<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Umbrella setup with VA without AD integration in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4173087#M976</link>
    <description>&lt;P&gt;OK, I configured it as planned:&lt;/P&gt;&lt;P&gt;1. AD controllers, which are running DNS, are pointing to VAs via forwarders.&lt;/P&gt;&lt;P&gt;2. All DHCP clients and other servers are pointing to VAs.&lt;/P&gt;&lt;P&gt;VAs are set to point to AD controllers for local DNS zones resolution.&lt;/P&gt;&lt;P&gt;As a result, I have ability to identify sources (IP addresses) of the DNS requests for Internet destinations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Oct 2020 03:31:04 GMT</pubDate>
    <dc:creator>1netconsulting</dc:creator>
    <dc:date>2020-10-25T03:31:04Z</dc:date>
    <item>
      <title>Umbrella setup with VA without AD integration</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4169879#M969</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am looking for option to deploy Umbrella&amp;nbsp; in AD environment (but without AD integration and roaming clients)&amp;nbsp; and have ability to track end system IP addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will this scenario work:&lt;/P&gt;&lt;P&gt;Deploy Umbrella VA and point end systems (including servers) DNS&amp;nbsp; to VA. For domain controllers specify forwarders pointing to Umbrella for external DNS queries.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 00:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4169879#M969</guid>
      <dc:creator>1netconsulting</dc:creator>
      <dc:date>2020-10-20T00:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella setup with VA without AD integration</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4170016#M970</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1056379"&gt;@1netconsulting&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your clients continue to point to the internal DNS server, which then sends the external DNS queries to Umbrella VA, the VA will see only the internal DNS server(s) as the source IP address, not the clients. The Umbrella VA needs to be the primary DNS server, forwarding internal DNS queries to the internal DNS servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only exception to that (that I am aware of) is Infoblox, which can preserve the original IP address before forwarding to the Umbrella VA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 06:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4170016#M970</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-20T06:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella setup with VA without AD integration</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4170374#M972</link>
      <description>This is not the scenario I am asking about:&lt;BR /&gt;Internal devises will be pointing to VA for DNS resolution.&lt;BR /&gt;VA is configured to point to internal DNS servers (which are in my case AD controllers) Only for internal domain resolution. All external dns requests from VA are going to Umbrella servers.&lt;BR /&gt;The difference in this Suggested scenario compared to “standard” is that there is no AD connectors/sync script configured&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 20 Oct 2020 15:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4170374#M972</guid>
      <dc:creator>1netconsulting</dc:creator>
      <dc:date>2020-10-20T15:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella setup with VA without AD integration</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4170395#M973</link>
      <description>&lt;P&gt;Ok I miss understood this:- "&lt;EM&gt;For domain controllers specify forwarders pointing to Umbrella for external DNS queries&lt;/EM&gt;." - the Domain Controllers should never receive external DNS queries if the VA is the primary DNS server. Umbrella doesn't recommend pointing the DC's DNS to the VAs as that can create a loop in DNS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No you don't need to run the script or configure AD connectors, you can just use the VA which will encrypt and forward the DNS request including the learnt client IP address to the cloud or if local forward to the internal DNS server.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 16:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4170395#M973</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-20T16:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella setup with VA without AD integration</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4173087#M976</link>
      <description>&lt;P&gt;OK, I configured it as planned:&lt;/P&gt;&lt;P&gt;1. AD controllers, which are running DNS, are pointing to VAs via forwarders.&lt;/P&gt;&lt;P&gt;2. All DHCP clients and other servers are pointing to VAs.&lt;/P&gt;&lt;P&gt;VAs are set to point to AD controllers for local DNS zones resolution.&lt;/P&gt;&lt;P&gt;As a result, I have ability to identify sources (IP addresses) of the DNS requests for Internet destinations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2020 03:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-setup-with-va-without-ad-integration/m-p/4173087#M976</guid>
      <dc:creator>1netconsulting</dc:creator>
      <dc:date>2020-10-25T03:31:04Z</dc:date>
    </item>
  </channel>
</rss>

