PDF(38.4 KB) View with Adobe Reader on a variety of devices
ePub(85.2 KB) View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
Mobi (Kindle)(79.4 KB) View on Kindle device or Kindle app on multiple devices
Updated:September 24, 2026
Document ID:224732
Bias-Free Language
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This document describes troubleshooting Umbrella errors for Active Directory and Virtual Appliances.
Issue
This document outlines common error, warning, and informational messages on the Sites and Active Directory page and provides resolution steps.
One or more error, warning, or informational messages appear on the Umbrella Settings > Sites and AD page for Virtual Appliances, Active Directory (AD) Connectors, or Domain Controllers (DCs).
Environment
The Umbrella Sites and Active Directory page is located at Settings > Sites and AD.
Affected components include Virtual Appliances (VAs), AD Connectors, and DCs.
DNSCrypt support is available in VA version 1.5.x or later.
If the connector is deployed on Windows Server (WS) 2012 or greater and stopped syncing to Umbrella, ensure that the connector is running version 1.6.31 or higher.
Connectors version 1.6.31 or higher function on WS 2008/2008 R2 if running .NET 4.5.2 or higher, but redeployment on a supported server is recommended.
Cisco announced End of Life (EOL) of Transport Layer Security (TLS) 1.0/1.1. Unsupported Windows versions (Windows Server 2008, 2008 R2, or Windows 7) do not support TLS 1.2 by default. Reinstall the connector on a supported server version (Windows Server 2012 or higher).
To send login event information to a Virtual Appliance, the Domain Controller (DC) must have a Connector installed in the same site.
Sites must contain at least one of each component type where noted by the message.
The Umbrella Connector service is tested to support 10 assets (Domain Controllers and Virtual Appliances) per CPU.
The Umbrella Connector service is tested to support approximately 850 continuous events (no hard limit) per second across all Domain Controllers in an Umbrella Site.
Resolution
Use the section that matches the component type shown on Settings > Sites and AD, then select the exact message text.
Virtual Appliances: VA registration/sync status, Connector association, DNSCrypt, local domains, redundancy, and DNS query failure messages.
AD Connectors: Connector registration/sync status, DC/VA connectivity, timeouts, parallel processing, and event drop messages.
Domain Controllers: Connector association and WMI connectivity messages.
"DNS queries forwarded by this VA to Umbrella are not encrypted"
DNSCrypt encrypts DNS packets forwarded from the Virtual Appliance (VA) to Umbrella public DNS resolvers and is enabled by default.
Confirm the VA is running version 1.5.x or later. DNSCrypt support is available in 1.5.x or later. If only one VA exists and it is not upgraded, upgrade it: Update Virtual Appliances.
Review firewall and inspection policies to ensure the DNSCrypt probe on port 53 (UDP/TCP) is not blocked or altered. If an Intrusion Prevention System (IPS) or Intrusion Detection System (IDS) performs deep packet inspection and expects only DNS traffic, the probe can fail.
For Adaptive Security Appliance (ASA) deployments, review the packet inspection guidance referenced by the deployment documentation.
"This VA is not redundant within its site (2+ VA required per site)"
Install a second VA for high availability. Refer to your Umbrella Virtual Appliance deployment documentation for guidance on running two Virtual Appliances per site.
"A large percentage of DNS queries to this VA are failing"
Collect relevant VA and Connector logs and open a support case.
Verify the DNS query failure rate returns to normal and the error clears on Settings > Sites and AD for the affected VA.
AD Connectors
"This Connector has registered but has never synced"
Use these checks to confirm initial synchronization completes successfully:
Cisco announced EOL of TLS 1.0/1.1. Unsupported Windows versions (Windows Server 2008, 2008 R2, or Windows 7) do not support TLS 1.2 by default. Reinstall the connector on a supported server version (Windows Server 2012 or higher).
If the connector is deployed on WS 2012 or greater and stopped syncing to Umbrella, ensure that the connector is running version 1.6.31 or higher.
Connectors version 1.6.31 or higher function on WS 2008/2008 R2 if running .NET 4.5.2 or higher, but redeployment on a supported server is recommended.
"The Connector is reporting drops while attempting to send events to some VAs"
Use these steps to reduce event drops and restore stable event delivery.
Check whether the total event rate across all Domain Controllers in the Umbrella Site exceeds the tested continuous capacity of approximately 850 events per second.
If the event rate exceeds this tested capacity, increase CPU cores on the Connector host to improve processing throughput.
If drops persist, enable load-balancing with two or more Connectors to share Domain Controller load. This advanced feature must be enabled by opening a support case with Umbrella support.
Domain Controllers
"Was at one point connected to one or more Connectors but is now connected to none"
If the Connector was removed, either redeploy the Connector or remove the Domain Controller.
DNSCrypt warning messages (VA): DNSCrypt is enabled by default to encrypt DNS packets forwarded from the Virtual Appliance (VA) to Umbrella public DNS resolvers. If firewall or inspection policies block or alter the DNSCrypt probe on port 53 (UDP/TCP), the probe fails. If an Intrusion Prevention System (IPS) or Intrusion Detection System (IDS) performs deep packet inspection and expects only DNS traffic, the probe fails.
Connector sync-stopped messages (AD Connector): Cisco announced End of Life (EOL) of Transport Layer Security (TLS) 1.0/1.1. Unsupported Windows versions (Windows Server 2008, 2008 R2, or Windows 7) do not support TLS 1.2 by default, which causes connector syncing to stop.
Connector performance messages (AD Connector): The Umbrella Connector service is tested to support 10 assets (Domain Controllers and Virtual Appliances) per CPU. When this sizing is exceeded, events processing is slower than expected.
Event drop warning messages (AD Connector): The Umbrella Connector service is tested to support approximately 850 continuous events (no hard limit) per second across all Domain Controllers in an Umbrella Site. If the overall rate exceeds this tested capacity, the Connector drops events.
WMI-down error messages (Domain Controller): WMI state is down when the Domain Controller is under load and does not respond to the WMI connection from the Connector.