The Umbrella Documentation Hub

Welcome to the Umbrella documentation hub. Here you'll find access to all of our Cisco Umbrella user guides.

Get Started    

Roaming Computer Settings

Several advanced settings for both the Umbrella roaming client and the AnyConnect Umbrella Roaming Security module can be configured.

  1. Navigate to Deployments > Core Identities > Roaming Computers and click Settings.
  1. Select a tab and then options on that tab:

General Settings

  • Auto-Delete Inactive Roaming Computers
    Automatically deletes all roaming computers that have not synced for the specified period of time. Unsynced roaming computers are removed from the Umbrella dashboard, but the client software is not automatically uninstalled from the computer. If a roaming computer comes back online it re-appears in the dashboard once it has re-synced, even if it has been deleted.
  • Traffic Forwarding on Umbrella Protected Networks—Disables the DNS-based protection applied by the Umbrella roaming client, AnyConnect Umbrella roaming security, and web-based protection applied by Anyconnect Umbrella roaming security while on a network protected by Umbrella. This includes the intelligent proxy as it is a DNS-based redirect. IP Layer enforcement is not affected. Relies on the protection of the network for all features except IP Layer Enforcement. To trigger this setting, network registration and the network must be the higher policy (not same, but higher) and the local DNS server egress network must be the same network registration as straight out from the computer to 208.67.222.222. Having the network in the same organization will not trigger the disabling of traffic redirection. Currently, DNS and web traffic forwarding can only be disabled together. See Add IP Layer Enforcement—DNS Policies Only and Roaming Client: Enable/Disable Protected Network.
  • Active Directory—Enables identity support for roaming computers. Identity support is an enhancement to the Umbrella roaming client or the AnyConnect Umbrella roaming security module that provides Active Directory user and group identity-based policies, in addition to user and private LAN IP reporting. See Identity Support for the Roaming Client.
  • VPN Compatibility Mode—The Cisco Umbrella roaming client works with most VPN software; however, certain AnyConnect and other VPN profiles may not resolve local DNS correctly on a VPN connection with Windows 10 due to the elimination of the system DNS binding order. The local LAN may bind above the VPN, failing to resolve local DNS over the tunnel. Select this setting to apply the legacy binding order behavior. For more information, see Windows 10: DNS Binding Order.

Umbrella Roaming Client

  • IPv6 DNS Redirection—Provides DNS protection through redirection to Umbrella resolvers for IPv6.
  • Allow IP Layer Enforcement—Provides protection against threats that bypass DNS lookups. IP Layer enforcement must be enabled for DNS policies to which the roaming computer is added.

AnyConnect Roaming Client

  • AnyConnect VPN Trusted Network Detection—Trusted Network Detection (TND) is configured in the AnyConnect VPN Client profile. Enabling this setting disables DNS and web traffic forwarding to Umbrella whenever TND indicates the current network is trusted. Currently, DNS and web traffic can only be disabled together.
    Note: For tunnels, this functionality is only supported for full tunnels. It does not work for full tunnels with dynamic split tunneling.
  • AnyConnect Full-Tunnel VPN—When enabled, DNS and web traffic forwarding to Umbrella is disabled when a full-tunnel AnyConnect VPN session is active.
  • Auto-update—When enabled, AnyConnect is automatically updated, except when active VPN is detected. This updates the entire AnyConnect client, including the roaming security module.
  • VA Backoff—When enabled, DNS and Web forwarding to Umbrella is disabled if the Umbrella roaming client is behind a virtual appliance.
    Note: Only supported for the Windows OS and AnyConnect 4.8 MR2 and above.
  • Trusted Network Domain—When enabled, DNS and web redirection to Umbrella is disabled if the subdomain name added to the Domain field is found on the network and resolves to an RFC-1918 local IP address.
    • Domain—The subdomain that Umbrella queries the local DNS server for when Trusted Network Domain is enabled.
  • IPv6 DNS Redirection—Provides DNS protection through redirection to Umbrella resolvers for IPv6. This setting is separate from the same tilted setting listed under Umbrella Roaming Client Settings.
    Note: The minimum required version of AnyConnect is 4.8mr2.
  • IPv4/IPv6 Dual-Stack Compatibility—Supports web requests on dual-stack networks to IPv4-only or dual-stack hosts.
    Note: Destinations on IPv6-only hosts are not supported.
  • IP Layer Enforcement—Provides protection against threats that bypass DNS lookups. IP Layer enforcement must be enabled for DNS policies.
  • Secure Web Gateway—Provides full web proxy protection for internet traffic by turning on the SWG Agent. See also, Enable the AnyConnect SWG Agent.
    Note: Currently, the Enable AnyConnect SWG setting turns on the SWG Agent for all AnyConnect endpoints. A future release will introduce the ability to selectively turn the SWG Agent on or off for individual or grouped endpoints.

Domain Management < Roaming Computer Settings > Command-line and Customization for Installation

Updated 13 days ago

Roaming Computer Settings


Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.