DNS Suffixes (Continued)
There are implications that should be considered with DNS Suffixes.
- This could allow an organization to not add any domains to the internal domains list in Secure Access. If DHCP is configured to use your domains as DNS Suffixes, the Cisco Secure Client automatically considers the domain as local, even without adding the domain to the internal domains list in Secure Access.
- If you use DNS suffixes to rely on internal domain resolution instead of populating the internal domains list in Secure Access, the endpoint traffic has increased security. Since DNS queries sent to domains on the internal domains list are sent unencrypted, this implies that a machine performing DNS queries for domains on the Secure Access internal domains list always sends unencrypted traffic on all networks.
Note: During the deployment of the Cisco Secure Client on user devices, you can disable the feature that adds the domains contained in the DNS suffixes list.