Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage the Access Policy

Want to summarize with AI?

Log in

Describes Manage the Access Policy in Cisco Secure Access. Secure Access has a single Access policy, which consists of policy rules and settings.


Secure Access has a single Access policy, which consists of policy rules and settings. Your private access and internet policy rules and the default policy rules control the access and security of your resources and protect the traffic in your organization. Before you start adding rules to your policy, we recommend that you read through the topics in this section in full.

The Access Policy Sample Internet Private interface.

Private and internet access rules

There are two types of access rules:

The Add Policy Rule Types interface.

Rule defaults and global settings

Default access rules

If your traffic does not match any of the rules in your policy, Secure Access applies the settings on the Default Access rules. For more information, refer to Default Access Rules in Your Policy.


About the Access Policy

The Cisco Secure Access policy is the collection of your internet and private access rules, rule defaults, and global settings. The policy displays your configured rule data and allows you to choose how to prioritize the rules in your policy. Once you add a rule, you can edit various components on the rule. You decide how to view and manage your rules that best meets your organization's access controls to resources.

Best Practices

When working with access rules, keep the following in mind:

Warning
If you attach an empty private resource group to a policy, the entire rule containing the empty private resource is dropped.
  • In each rule, features where you can configure a default option show one of the following indicators:

    • Rule Defaults—If you see this icon beside a control, it means the selected option or value is the selection configured on the rule default page.



    • Custom—If you see this icon beside a control, it means the selected option or value is different from the selection configured on the rule default page.


      The Policy Rules Custom Rules interface.

Control Options on an Access Rule

In Secure Access, the Access policy contains the organization's configured access rules and the details about the Default Access Rules. From each access rule in the rules table, you can show the menu of rule controls and choose how to manage an access rule.

Before you begin

Procedure

  1. Navigate to Secure > Access Policy and then navigate to an access rule in the rules table.


    The Policy Customize View Rule interface.
  2. At the end of the row, click the ... (ellipsis) to open the menu.

  3. In the drop-down menu, choose one of the controls to manage the access rule or monitor the traffic enforced by the access rule.


    The Access Rules Control Panel interface.
    • Duplicate—Make a copy of the access rule and add the new rule in the Access policy.

    • View—View the details for the access rule.

    • View on Activity Search—View the events in the Activity Search report for the traffic where Secure Access enforced the access rule.

    • Edit—Edit the access rule.

    • Create Alert—Configure an alert rule for monitoring the changes to the access rule.

    • Disable—Disable the access rule in the Access policy.

    • Move to top—Move the access rule before the first rule in the Access policy.

    • Move to bottom—Move the access rule after the last rule in the Access policy.

    • Copy link—Copy the link to the access rule.

    • Delete—Duplicate the access rule.


Rule Data

The Secure Access policy displays various columns of data on your configured internet and private access rules. For information about choosing additional data on your rules, see Show Additional Data on Your Access Rules.


The Policy Customize View Rule interface.
  • #—The pound sign (hash symbol) indicates the priority of the rule.

  • Rule name—The unique name that you assigned to the rule. A rule name may contain a sequence of 2–50 alphanumeric, hyphen, underscore, and space characters.

  • Access—The type of access rule either Internet or Private.

  • Action—The type of action on the rule.

    • For internet access rules: Allow, Block, Isolate, or Warn.

    • For private access rules: Allow or Block.

  • Sources—The sources that can connect to the destinations.

  • Destinations—The resources that are available on the organization and from the internet.

  • Security—The security controls applied to the rule.


    The Policy Security Controls Profiles interface.

    Security controls are the globally-configured profiles that are enabled on the rule: Intrusion Prevention (IPS), Security profiles, and Tenant profiles. Hover over the security icon to display the profile information for the rule.

  • Hits—The number of times in the last seven days that Secure Access applied the access rule to the traffic defined by the sources and destinations.

  • Status—The state of the rule. Indicates whether the rule is enabled or disabled.

    Status of Rule Status Icon
    Enabled The Policy Rule Status Enabled interface.
    Disabled The Policy Rule Status Disabled interface.
  • Comments: The notes added to a rule. Click the ... icon to view or add comments. You can add comments to access policy rules to provide context, track changes, or share notes with other administrators.


    The Add Comments interface.

    Note
    The Comments column is hidden. To view, click the settings gear icon and check the Comments column. This column also displays the selected rule's comment count.
    Note
    Comments are limited to 1024 characters and are sorted in reverse chronological order (most recent comment on top).

    Each comment displays its author's name and time stamp.

    • Add a comment:

      • Rules page: Locate the rule and click the comment icon to add a note.

      • Edit rule: Click the edit icon for a rule and add a comment in the rule details page.

      • Rule details: Click the rule name to open the rule details page, scroll to the comments section, and add your note.

    • View a comment:

      • Click the table settings icon.

      • Select the Comments column and click Apply.

      • Click the comment icon in the row to view the comments page for that rule.

    • Edit or delete a comment: Navigate to the rule details page or the comments page, locate your comment, and select the appropriate action. An edited comment has a label "Edited".

    Note
    Only the author of a comment can edit or delete it. When a rule is deleted, all comments associated with that rule are permanently removed.

