Domain Management
Cisco Secure Access provides the option to manage domains when endpoints connect to internet resources with the Cisco Secure Client or a PAC file. Domain management allows DNS queries for certain domains to query the local network's DNS servers instead of the Secure Access DNS servers.
If you do not specify a list of internal domains, all DNS queries are sent directly to Secure Access, and as a result, cannot reach your network's local resources (for example: computers, servers, printers) on internally-hosted domains that rely on local DNS servers.
When you add internal domains to your bypass list, these internal domain queries sent from an endpoint with a Secure Access PAC file or the Cisco Secure Client bypass the Secure Access DNS resolvers. However, in the case of a tunnel, this configuration is not passed down, so there is no way to bypass traffic to the proxy per-organization with a custom configuration for network tunnels.
To ensure uninterrupted access to these resources, administrators should add the appropriate domains to the organization's domain bypass list. The domain bypass list syncs to all Cisco Secure Clients in your organization.