of integration
9.5
(0 ratings)
-
(0 ratings)
Product Scalability
8.0
(0 ratings)
7.9
(0 ratings)
Vendor post-sale
8.0
(0 ratings)
-
(0 ratings)
Vendor pre-sale
8.0
(0 ratings)
-
(0 ratings)
User Testimonials
Cisco UmbrellaFireMon
Likelihood to Recommend
It is good for whole network protection, and individual PCs with the client. Provide good reporting on where your network is going on the net. One thing I would like is a longer history with the logs 14 and 30 days are too short some times.
Read full review
FireMon is best used in a large environment (for example, I have >100
firewalls in my environment). It's best used when trying to improve
security posture and showing changes in firewall security over time. It
might not be the best choice for smaller environments or those that aren't concerned about security management.
Read full review
Pros
  • Managing the overall security policies is quite seamless in Cisco Umbrella. it is quite easy to set up and implement web filtering rules and other necessary configurations without any hassle.
  • The reporting features like 'activity search' provides greater visibility of our user's internet activity within our organization. We can identify security related risks quickly and take decisions to mitigate them.
  • The deployment and integration of Cisco Umbrella with other vendors product is quite appreciable. We other non cisco security devices which Cisco Umbrella was integrated with without any major issues.
  • We can easily track down any user that goes to the internet through the activity search feature.
Read full review
  • PCI Reporting - After identifying which firewalls and rulesets are in scope, producing a report artifact to satisfy PCI requirements on Firewall reviews is literally a two-click operation.
  • Storing Rule Metadata - FireMon stores metadata (prefilled fields, standard fields, and custom fields) for each rule in each policy which is valuable for context during firewall reviews in particular
  • API - FireMon exposes most if not all of its functionality via REST API
Read full review
Cons
  • There's always room for improvement in all products for sure. On the umbrella part, I would say that the room for improvement is on the data loss prevention part. So it sits on the PCs, it sees a lot of the traffic that goes on, it knows what files are on the PCs, but it's actually not stopping some of the intellectual property or personal identifiable information from going out. So we are able to block users from accessing applications and websites or even IP addresses, but we're not able to go a bit more granular, more on the data loss side. So that's a gap that I have in the product.
Read full review
  • Some features could be added to the existing functionality which include NAT rules usage
  • Rule expiration normalization from firewalls rather than entering them in rule documentation
  • .csv exports of the files from the firewall pane only gives usage for 30 days by default and that should be increased
Read full review
Likelihood to Renew
First off I never give anything a "10" unless it's perfect. LOL - I grade on the curve. I think OpenDNS/Umbrella is a very good product. I think that fact that Cisco absorbed them is one of the proofs of that. I have used the product back when it was free for companies our size. I have not always appreciated the cost - but in the post pandemic cyber chaos, I believe the cost benefit ratio is still very high. I have honestly not looked at other products because Umbrella continues to work to my satisfaction. I consider Umbrella to be one of the key layers in my cyber security strategy.
Read full review
Once all the customization has been completed, the business is starting to see the return on investment. The visibility it provides into the network gear that is owned by other IT groups is immeasurable and has allowed us to apply standards across the board. The only thing I have concern with is their support documentation.
Read full review
Usability
The product was easy to install and get running. To maintain the product is also a simple matter of maintaining lists of wanted and unwanted domains or URLs. The basic and advanced security features all do what they are intended to do with no known erroneous outcomes
Read full review
It save me time and I'm able to have the review - review the rule independently with using my time.
Read full review
Reliability and Availability
Cisco umbrella services in the cloud are always available. However, the weakness is the VM installed in the data center that are the first resolvers. If the VMs become unavailable for any reason or the vSphere goes down, then all DNS is affected
Read full review
FireMon has been relatively stable overall. However, there have been a handful of times where we had issues with the console. For example, we couldn't update which devices to include in a security assessment. The initial suggestion from support was to just reboot it. It seems like there weren't many other options available such as to restart services before going to the extreme of a complete reboot.
Read full review
Performance
our experience with cisco products has always been awesome and same is the case with cisco umbrella .Under umbrella cisco provides flexible and scalable software solution to use across different dept and sites . These softwares are very user friendly ,pages load quickly as these applications are designed for minimum latency and reports are also provided quickely
Read full review
I'm not sure we have the largest implementation of FireMon out there but we do have a few 1000 devices being probed by FireMon. Overall, the system's performance has been rock solid. The console refreshes quickly and reports are generated within an expected timeframe.
Read full review
Support Rating
Whilst the support is good once you get through to them, it's email only and the response is slow. This is a issue, because its a core system that needs to work. We have had issues in the past where several of our companies have gone down due to Umbrella and support is nowhere to be seen. It is very difficult to know whether Umbrella is having service issues, since they do not regularly update customers on the status of their services, such as is seen by providers such as Microsoft (status.umbrella.com just seems to show up all of the time, I'm not sure it's even updated)
Read full review
FireMon technical support is awesome! They respond quickly to our requests and they are well trained and very knowledgeable about the tool. Some issues have to be referred to the development team, but technical support largely provides solutions for any issues that we may have.
Read full review
Online Training
Quite easy to understand training modules prepared by knowledgeable trainers. Training modules have included all the desired features of these softwares and the content delivery is very good from the respective module trainers and it explains in details the features and apart from that further training material support is also provided if needed.
Read full review
No answers on this topic
Implementation Rating
At the time we were forced to move from Cloud Web Security to Cisco Umbrella, Cisco Umbrella was far from being a direct replacement. It was frustrating and difficult to migrate due to the lack of functionality. This has since been addressed, however we now have legacy rulesets that were built as bandaids that cannot be removed. Hopefully the migration to Secure Access will address this.
Read full review
Implementation is fairly simple. Most issues can be resolved by referencing manuals.
Read full review
Alternatives Considered
Different products in different spaces. The Z3 was more of a VPN endpoint so that users didn't have to worry about a client. If they are at home, they are on their corporate network and able to access resources. Cisco Umbrella can be used then to serve corporate DNS across the VPN tunnel to the Z3 device and extend the capabilities of Cisco Umbrella.
Read full review
I has worked with AlgoSec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can easily import firewalls and begin to work on them to improve them
Read full review
Scalability
Cisco umbrella provides fleaxible and scalable software solutions which are easy deploy across multiple departments and sites wherever needed and this softwares are very easy to use and provides the best interface along with cisco support for other devices apart from cisco infrastructure but still there is scope for improvement on the inclusion of latest features
Read full review
Firemon Is easily scalable and maintainable with any size team. Although it requires some tech debt, it is well worth the time to invest to ensure compliance is visible and reports are accurate. Although our environment is very large we do not fully utilize the scalability of the Firemon product.
Read full review
Return on Investment
  • It's too early for us to say now. We started with Cisco Umbrella with the migration and during the migration we choose all the specific access. Now we are going to Cisco Secure Access in our simulations there will be much of cost savings because we don't need the on-premise data center anymore for the ASARs and for the local firewalls and the people, they are managing that on-premise. So we estimate there will be a lot of cost savings, but currently it's not on the paper yet. So we have to wait what the experience is with it, but we are optimistic.
Read full review
  • It helps us save us time in determining what change was made and by whom.
  • Real time alerting is a great convenience in helping us know if something went wrong, we can immediately review the last report to determine what has changed.
  • Allows us to determine what rules are not used and if said rules are still required.
Read full review
ScreenShots