Troubleshoot DNS Resolution Failures Behind a Firewall
The VA offers DNSCrypt functionality that protects the content of your DNS queries. This functionality may be blocked by your firewall.
If you are using the Cisco ASA firewall, you can see an indication of this in the ASA log.
For example:
Dropped UDP DNS request from inside:192.168.1.1/53904 to outside-fiber:208.67.220.220/53;
label length 71 bytes exceeds protocol limit of 63 bytes
DNS resolution is not affected by this blocking, but your DNS queries are not fully protected.
To address this, ensure that your firewall allows outbound queries on port 443 and 5353 for both TCP and UDP to the Secure Access resolver IP addresses as mentioned in the Pre-requisites section.