Cisco Secure Access Help

PDF

Cisco Secure Access Help

DNS requirements

Want to summarize with AI?

Log in

Network requirements to support DNS in Secure Access.


Your network must meet the following DNS requirements for Secure Access.


Secure Access DNS Resolvers

Required by applications or devices connecting to the Secure Access DNS resolvers, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).

IPv4 IPv6 Port/Protocol Description
208.67.222.222 2620:119:35::35 53 TCP/UDP Primary
208.67.220.220 2620:119:53::53 53 TCP/UDP Secondary
208.67.222.220 n/a 53 TCP/UDP Tertiary
208.67.220.222 n/a 53 TCP/UDP Quaternary
208.67.221.76 2620:119:17::76 53 TCP/UDP USA only Primary (For more information, see Best Practices.)
208.67.223.76 2620:119:76::76 53 TCP/UDP USA only Secondary (For more information, see Best Practices.)
208.67.222.64 2620.119.53::64 53 TCP/UDP DNS64 Primary (For more information, see Best Practices.)
208.67.220.64 2620:119:53::64 53 TCP/UDP DNS64 Secondary (For more information, see Best Practices.)
146.112.70.70 2a04:e4c0:170::170 53 TCP/UDP Saudi Arabia-Alternate Primary
146.112.71.71 2a04:e4c0:171::171 53 TCP/UDP Saudi Arabia-Alternate Secondary

Best Practices

You can use either IPv4 or IPv6 DNS addresses as your primary or secondary DNS server. You must use both numbers and not the same IP address twice. If your router requires a third or fourth DNS server setting, you can use 208.67.220.222 and 208.67.222.220 or 2620:119:35::35 and 2620:119:53::53 as the third and fourth entry respectively.

DNS64 (RFC 6147) is meant for single-stack IPv6 networks. This is to help with IPv4 to IPv6 transitions. If you are using Secure Access DNS on devices without IPv4 access, these resolvers will synthesize records that can reach those destinations through a NAT64 gateway using the Well-Known Prefix. See details: https://datatracker.ietf.org/doc/html/rfc6147

North America (USA-only) DNS resolvers guarantee only that DNS queries are resolved by a USA-based Secure Access data center. Block pages use global Anycast and may go to any data center, including one located outside of the USA.

If you have an organization with roaming or integrated identities that frequently move across networks owned by different Cisco organizations, DNS queries are resolved under your own organization's policy rather than the policy of the unrelated network you are currently on. DNS queries have unique identifiers such as device ID, GUID, and organization ID embedded into DNS requests. The Secure Access DNS resolvers then enforce the correct security policies based on the embedded identity information, regardless of the network the user is roaming on. This prevents policy misapplication from other Cisco organizations' networks and ensures consistent policy enforcement tied to your organization.

Several systems allow you to specify multiple DNS servers. We recommend that you only use the Cisco Secure Access servers and do not include any other DNS servers.


Cisco Secure Client

The Cisco Secure Client Umbrella Roaming Security module uses standard DNS ports 53/UDP and 53/TCP to communicate with Secure Access. If you explicitly block access to third-party DNS servers on your corporate or home network, you must allow certain CIDRs on the ports and protocols in your firewall.

In circumstances where third-party DNS servers are blocked, the Cisco Secure Client Umbrella Roaming Security module transitions to a state where it temporarily uses the DHCP-delegated DNS servers for resolution.


Cisco Secure Client and External DNS Resolution

In normal circumstances, the Cisco Secure Client Umbrella Roaming Security module functions only on networks where external DNS resolution exists. The Cisco Secure Client Umbrella Roaming Security module can not function successfully if DNS connectivity is broken or blocked on the local network.

Bypass Requirements

For the Cisco Secure Client device registration process to complete, send the following destinations directly and bypass them from any form of authentication, SSL inspection, or filtering:

  • crl3.digicert.com

  • crl4.digicert.com

  • ocsp.digicert.com

DNS Resolution Requirements

For the Cisco Secure Client Umbrella Roaming Security module to enable DNS-layer protection, you must allow the following external DNS names to resolve by the local DNS server. Allow recursive DNS queries to the following domains on the local DNS server:


Secure Access Encrypted DNS Queries

Required by applications or devices connecting to the Secure Access DNS resolvers, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).

