I am looking into implementing Umbrella for a customer with a couple remote branches. Each branch currently has a local DC. I like the idea of the transparently inspecting the queries with an ISR, but it looks like that doesn't currently support including user identity. Would deploying a virtual appliance for the sole purpose of connecting to AD and pulling user-to-IP mapping, and letting the ISR handle the conditional forwarding work? Would Umbrella still be able to piece together the user-to-query mapping even if the information comes from two different devices? Below is a quick diagram of what I am curious about - the big benefit to this is that endpoints don't need to change their current DNS settings (which can be a little bit of a pain if there are devices with static settings).
Nevermind - re-read the guide, and the AD Connector is installed on a separate server, and doesn't require the Virtual Appliance - so this should work. Since I already made the post, anyone have any experience with this yet?
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.