# Cisco Umbrella vs Cloudflare Gateway for a mid-size company that wants DNS-level security without the complexity of a full SASE deployment?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hey G2 community, I'm putting together a comparison of Cisco Umbrella vs Cloudflare Gateway for a mid-size company that wants DNS-level security without the complexity of a full SASE deployment. Pulling from mid-market reviews in the <a class="a a--md" elv="true" href="https://www.g2.com/categories/dns-security-solutions">DNS security solutions</a> category, here's the gist:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cisco-umbrella/reviews"><strong>Cisco Umbrella</strong></a>: Mid-market admins like that it protects on and off the corporate network through its own Windows agent and mobile app, and that going live can be as simple as pointing DNS at it. The recurring caveats are cost as you scale seats and a learning curve on the advanced policy config, so it can pull you toward the fuller platform over time.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cloudflare-application-security-and-performance/reviews"><strong>Cloudflare</strong></a> (Gateway): Reviewers highlight fast anycast resolution and setup that's quick to stand up, with filtering, analytics, and policies in one dashboard. The common gripe is that advanced rules and proper logging get more complex and often sit behind higher tiers, so even the simple DNS use case can creep upward in cost.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">If DNS-level filtering is genuinely all you need right now, a few people in these threads also floated <a class="a a--md" elv="true" href="https://www.g2.com/products/dnsfilter/reviews"><strong>DNSFilter</strong></a> as a lighter option that skips the SASE framing entirely.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For the mid-size folks who've run either Umbrella or Cloudflare at the DNS layer only, did you manage to stay at that layer, or did you get pulled into the broader secure web gateway and SASE features? And which was easier to live with day to day for policy changes?</p>

##### Post Metadata
- Posted at: 25 days ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

From the mid-market reviews on both, my honest answer to your first question is that scope creep is a choice, not an inevitability, but the pricing nudges differ. The Umbrella complaints are about per-seat cost climbing and advanced policy config pulling you toward the fuller Cisco stack. The Cloudflare complaints are about useful rules and logging sitting in higher tiers, so the creep is upward in plan rather than outward in product. For day-to-day policy changes, reviewers describe Cloudflare&#39;s dashboard as quicker to live with and Umbrella&#39;s as more familiar to network teams. And if DNS filtering is truly the whole requirement, the DNSFilter suggestion in your thread is the one that structurally can&#39;t upsell you into SASE.

##### Comment Metadata
- Posted at: 21 days ago





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: about 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: about 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: about 13 years ago
  - Comments: 4


