Advanced DNS Security - Technical FAQ

How long does it take to activate the service?
How does Advanced DNS Security work?
Where can I download Cisco Secure Client?
How do I set up a minimal DNS Defense configuration with forwarders?
How do I set up a minimal configuration for the Cisco Secure Access client agent with the Umbrella / DNS Defense module?
Where does Cisco gets all its data from?
What will end users see when their DNS query is blocked?
Does Advanced DNS Security also work for DNS over HTTPS?
How does Cisco handle false positives?
Where can I find more information about possible integrations with Infoblox, EfficientIP, and others?
What can I do when internal DNS names fail to resolve while using a 3rd party VPN with split tunneling?

 

How long does it take to activate the service?

The service can be activated in less than an hour. It is easy to deploy on your network, regardless of the number of connected devices. 

You can watch this video to get started.

Or check the following documentation to help you with the onboarding:

 

How does Advanced DNS Security work?

Cisco Secure Access DNS Defense acts as a cloud-delivered, first line of defense that secures user internet access by intercepting and inspecting DNS requests. It blocks connections to malicious domains, IPs, and phishing sites before they are established, protecting users both on and off the network. It operates through DNS-layer security, a Secure Web Gateway (SWG), and a firewall-as-a-service.

 

Where can I download Cisco Secure Client?

  • Go to Dashboard - Connect - End user connectivity 
  • At the top right you will see the Cisco Secure Client button. Click on it to download the Client.

 

How do I set up a minimal DNS Defense configuration with forwarders?

  1. Go to the main portal: https://security.cisco.com/ 
  2. After creating an account, give a name for your organization. 

If you only use Cisco DNS Defense, you do not need to complete the entire “Get started with Cisco Secure Access” flow. You can collapse it using the ^ icon on the right. 

  1. Configure admin access

Platform Management / Administrator Access 

Tabs: Administrators, Admin groups, Admin role 

  1. Activate a trial or full subscription for Cisco Secure Access DNS Advantage 

Platform management / Subscriptions, Claim subscriptions 

  1. Register the network IP addresses that will send DNS requests. 

Secure Access, Resources / registered networks 

Add network, add IP address or IP range 

This “add network” page shows the IP addresses to use as DNS forwarders on your servers. 

  1. After adding all the IP addresses, use these Cisco IP addresses to your DNS server(s) forwarders list. 

DNS Defense will now work with the default rules. 

To verify if DNS requests are processed: 

  • Monitor / Activity Volume 
  • Monitor / Activity Search (may not show results immediately) 
  • Secure / Access policy, view, add or modify rules. Optionally enable logging (by default, only blocked requests are logged) 

Some pages to configure rules and notifications: 

  • Secure / Security profiles 
  • Secure / Thread categories 
  • Secure / Notification pages 
  • Resources / Internet and SaaS Resources 
  • Secure / Access policy

 

How do I set up a minimal configuration for the Cisco Secure Access client agent with the Umbrella / DNS Defense module?

You need two files: 

  1. Endpoint agent setup: 

Secure Access / Connect / End user connectivity, Cisco secure client (top-right) (file: cisco-secure-client-win-[version]-predeploy-k9.zip) 

  1. Installation profile: 

Internet Security, Download profile (file: OrgInfo.json) 

Steps: 

  • Extract the zip file. 
  • Copy the OrgInfo.json file into the Profiles\umbrella\ directory. 

For manual installation, run setup.exe. 

  • Minimum required components: Core & AnyConnect VPN + Umbrella 
  • The Cisco AnyConnect Virtual Miniport Adapter will be disabled on Windows. 

Silent unattended installation: 

  • Replace /qn with /passive to see a progress window. 
  • msiexec /package cisco-secure-client-win-[version]-core-vpn-predeploy-k9.msi /norestart /qn PRE_DEPLOY_DISABLE_VPN=1 
  • msiexec /package cisco-secure-client-win-[version]-umbrella-predeploy-k9.msi /norestart /qn 

The client will automatically register on the Cisco platform. 

To verify active clients: Secure Access / Resources / Roaming Devices 

Note: Sync between client and platform is not real time. It typically takes less than one hour. 

On the client computer, the Cisco Secure Client UI also updates its state when a DNS request is made.

 

Where does Cisco gets all its data from?

Cisco Secure Access DNS Defense acts as a secure internet gateway, using Cisco Talos's threat intelligence to analyze and block malicious DNS requests, IPs, and URLs in real time. By integrating Talos's massive, AI-driven threat data, Umbrella proactively prevents connections to malware, phishing, and ransomware sites before they reach the network.
Cisco Talos is one of the world's largest commercial threat intelligence teams, collecting data from millions of devices, emails, and web requests to identify new threats.

 

What will end users see when their DNS query is blocked?

This is entirely up to you. You can configure your own pages.

 

Does Advanced DNS Security also work for DNS over HTTPS?

Cisco supports DNS over HTTPS (DoH), allowing for encrypted DNS queries to be sent to Umbrella's resolvers, which enhances privacy and security. 
Cisco added native support for DoH directly to their core resolvers, providing the same security and filtering capabilities as traditional, unencrypted DNS. 

 

How does Cisco handle false positives?

Cisco Umbrella manages false positives through a combination of automated, intelligent traffic analysis, customizable policy configurations, and, when necessary, manual review by security teams. It aims to strike a balance between high security and operational efficiency by limiting the need to proxy all traffic, focusing only on risky destinations.

 

Where can I find more information about possible integrations with Infoblox, EfficientIP, and others?

For more information about possible integrations, check Network Devices with Cisco Umbrella (DNS).

 

What can I do when internal DNS names fail to resolve while using a 3rd party VPN with split tunneling?

This issue may occur when Cisco Secure Access (with the Umbrella / DNS Defense module) is combined with a VPN using split tunneling. Internal DNS names may fail to resolve or return incorrect results, especially if domain names on the local network differ from public DNS records. 

  • Option 1: Enable Third-Party VPN Compatibility. 

Secure Access, Connect / End User Connectivity / Internet security (tab), Settings, General settings, Third party VPN compatibility 

If Option 1 does not fix the issue, try option 2. 

  • Option 2: exclude a domain to be processed by the client agent. 

Secure Access, Connect / End User Connectivity / Internet security (tab), Traffic Steering, Add destination: domain-name.be (will validate *.domain-name.be) 

Requests instead use local DNS resolvers or directly access the Internet without using the web proxy. 

The change becomes active after the next client sync.

Did you find this FAQ useful?
Copyright © 2026 Belnet.