Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage DDNS Servers

Want to summarize with AI?

Log in

Use Dynamic DNS (DDNS) to ensure that changing IP addresses for devices are automatically updated to provide consistent, reliable access to resources.


When end-user devices connect to secure access using the VPNaaS, it is assigned an IP from an IP pool. When the device disconnects and reconnects the VPN, the IP address can change. If the device needs to be reachable using a fully qualified domain name (FQDN), the IP address change can cause the DNS server resource records (RRs) to become stale.

Dynamic DNS (DDNS) provides a mechanism to update DNS RRs whenever the IP address or hostname changes. Add DDNS servers to ensure that changing IP addresses for devices (especially those on dynamic IPs) are automatically updated to provide consistent, reliable access to resources without manual intervention.

When adding these DDNS servers, DDNS Server 1 resolves before DDNS Server 2. Provide DDNS servers that could resolve both IPv4 and IPv6 if applicable. You can also use DDNS for static IP addressing.


Add a DDNS Server Group

The following procedure describes how to add a DDNS server group managed by Secure Access.

Before you begin

A Full Admin user role is required. For more information, see Manage Accounts.

Procedure

  1. Navigate to Connect End User Connectivity > Manage Servers > DDNS Servers.


    End User Connectivity page showing option to view configured DDNS Servers
  2. Click + Add to configure a new DDNS server.

    1. Input a DDNS server group name.
    2. DDNS Server 1: Provide the IP address of the primary DDNS server.
    3. DDNS Server 2 (optional): Provide the IP address of the secondary DDNS server.

    Configuring a new DDNS Server group
    Note
    DDNS server fields cannot use addresses listed in IP Address Restrictions.
  3. TSIG key configuration: Select the algorithm and key that the DDNS server group configuration will use to secure server-to-server communications. TSIG (transaction signature) key configuration (defined in RFC 2845) enables the DNS to authenticate updates to a DNS database.

    1. Input a Key name.
    2. Select an Algorithm.
    3. Input a Secret key.

    TSIG key configuration page for configuring algorithm and key for DDNS server group
  4. Click Save.


View DDNS Servers

You can view the DDNS servers that are configured for your organization. Your DNS traffic routes through the DDNS servers managed by Secure Access.

Procedure

  1. Navigate to Connect > End User Connectivity, click Manage Servers and choose DDNS Servers.


    End User Connectivity page showing option to view configured DDNS Servers
  2. The list of configured DDNS servers is displayed.


    DDNS Servers page showing configured DDNS Servers
  3. From the list you can click Add to add a new entry, or click the edit icon to Edit or the trash can icon to Delete a DDNS server group entry.

  4. Click Close to dismiss the list.


Edit a DDNS Server

You can edit the attributes for a DDNS server group entry.

Procedure

  1. Navigate to Connect > End User Connectivity, click Manage Servers and choose DDNS Servers.


    End User Connectivity page showing option to view configured DDNS Servers
  2. Click the Edit icon for a DDNS server entry.


    Edit DDNS server group page showing editable attributes
  3. You can modify the label for the DDNS server group in the DDNS server group name field as well as modify the IP address of the primary and secondary DDNS servers as needed for DDNS Server 1 and DDNS Server 2.

  4. Click Save.