Clarification for Cisco Secure Access regarding how the Umbrella module protection status is displayed on the Roaming Devices screen.
Specifically, there is a need to understand the expected DNS and Web protection status values shown when devices are operating normally, comparing states when RAVPN (Remote Access VPN) is connected versus not connected.
The inquiry focuses on the correct specification for status display behavior in an environment where Internet Security > Cisco Secure Client Settings has "Web Security (port 80/443 traffic only)" enabled, while "DNS Security" remains in its default enabled state.
Cisco Secure Access
Umbrella module integrated with Cisco Secure Client
Internet Security configuration with Web Security enabled for port 80/443 traffic only
DNS Security enabled (default fixed setting)
RAVPN connectivity scenarios (connected and disconnected states)
Roaming Devices screen monitoring
The Umbrella module performs synchronization with the Umbrella API endpoint at sync.hydra.opendns.com. This synchronization process follow a specific pattern:
Initial synchronization occurs once at service start
Subsequent synchronizations occur at approximately 30-minute intervals when there is no network change
The Roaming Devices page status reflects the device last connection timestamp to the Umbrella service
Based on lab testing, the Secure Web Gateway Protection Status on the Roaming Devices screen displays as "Protected" regardless of RAVPN connection state when the device is functioning normally with proper Umbrella module operation.
When Remote Access VPN and the Umbrella module are used together, DNS policy is applied in some operational scenarios. This behavior represents an operational observation that needs to be considered when designing security architectures that combine these technologies.
The protection status values are documented as available in the Cisco Secure Access system:
Protected
Disabled due to VPN
Additional status indicators as defined in the Secure Web Gateway and Security Information documentation
The inquiry arose from the need to understand the correct specification behavior for Umbrella module status display in different RAVPN connectivity states. The status display behavior is determined by the Umbrella module synchronization process with the Umbrella API endpoint and the device last successful connection timestamp, rather than real-time connectivity status.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
02-Jun-2026
|
Initial Release |