The Cisco Secure Client Umbrella Roaming Security module supports the encryption of DNS queries sent to Secure Access on port 443 over TCP or UDP. If you would like to ensure encryption is enabled, and use a default deny ruleset in your firewall, allow the following CIDRs on the ports and protocols in your firewall.

Note: The Cisco Secure Client Umbrella Roaming Security module automatically encrypts DNS queries when it senses that 443/UDP is open.

IPv4 IPv6 Port/Protocol Description
208.67.222.222 2620:119:35::35 443 TCP/UDP Primary
208.67.220.220 2620:119:53::53 443 TCP/UDP Secondary

Secure Access DNS, Web, and Block Pages

Required by applications or devices connecting to the Secure Access DNS-layer security, including Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security).

We recommend that you allow all traffic on ports 80 and 443 over TCP for the Secure Access DNS-layer, internet security, and Block Page services.

IP Ports/Protocol
67.215.64.0/19 80/443 TCP
146.112.0.0/16 80/443 TCP
155.190.0.0/16 80/443 TCP
185.60.84.0/22 80/443 TCP
204.194.232.0/21 80/443 TCP
208.67.216.0/21 80/443 TCP
208.69.32.0/21 80/443 TCP

Secure Access DNS and Web – Client Configuration Services

Required by applications or devices connecting to the Secure Access DNS-layer security, including the Secure Access Active Director (AD) Connector and Cisco Secure Client deployments with the Umbrella Roaming Security module (DNS-layer security and Web).

We recommend that you allow all traffic on port 443 over TCP for the Secure Access Client Configuration services.

Domains Port/Protocol Description
api.opendns.com 443/TCP Configuration

The Cisco Secure Client Umbrella Roaming Security module uses HTTPS (443/TCP) to communicate with Secure Access for the following uses:

  • Initial registration of the Cisco Secure Client Umbrella Roaming Security module upon installation.
  • Checking for new versions of the Cisco Secure Client Umbrella Roaming Security module.
  • Reporting the status of Cisco Secure Client Umbrella Roaming Security module to Secure Access.
  • Checking for new internal domains.
IP Ranges Port Protocol
67.215.71.201 443 TCP
67.215.92.210 443 TCP
146.112.255.101 443 TCP
146.112.255.152/29 443 TCP
2620:0:cc1:115::210 (IPv6) 443 TCP
2a04:e4c7:ffff::20/125 (IPv6) 443 TCP

Windows Only

If you utilize an HTTP proxy that is configured at the user-level (normally using GPO), make sure the SYSTEM user is also configured to use the proxy.


Secure Access DNS and Web – Client Sync Services

Required by devices or applications that are protected by Secure Access DNS or Web security. Includes Cisco Secure Client deployments with the Umbrella Roaming Security module.

Domains IP Ranges Port/Protocol Description
sync.hydra.opendns.com 146.112.63.3 - 146.112.63.9 146.112.63.11 - 146.112.63.13 443/TCP Syncing data

The sync.hydra.opendns.com domain resolves to multiple IP addresses, all within the 146.112.63.0/24 IP range. We recommend that you add this entire range. The IP addresses for sync.hydra.opendns.com are Anycast and may change.


Secure Access DNS and Web – Client Certificate Revocation Services

Required by devices or applications that are protected by Secure Access DNS or Web security. Includes the Secure Access Active Director (AD) Connector and Cisco Secure Client deployments with the Umbrella Roaming Security module.

Domains Port/Protocol Description
crl3.digicert.com 80/TCP CRL
crl4.digicert.com 80/TCP CRL
ocsp.digicert.com 80/TCP OCSP
sync.hydra.opendns.com 443/TCP Registration (without deployment keys)
api.opendns.com 443/TCP Registration (without deployment keys)
devices.api.sse.cisco.com 443/TCP Registration (SSE Global region with deployment keys)
r13.c.lencr.org 80/TCP CRL lookup for devices.api.sse.cisco.com
Note
The Digicert domains resolve to various IP addresses based on a CDN and are subject to change.