<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does roaming client know to disable itself in Internal Network? in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/4045550#M802</link>
    <description>Would be interesting to know how the RC can deferentiate between VAs and that it is behind the VA of it's own organisation. Thinking along the lines of connecting to the internal infrastructure of another organisation (a customer for example) that are running it's own VAs. Would the RC still see itself as roaming I wonder?</description>
    <pubDate>Fri, 13 Mar 2020 14:31:06 GMT</pubDate>
    <dc:creator>Anthony Owen</dc:creator>
    <dc:date>2020-03-13T14:31:06Z</dc:date>
    <item>
      <title>How does roaming client know to disable itself in Internal Network?</title>
      <link>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/3929787#M697</link>
      <description>&lt;P&gt;From the Umbrella user guide appendix B - Virtual Appliances -&amp;nbsp;&lt;A href="https://docs.umbrella.com/deployment-umbrella/docs/appx-b-virtual-appliances" target="_blank" rel="noopener"&gt;https://docs.umbrella.com/deployment-umbrella/docs/appx-b-virtual-appliances&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It says "If a computer running the Umbrella roaming client enters a network with VAs set in DHCP's DNS settings, the Umbrella roaming client does the following:&amp;nbsp;&lt;SPAN&gt;Disables itself."&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Is there a document which explains how the mechanism works for RC to detecting on-prem or off-prem in more detail? For the RC to know it is off-prem does it do some type of probe to Umbrella cloud and receive a response telling it its off-prem (ie. originid field must match configured public egress IP's registered network in dashboard)? Or does the client figure it out for themselves without the umbrella cloud telling it its off-prem?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 13:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/3929787#M697</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2019-09-25T13:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: How does roaming client know to disable itself in Internal Network?</title>
      <link>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/3930984#M700</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It sends probes to debug.opendns.com reguarly, depending on the result it determines whether it's connected behind a VA, if there is a local VA the roaming client disables, relying on the VA to perform the DNS enforcement. &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200940-Anyconnect-OpenDNS-Roaming-Security-Modu.html#anc12" target="_self"&gt;This&lt;/A&gt; doc describes the DNS probes in more detail, however it is for the AnyConnect Roaming Security module, but as far as I am aware it's the same behaviour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 17:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/3930984#M700</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-09-26T17:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: How does roaming client know to disable itself in Internal Network?</title>
      <link>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/4045550#M802</link>
      <description>Would be interesting to know how the RC can deferentiate between VAs and that it is behind the VA of it's own organisation. Thinking along the lines of connecting to the internal infrastructure of another organisation (a customer for example) that are running it's own VAs. Would the RC still see itself as roaming I wonder?</description>
      <pubDate>Fri, 13 Mar 2020 14:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/how-does-roaming-client-know-to-disable-itself-in-internal/m-p/4045550#M802</guid>
      <dc:creator>Anthony Owen</dc:creator>
      <dc:date>2020-03-13T14:31:06Z</dc:date>
    </item>
  </channel>
</rss>

