Configure DNSSEC Support
Secure Access supports DNSSEC by performing validation on queries sent from Secure Access DNS resolvers to upstream authorities.
If your endpoints are making DNS queries with the DNSSEC OK (DO) bit to the VA, the default behavior of the VA is to turn off this bit before forwarding the query to Secure Access or the local DNS server.