<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Umbrella questions in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731262#M1606</link>
    <description>&lt;P&gt;Assume a customer is running Umbrella VA's on premise. &lt;BR /&gt;&lt;BR /&gt;Question 1: If the DNS query is for a host outside of the organization the VA's forward the query to Umbrella DNS servers using DNSCrypt. Assuming the Umbrella DNS servers don't have the answer do they act as recursive DNS resolvers and thus iteratively query the root, TLD, and authoritative DNS servers and then return the answer to the customer? I assume the VA's do NOT act as the recursive resolvers.&lt;/P&gt;
&lt;P&gt;Question 2: If the first answer to the question above is the Umbrella DNS servers do in fact act as recursive resolvers, do they use DNSSec when forwarding queries to other DNS servers (root, TLD, etc)?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 22:04:09 GMT</pubDate>
    <dc:creator>PatrickCavell85782</dc:creator>
    <dc:date>2022-12-01T22:04:09Z</dc:date>
    <item>
      <title>Umbrella questions</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731262#M1606</link>
      <description>&lt;P&gt;Assume a customer is running Umbrella VA's on premise. &lt;BR /&gt;&lt;BR /&gt;Question 1: If the DNS query is for a host outside of the organization the VA's forward the query to Umbrella DNS servers using DNSCrypt. Assuming the Umbrella DNS servers don't have the answer do they act as recursive DNS resolvers and thus iteratively query the root, TLD, and authoritative DNS servers and then return the answer to the customer? I assume the VA's do NOT act as the recursive resolvers.&lt;/P&gt;
&lt;P&gt;Question 2: If the first answer to the question above is the Umbrella DNS servers do in fact act as recursive resolvers, do they use DNSSec when forwarding queries to other DNS servers (root, TLD, etc)?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 22:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731262#M1606</guid>
      <dc:creator>PatrickCavell85782</dc:creator>
      <dc:date>2022-12-01T22:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella questions</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731274#M1607</link>
      <description>Hi Patrick,&lt;BR /&gt;&lt;BR /&gt;The answer to both your question is Yes.&lt;BR /&gt;Question 1: VA acts as a forwarder only, and Umbrella DNS acts as recursive DNS resolver.&lt;BR /&gt;Question 2: Yes, Umbrella DNS acts as fully RFC compliant security aware resolvers by performing DNSSEC validation on queries to authoritative nameservers for signed zones&lt;BR /&gt;&lt;BR /&gt;Hope that helps.&lt;BR /&gt;</description>
      <pubDate>Thu, 01 Dec 2022 22:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731274#M1607</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2022-12-01T22:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella questions</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731322#M1608</link>
      <description>&lt;P&gt;Thanks Jennifer. That was very helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 02:00:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-questions/m-p/4731322#M1608</guid>
      <dc:creator>PatrickCavell85782</dc:creator>
      <dc:date>2022-12-02T02:00:18Z</dc:date>
    </item>
  </channel>
</rss>

