> ## Documentation Index
> Fetch the complete documentation index at: https://docs.inviolet.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cisco Umbrella

> Connect Cisco Umbrella to Inviolet — observe LLM bypass volume (CASB) today; network enforcement (SWG) on request.

Cisco Umbrella integrates with Inviolet in the two directions described in the
[network enforcement overview](/integrations/network/overview): **observe**
(read the vendor's egress logs into Inviolet) and **enforce** (block direct LLM
access).

## Observe (CASB) — available today

Inviolet's `casb-umbrella` connector pulls Cisco Umbrella egress events and ingests the ones
bound for LLM providers, so bypass volume and attribution show up in the
[Shadow IT analytics](https://app.inviolet.ai/analytics/shadow-it) view.

**Set it up:** Inviolet → **Settings → Data Sources → Admin Connectors → New →
Cisco Umbrella**, then paste your credentials.

**Credentials:** Umbrella — an API key + secret (Admin → API Keys) + your Umbrella org id.

## Enforce (SWG) — on request

Network enforcement packs for Cisco Umbrella (block direct LLM API + consumer UIs, forcing
traffic through Inviolet) are delivered per engagement. Unlike Cloudflare — which
matches at the DNS layer natively — Cisco Umbrella enforcement is scoped to your tenant's
capabilities. [Contact us](mailto:support@inviolet.ai) to scope a deployment.

<Note>
  **Cloudflare is the reference vendor**, validated end to end (enforcement +
  observability). See the [Cloudflare guide](/integrations/network/cloudflare) for
  the full pattern; the same shape applies here once your enforcement pack is built.
</Note>
