Allow Connections to Various Domains and Services
You must allow connections to certain domains and URLs for the Virtual Appliances to communicate with the Secure Access cloud services and local DNS servers. These requirements apply to each platform where the VA is deployed.
- For DNS traffic to Secure Access, see Secure Access DNS Resolvers.
- Standard and encrypted DNS queries to the Secure Access DNS resolvers.
- Port 443 is used as failover if your firewall does not allow DNSCrypt on port 53.
- Port 5353 is used as failover if DNSCrypt is not allowed on port 53 and port 443.
- Standard and encrypted DNS queries to the Secure Access DNS resolvers.
- For DNS traffic on internal domains, allow connections on the Virtual Appliance to local DNS servers on UDP and TCP port 53.
- For more information, see Secure Access DNS and Web – Client Certificate Revocation Services.
- For more information, see Secure Access DNS and Web – Client Configuration Services.
- For more information, see Secure Access Cisco Secure Client and External DNS Resolution.