Local DNS Forwarding
Cisco Secure Access Virtual Appliances (VAs) are conditional DNS forwarders in your network, forwarding public DNS queries to Secure Access, and local DNS queries to your existing local DNS servers and forwarders, respectively.
When the VAs receive queries which match domains or subdomains of a local DNS zone (local domain), the VA forwards those queries to your local DNS server for resolution instead of the Secure Access public DNS resolvers. This is accomplished by defining your local domain names in Secure Access.
|
Do not set your local DNS forwarders to point to the VAs. It is possible to create loops in DNS in this configuration and it's not recommended or supported.
|