09-24-2019 05:46 PM - edited 09-25-2019 06:50 AM
From the Umbrella user guide appendix B - Virtual Appliances - https://docs.umbrella.com/deployment-umbrella/docs/appx-b-virtual-appliances
It says "If a computer running the Umbrella roaming client enters a network with VAs set in DHCP's DNS settings, the Umbrella roaming client does the following: Disables itself." Is there a document which explains how the mechanism works for RC to detecting on-prem or off-prem in more detail? For the RC to know it is off-prem does it do some type of probe to Umbrella cloud and receive a response telling it its off-prem (ie. originid field must match configured public egress IP's registered network in dashboard)? Or does the client figure it out for themselves without the umbrella cloud telling it its off-prem?
09-26-2019 10:33 AM
Hi,
It sends probes to debug.opendns.com reguarly, depending on the result it determines whether it's connected behind a VA, if there is a local VA the roaming client disables, relying on the VA to perform the DNS enforcement. This doc describes the DNS probes in more detail, however it is for the AnyConnect Roaming Security module, but as far as I am aware it's the same behaviour.
HTH
03-13-2020 07:31 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide