Secure Web Gateway Backoff Settings
-
Select Follow compatible DNS backoff settings.
Enable this option to allow the Cisco Secure Client with the Umbrella Roaming Security module to follow the DNS backoff behavior for any of these DNS backoff settings: Customer trusted network or AnyConnect Trusted Network Detection (TND).
-
Select Follow independent backoff settings (Advanced).
The AnyConnect Trusted Network Detection (TND) and Your trusted network options are only supported with user devices that have version 5.1.3.62 or higher of the Cisco Secure Client with the Umbrella Roaming Security module deployed. For information about downloading the Cisco Secure Client software packages, see Cisco Secure Client Version 5.1.3.62 .Bypass Web traffic from Secure Access for the following contexts:
- Select AnyConnect Trusted Network Detection (TND) to disable web traffic forwarding from an endpoint to Secure Access if the network is trusted. This setting requires that you have the Trusted Network Detection (TND) setting enabled in the AnyConnect VPN profile for the user devices.
- Select Your Trusted network to enable endpoints to detect an organization's trusted network, which is identified by the Trusted server and Trusted server SHA256 hash fields. When the endpoint detects trusted networks, traffic from the endpoints bypass Secure Access and the endpoints rely on the network protections.
- For Trusted server, enter the URL (
<domain>:<port>
) of the trusted network server, which hosts the trusted server certificate. This option disables redirects to Secure Access when on the trusted network identified by the trusted network server. - For Trusted server SHA256 hash , enter the SHA256 hash for the trusted network server's certificate. The ID of the trusted network server's certificate must match the configured SHA256 hash.
- For Trusted server, enter the URL (