Software Secure Access
Activity Manage

Cisco Secure Access Help Network Requirements for Secure Access Secure Access Encrypted DNS Queries

Last updated: Aug 07, 2025

Secure Access Encrypted DNS Queries

Required by applications or devices connecting to the Secure Access DNS resolvers, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).

The Cisco Secure Client Umbrella Roaming Security module supports the encryption of DNS queries sent to Secure Access on port 443 over TCP or UDP. If you would like to ensure encryption is enabled, and use a default deny ruleset in your firewall, allow the following CIDRs on the ports and protocols in your firewall.

Note: The Cisco Secure Client Umbrella Roaming Security module automatically encrypts DNS queries when it senses that 443/UDP is open.

IPv4 IPv6 Port/Protocol Description
208.67.222.222 2620:119:35::35 443 TCP/UDP Primary
208.67.220.220 2620:119:53::53 443 TCP/UDP Secondary