- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DoH and DoT: dns google - Being Block by Cisco Umbrella
Hi everyone,
I recently added the security subscription to my Meraki GO setup. Very happy I have the added protection.
However, I'm receiving a ton of notifications for "DoH and DoT: dns google" being blocked.
When I searched google it appears these are used for encrypted DNS traffic. I'm curious why they are being blocked if that's accurate. Could anyone explain?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @CHaywood - I had the same question initially! From my experience, this is intentional as the device blocks known encrypted DNS traffic endpoints so that the content filter/security subscription cannot be circumvented. Without this block, users could still open whatever they content they like as the encrypted DNS traffic cannot be inspected by the device.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can exclude those
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Greetings @CHaywood
@jesseb514 nailed it. If the DNS queries are encrypted, the security service is unable to see what the query is and take action based on the query.