Audit logs

All actions related to comments, including adding, editing, and deleting, are captured in the admin audit logs. You can view these events in the audit log to track administrative changes to your organization policy. For more information, refer to Admin Audit Log Report.


Show Additional Data on Your Access Rules

The Cisco Secure Access policy table lists the configured properties, security controls, logging, and status information for your internet and private access rules. The table shows a default set of columns on the table. You can customize your view of the policy table. For more information about the default rule data, see Rule Data.

To customize the policy table, you can change the height of the table rows, add more columns of rule data, and remove the Security and Hits columns.

Customize the row height on the policy table, select additional data to display about your access rules, and remove data columns on your policy table view.


The Policy Customize View Rule interface.

Before you begin

  • Full Admin user role. For more information, see Manage Accounts.

  • Your policy has at least one configured access rule.

Procedure

  1. Navigate to Secure > Access Policy, and then click Customize view.


    The Policy Customize View interface.
  2. (Optional) For Select a row height, choose the height of the rows in the policy table.

    Select either Compact, Medium, or Tall. The default table row height is Medium.
    The Policy Customize View Row Height interface.
  3. For Show selected columns, add the names of the data columns to display on your policy table and remove the Security Control or Hits columns.


    The Policy Customize View Control Data interface.
    • Security—The security controls applied to the rule.


      The Policy Security Controls Profiles interface.

      Security controls are the globally-configured profiles that are enabled on the rule: Intrusion Prevention (IPS), Security profiles, and Tenant profiles. Hover over the security icon to display the profile information for the rule.

    • Logging—Indicates whether logging is enabled for the organization.

    • Posture—The name of the endpoint posture profile that is defined on the rule.

    • Hits—The number of times in the last seven days that Secure Access applied the access rule to the traffic defined by the sources and destinations. For more information, see Edit the Order of the Rules in Your Access Policy.

    • Last Modified—The date of the modification of the access rule by the user account.

      Note
      Hover over the date to display the ID of the user account that last modified the rule.

      The Policy Rules Last Modified interface.
  4. Click Reset defaults to show the policy table with the default rule data view or click anywhere on the page outside of the Customize View component to enable your selections and close the window.


    The Policy Customize View Extra Data interface.

Edit the Order of the Rules in Your Access Policy

The order of the rules listed on the Policy page is critical to traffic handling.

Traffic is handled by the first rule in the list that matches the traffic. Rules lower in the list have no effect on traffic that matches a rule higher in the list.

Order your rules so that more specific rules are above more general rules that might also apply to the traffic.

Put essential rules at the top, such as rules blocking access for all users to sites that you absolutely do not want any users to visit.

If no rule in the list matches the traffic, Secure Access applies the applicable default access rule for the type of traffic (internet access or private access.) Default access rules (one for each type) appear at the bottom of the Policy page.

For rule matching of encrypted internet traffic, see Ensure Rule Matching for Encrypted Internet Traffic.

An error in configuration may result in unintended results:

Resources may be unprotected from threats or users may access destinations you want blocked. Plan and design your rules before you build them.

Ways to reorder rules:

  • On the Access Policy page, right-click a rule and choose one of the following options:

    • Move to top of the list

    • Move to bottom of the list

    • Move to and then choose an order

  • While editing a rule, click the Rule Order field and click the rule you want to be immediately before the rule you are moving.


Default Access Rules in Your Policy

If your traffic does not match any of the rules in your policy, Secure Access applies the settings in the Default Access rules. For more information, see View or Edit Default Access Rules.


The Policy Default Rule Settings interface.

Default Internet Access Rule

  • Secure Access applies this rule to traffic to internet destinations that does not match any other internet access rule in the policy.

  • The default internet access rule allows traffic that hits it. You cannot change the rule action.

  • You can edit the logging settings.

  • You can edit the security control settings.

  • Posture is not applicable for internet access rules.

Default Private Access Rule

  • Secure Access applies this rule to traffic to private destinations that does not match any other private access rule in the policy.

  • The default private access rule blocks traffic that hits it. You cannot change the rule action.

  • You cannot edit the logging settings.

  • Because the action for this rule is Block, the security control settings are not needed or offered.

  • Posture is not applicable for the default access rule. Secure Access blocks the traffic whether or not the posture requirements are met.


View or Edit Default Access Rules

Secure Access has a default internet access rule and a default private access rule. The default access rules apply to traffic that does not match any other rule in the Access policy.

You can view the settings for a default private access rule. You can view and edit the settings on a default internet access rule.

Before you begin

Procedure

  1. Navigate to Secure > Access Policy.

  2. Navigate Default Access Rules located at the bottom of the Access policy page.


    The Default Access Rules View interface.
  3. Navigate to For all private access and click the ellipsis (...) at the end of the row to open the menu.

    1. Choose View to display the logging and security controls on the default private access rule.
  4. Navigate to For all internet access and click the ellipsis (...) at the end of the row to open the menu.

    1. Choose View to display the logging and security controls on the internet access rule.
    2. Choose Edit to modify the logging and security controls on the default internet access rule.
    3. For Rule Logging, enable or disable the settings and then click Save.

      The Default Internet Access Rules Edit interface.
    4. For Security Controls, enable or disable the security control settings, select an IPS profile, select a Security profile, and then click Save.

      The Default Internet Access Rules Security Controls interface.