Network requirements to support DNS in Secure Access.
Your network must meet the following DNS requirements for Secure Access.
Cisco Secure Access Help
Network requirements to support DNS in Secure Access.
Your network must meet the following DNS requirements for Secure Access.
Required by applications or devices connecting to the Secure Access DNS resolvers, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).
| IPv4 | IPv6 | Port/Protocol | Description |
|---|---|---|---|
| 208.67.222.222 | 2620:119:35::35 | 53 TCP/UDP | Primary |
| 208.67.220.220 | 2620:119:53::53 | 53 TCP/UDP | Secondary |
| 208.67.222.220 | n/a | 53 TCP/UDP | Tertiary |
| 208.67.220.222 | n/a | 53 TCP/UDP | Quaternary |
| 208.67.221.76 | 2620:119:17::76 | 53 TCP/UDP | USA only Primary (For more information, see Best Practices.) |
| 208.67.223.76 | 2620:119:76::76 | 53 TCP/UDP | USA only Secondary (For more information, see Best Practices.) |
| 208.67.222.64 | 2620.119.53::64 | 53 TCP/UDP | DNS64 Primary (For more information, see Best Practices.) |
| 208.67.220.64 | 2620:119:53::64 | 53 TCP/UDP | DNS64 Secondary (For more information, see Best Practices.) |
| 146.112.70.70 | 2a04:e4c0:170::170 | 53 TCP/UDP | Saudi Arabia-Alternate Primary |
| 146.112.71.71 | 2a04:e4c0:171::171 | 53 TCP/UDP | Saudi Arabia-Alternate Secondary |
You can use either IPv4 or IPv6 DNS addresses as your primary or secondary DNS server. You must use both numbers and not the same IP address twice. If your router requires a third or fourth DNS server setting, you can use 208.67.220.222 and 208.67.222.220 or 2620:119:35::35 and 2620:119:53::53 as the third and fourth entry respectively.
DNS64 (RFC 6147) is meant for single-stack IPv6 networks. This is to help with IPv4 to IPv6 transitions. If you are using Secure Access DNS on devices without IPv4 access, these resolvers will synthesize records that can reach those destinations through a NAT64 gateway using the Well-Known Prefix. See details: https://datatracker.ietf.org/doc/html/rfc6147
North America (USA-only) DNS resolvers guarantee only that DNS queries are resolved by a USA-based Secure Access data center. Block pages use global Anycast and may go to any data center, including one located outside of the USA.
If you have an organization with roaming or integrated identities that frequently move across networks owned by different Cisco organizations, DNS queries are resolved under your own organization's policy rather than the policy of the unrelated network you are currently on. DNS queries have unique identifiers such as device ID, GUID, and organization ID embedded into DNS requests. The Secure Access DNS resolvers then enforce the correct security policies based on the embedded identity information, regardless of the network the user is roaming on. This prevents policy misapplication from other Cisco organizations' networks and ensures consistent policy enforcement tied to your organization.
Several systems allow you to specify multiple DNS servers. We recommend that you only use the Cisco Secure Access servers and do not include any other DNS servers.
The Cisco Secure Client Umbrella Roaming Security module uses standard DNS ports 53/UDP and 53/TCP to communicate with Secure Access. If you explicitly block access to third-party DNS servers on your corporate or home network, you must allow certain CIDRs on the ports and protocols in your firewall.
In circumstances where third-party DNS servers are blocked, the Cisco Secure Client Umbrella Roaming Security module transitions to a state where it temporarily uses the DHCP-delegated DNS servers for resolution.
In normal circumstances, the Cisco Secure Client Umbrella Roaming Security module functions only on networks where external DNS resolution exists. The Cisco Secure Client Umbrella Roaming Security module can not function successfully if DNS connectivity is broken or blocked on the local network.
For the Cisco Secure Client device registration process to complete, send the following destinations directly and bypass them from any form of authentication, SSL inspection, or filtering:
crl3.digicert.com
crl4.digicert.com
ocsp.digicert.com
For the Cisco Secure Client Umbrella Roaming Security module to enable DNS-layer protection, you must allow the following external DNS names to resolve by the local DNS server. Allow recursive DNS queries to the following domains on the local DNS server:
api.opendns.com (Required if deployment keys are not used for registration)
sync.hydra.opendns.com (Required if deployment keys are not used for registration)
devices.api.sse.cisco.com (Required for SSE Global region when deployment keys are used)
http://r13.c.lencr.org/7.crl(CRL lookup service for devices.api.sse.cisco.com)
debug.opendns.com— This domain can receive a response to a TXT record query.
