Last year, Belnet launched a new tender for Advanced DNS Security. Following a rigorous evaluation, the Cisco Secure Access – DNS Defense solution was selected. Among the first field feedback, Sciensano, a Belnet client, has already been using it for several years. In this testimonial, their network and security engineer shares his experience.
Sciensano is the Belgian institute for public health. The organisation covers all areas related to public health, of both humans and animals. Its scientific departments conduct studies on air quality, pesticides in our food, the impact of certain vaccines on animals, the effects of medicines, contaminants, and more. Sciensano also carries out numerous epidemiological studies, a role that became particularly visible during the pandemic. “In this type of situation, we sometimes have to deal with crisis that require mobilising additional resources, while ensuring the continuity and security of our activities,” explains Mr. Taquet, network and security engineer at Sciensano.
Securing DNS: an obvious choice
Within Sciensano, DNS is identified as a critical component of the infrastructure. “DNS is a sensitive and critical protocol, and above all essential for the proper functioning of an organisation. Securing it, therefore, seems obvious.”
The choice naturally fell on Cisco Umbrella. “We have been working with Cisco for several years and we trust their technologies. The ease of integration with products we were already using, such as Cisco Secure Client and Cisco Secure Firewall, was also a key factor.”
A simple and fast implementation
The deployment was carried out without major complexity. “The implementation was relatively straightforward: a few very lightweight servers to deploy, policies to configure in the Umbrella interface to match our needs, and then modifying the DNS via DHCP for the clients.”
Ease of use, visibility, and support
On a daily basis, Umbrella stands out for its simplicity. “It’s an easy solution to deploy, and the interface is very user-friendly.”
Sciensano has also benefited from its reporting capabilities. “We have already used the reports it provides several times—giving us, in particular, a great deal of visibility.”
On the support side, Sciensano notes an improvement: “In the past, Umbrella support was separate from Cisco support, which made things more complicated. Since last year, Umbrella support has been integrated into Cisco support.”
Feedback from experience
As with any integration, a few challenges were encountered. In particular, around the use of a publicly signed certificate (for communication between the Umbrella appliances and our Active Directory), it was necessary to use self-signed certificates.
There was also a subtle integration issue with the firewall (also Cisco): “To put it simply, the way so-called ‘trusted’ domains were implemented in the Umbrella console was not case-sensitive, whereas they became case-sensitive when added to the firewall. This was neither documented nor known by support at the time.”
Despite this, the overall evaluation remains very positive. Sciensano would recommend Cisco Umbrella to other organisations for the following reasons:
- Ease of implementation
- Ease of use
- Flexibility in policy deployment
- Ease of maintaining agents and appliances
- Visibility and control over traffic through DNS
“For us, it is the combination of simplicity, flexibility, and control that makes Cisco Umbrella particularly relevant,” concludes Mr. Taquet.
Would you like more information about the new Advanced DNS Security solution?