Active Directory Sites and Internal Networks Sites and Internal Networks: Setup Guide Sites and Internal Networks Setup Guide for Umbrella Page 1
Overview Internal Networks allows to you manage your Umbrella policy for subnets of computers based on the internal IP addresses of your network. To create a Networks identity, define a subnet that's non-routable (or RFC 1918 compliant) as an Identity you can apply policy to. For instance, if your Internal Network is defined as 192.168.0/24, any computer, tablet or device with an IP on that subnet would receive the filtering policy defined for it whenever it made a request to access the Internet. From there you can begin to build multiples Sites if you have more than one physical location or if you have more than one Internal Network to configure. For an overview on the process of setting up an internal network check out the getting started video here. Prerequisites These steps assume you have set up at least one Virtual Appliance (VA). Please ensure: A Virtual Appliance (VA) has been deployed. Please follow the steps in the Virtual Appliance Setup Guide for Umbrella to configure your Virtual Appliance. Local clients are have been configured and are successfully able to route DNS queries to the VA. This is covered on page 20 of the Virtual Appliance Setup Guide for Umbrella.!NOTE: The recommended requirements for installation include a second VA for redundancy to ensure uptime during upgrade and high availability. For additional guidance on step-by-step configuration of a virtual appliance, please see our article here: https://support.opendns.com/entries/22085690-quick-start-virtual-appliances-stage-1-getting-ready We require a minimum of two (2) virtual appliances per site to be deployed for high availability in case of outage or upgrade to the VA. A "site" refers to a localized contiguous subnet without NAT between the VA and the network.!important! In order for the VA to properly route local DNS queries and external DNS queries, all clients that are to be managed by Umbrella need to have their DNS addresses be the addresses of your VAs. Sites and Internal Networks Setup Guide for Umbrella Page 2
Step 1: Provisioning a Site and Subnet for Your VA The first step is to define a Site for the Virtual Appliances you d configured previously (see: prerequisites). If you re configuring Virtual Appliances for more than one site, please see Appendix A in this guide for assistance understanding multiple sites. To define a site, navigate to System Settings > Sites & Active Directory in your Umbrella dashboard. By default, the first VA will be assigned to the Default Site. If you would like to change the name of the Site for the VA, or if you would like to add a second Site for a second VA, you can change the Site for the VA by adding a new site. Just expand the VA, add a new Site or pick the Default Site: Sites and Internal Networks Setup Guide for Umbrella Page 3
Step 2: Add an Internal Network for your Site Once you've set your first site up, in the Umbrella dashboard go to Configuration > Identities > Internal Networks To configure your first Internal Network, click 'add a new network'. You'll be asked to name your network and provide a valid subnet. In this case, we've picked a /24 subnet, so the final octet of the IP range will be.0!important! If you re unfamiliar with traditional subnet masks, there are subnet calculating tools online to help. The final octet of your IP range should match the mask for that range. The Internal Networks setup will not allow an invalid range to be configured. Some examples of valid subnets, either very small or very large are: Sites and Internal Networks Setup Guide for Umbrella Page 4
This control can be quite granular: you can assign an individual Internal Network policy to a single IP or to a DHCP scope that's already been configured for your network. Sites and Internal Networks Setup Guide for Umbrella Page 5
Step 3: Policy Configuration for your Site By default the Internal Network you've configured will be assigned to the Default Site, which is given the Default Policy in your Umbrella. You can change this by assigning the Identity for your Site to a new Policy, which can take precedence if ordered first. Alternately, you can create a unique Policy for the Identity for your site by drilling down through the Sites under the Policy section: Once you've selected the site that contains your Internal Networks, you can begin to select the parts of the policy to apply to these computers with the policy builder. Sites and Internal Networks Setup Guide for Umbrella Page 6
1. Navigate to Configuration >Policies, and click add a new policy or click the name of an existing policy. 2. Check the Sites box if you want to apply a single policy for all installed Sites, or check the box next to one or more sites by drilling down on the identity picker. To remove a selected Site, either uncheck its box via the identity picker or click the red X icon to the right of its name. Then click next. 3. Select the 'Policy Settings' for Security Settings, Content Settings and Domain Lists, then 'Block Page Settings' you would like enforced for this policy. Then click next.!note: If you have not yet created any non-default settings, go to the 'Policy Settings' or 'Block Page Settings' pages to do so. 4. Set a meaningful description for the policy, then click save.!note: The policy you created will be applied within 60-90 seconds to any new connections coming into Umbrella from the computers at this selected site. 5. Click and hold the drag handle icon to re-order the policy above or below any other existing policies.!note: Policy execution follows a top-down, first-match order of operations. The first policy assigned to an identity is enforced. Any subsequent policies assigned to the same identity are ignored. There is an editable, but immutable, Default Policy always ordered last, which is a catchall for any identity.!important: When testing the policy enforcement, some DNS responses may already be cached for several minutes to days. You may want to flush the DNS cache via both the browser and the OS to avoid waiting for the cached responses to expire. You can confirm that your policy is being applied to the network in question by selecting Identities > Internal Networks, and ensuring that your network has the appropriate policy applied. Sites and Internal Networks Setup Guide for Umbrella Page 7
Step 4: Testing Traffic for your Internal Network A quick test to ensure your internal network is provisioned correctly for the network you ve set up is to check the reporting for that identity. First, ensure you ve used a computer or other device within the Internal Network s IP range to access the Internet to generate reporting data. Next, Go to Reports > Activity Report and then set the filter for the report to the Internal Network you created: Once you ve run the report, you should see the identity name listed along with Internet traffic coming from the IP addresses associated with your Internal Networks. Sites and Internal Networks Setup Guide for Umbrella Page 8
Appendix A: About Sites "Sites in Umbrella refer to separate different locations or networks, which do not have a direct connection to another of your locations or networks. Utilizing different Sites results in a segregated Internal Networks environment. In example: different "Sites" means that each location must have a minimum of 1 Virtual Appliance (VA's). Note: We recommend 2 VA's for redundancy. When you do NOT want to use Sites You have multiple locations or networks, which are interconnected by a Site-2-Site VPN. You have an MPLS circuit between multiple locations. You utilize a networking methodology wherein your end-machine's internal IP address is maintained when communicating with another network (No NAT). When you DO want to use Sites There is 150ms or more of latency between two locations Your locations communicate between a NAT device, which causes the internal IP address of an end machine to be lost. Adding/Managing Sites For managing Sites, click on an existing Insights identity, and the dropdown will contain a menu to add a new Site, or change the site of the component. Sites and Internal Networks Setup Guide for Umbrella Page 9
Umbrella is brought to you by OpenDNS. Trusted by millions around the world. The easiest way to prevent malware and phishing attacks, contain botnets, and make your Internet faster and more reliable. OpenDNS, Inc. www.umbrella.com 1.877.811.2367 Copyright 2012 OpenDNS, Inc. All rights reserved worldwide. No part of this document may be reproduced by any means nor translated to any electronic medium without the written consent of OpenDNS, Inc. Information contained in this document is believed to be accurate and reliable, however, OpenDNS, Inc. assumes no responsibility for its use.