Cisco Secure Client and External DNS Resolution
In normal circumstances, the Cisco Secure Client Umbrella Roaming Security module functions only on networks where external DNS resolution exists. The Cisco Secure Client Umbrella Roaming Security module can not function successfully if DNS connectivity is broken or blocked on the local network.
For the Cisco Secure Client Umbrella Roaming Security module to enable DNS-layer protection, you must allow the following external DNS names to resolve by the local DNS server. You must allow recursive DNS queries to the following domains on the local DNS server:
- disthost.umbrella.com
- api.sse.cisco.com
- api.opendns.com
- crl3.digicert.com
- crl4.digicert.com
- ocsp.digicert.com
-
debug.opendns.com— This domain can receive a response to a TXT record query.
The Cisco DNS resolvers must answer this DNS request.
NXDOMAIN
is accepted, however, timeouts may delay or prevent Secure Access DNS-layer security protection on the network interface where this domain query times out.