Hey everyone! I've been setting up Cisco Umbrella for our cloud infrastructure and hit a snag I'm hoping someone can help with.
Our on-premises traffic is logging perfectly into Investigate, but all DNS queries originating from our AWS VPC are completely invisible there. The VPC resolvers are pointing to the Umbrella DNS VIPs (I double-checked 208.67.222.222 and 208.67.220.220), and the security group allows outbound UDP 53 to those IPs. Instances can resolve external domains, so basic DNS is working.
Here's what I've already verified:
* The network ACLs in the VPC are open for ephemeral ports on the return.
* We're using the same identity (IP-based) that works for on-prem.
* No custom DNS forwarders or Route 53 Resolver endpoints are interfering.
Has anyone else run into this "silent drop" of cloud DNS queries in Investigate? I'm wondering if there's a specific AWS integration step I missed, or if I need to look at the VPC DNS Resolver settings differently. The docs seem a bit more focused on the on-prem deployment.
Any pointers would be super helpful! I'm eager to get this visibility so I can start building some dashboards.
– Amanda
Show me the accuracy numbers.