How Secure Access Virtual Appliances Work
Virtual Appliances act as conditional DNS forwarders in your network. VAs intelligently forward public DNS queries to the Cisco Secure Access global network and local DNS queries to your existing local DNS servers and forwarders. Every public DNS query sent to Secure Access is encrypted, authenticated, and includes the client's internal IP address.
VAs do not cache DNS records. Caching occurs on the Secure Access DNS resolvers. When a VA responds with records to an endpoint's DNS query, any Time-to-Live (TTL) values in the response are equal to the TTLs as set by the authoritative DNS nameserver minus any time a record set has been in the Secure Access resolver cache.