The Cisco DNS resolvers must answer this DNS request.
NXDOMAINis accepted, however, timeouts may delay or prevent Secure Access DNS-layer security protection on the network interface where this domain query times out.
Required by applications or devices connecting to the Secure Access DNS resolvers, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).
The Cisco Secure Client Umbrella Roaming Security module supports the encryption of DNS queries sent to Secure Access on port 443 over TCP or UDP. If you would like to ensure encryption is enabled, and use a default deny ruleset in your firewall, allow the following CIDRs on the ports and protocols in your firewall.
Note: The Cisco Secure Client Umbrella Roaming Security module automatically encrypts DNS queries when it senses that 443/UDP is open.
| IPv4 | IPv6 | Port/Protocol | Description |
|---|---|---|---|
| 208.67.222.222 | 2620:119:35::35 | 443 TCP/UDP | Primary |
| 208.67.220.220 | 2620:119:53::53 | 443 TCP/UDP | Secondary |
Required by applications or devices connecting to the Secure Access DNS-layer security, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).
We recommend that you allow all traffic on ports 80 and 443 over TCP for the Secure Access DNS-layer, internet security, and Block Page services.
| IP | Ports/Protocol |
|---|---|
| 67.215.64.0/19 | 80/443 TCP |
| 146.112.0.0/16 | 80/443 TCP |
| 155.190.0.0/16 | 80/443 TCP |
| 185.60.84.0/22 | 80/443 TCP |
| 204.194.232.0/21 | 80/443 TCP |
| 208.67.216.0/21 | 80/443 TCP |
| 208.69.32.0/21 | 80/443 TCP |
Required by applications or devices connecting to the Secure Access DNS-layer security, including the Secure Access Active Director (AD) Connector and Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security and Web).
We recommend that you allow all traffic on port 443 over TCP for the Secure Access Client Configuration services.
| Domains | Port/Protocol | Description |
|---|---|---|
| api.opendns.com | 443/TCP | Configuration |
The Cisco Secure Client Umbrella Roaming Security module uses HTTPS (443/TCP) to communicate with Secure Access for the following uses:
| IP Ranges | Port | Protocol |
|---|---|---|
| 67.215.71.201 | 443 | TCP |
| 67.215.92.210 | 443 | TCP |
| 146.112.255.101 | 443 | TCP |
| 146.112.255.152/29 | 443 | TCP |
| 2620:0:cc1:115::210 (IPv6) | 443 | TCP |
| 2a04:e4c7:ffff::20/125 (IPv6) | 443 | TCP |
If you utilize an HTTP proxy that is configured at the user-level (normally using GPO), make sure the SYSTEM user is also configured to use the proxy.
Required by devices or applications that are protected by Secure Access DNS or Web security. Includes Cisco Secure Client deployments with the Umbrella Roaming Security module.
| Domains | IP Ranges | Port/Protocol | Description |
|---|---|---|---|
| sync.hydra.opendns.com | 146.112.63.3 - 146.112.63.9 146.112.63.11 - 146.112.63.13 | 443/TCP | Syncing data |
The sync.hydra.opendns.com domain resolves to multiple IP addresses, all within the 146.112.63.0/24 IP range. We recommend that you add this entire range. The IP addresses for sync.hydra.opendns.com are Anycast and may change.
Required by devices or applications that are protected by Secure Access DNS or Web security. Includes the Secure Access Active Director (AD) Connector and Cisco Secure Client deployments with the Umbrella Roaming Security module.
| Domains | Port/Protocol | Description |
|---|---|---|
| crl3.digicert.com | 80/TCP | CRL |
| crl4.digicert.com | 80/TCP | CRL |
| ocsp.digicert.com | 80/TCP | OCSP |
| sync.hydra.opendns.com | 443/TCP | Registration (without deployment keys) |
| api.opendns.com | 443/TCP | Registration (without deployment keys) |
| devices.api.sse.cisco.com | 443/TCP | Registration (SSE Global region with deployment keys) |
| r13.c.lencr.org | 80/TCP | CRL lookup for devices.api.sse.cisco.com |
The Digicert domains resolve to various IP addresses based on a CDN and are subject to change.