Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Registered Networks

Want to summarize with AI?

Log in

A Registered Network resource represents a single public static or dynamic IP address, or a range of IP addresses. Cisco Secure Access supports both IPv4 and IPv6 static IP addresses and dynamic IP addresses over IPv4.


A resource is an internet capable entity that is managed by your organization. After you add a resource to Cisco Secure Access, your resource is protected against threats and attacks through security configurations defined in policy rules. Secure Access can support high-level entities within your organization—for example, registered or internal networks —or very granular entities—for example, a single user logged into Microsoft o365. For more information about policy rules, see Manage the Access Policy.

A Registered Network resource represents a single public static or dynamic IP address, or a range of IP addresses. Cisco Secure Access supports both IPv4 and IPv6 static IP addresses and dynamic IP addresses over IPv4. In Secure Access, all traffic originating from the public IP space is identified as coming from that network. The public IP space or IP range defines the scope of the network resource.

To start protecting the networks in your organization, see Add Network Resources.


Add Network Resources

A Registered Network resource represents a single public static or dynamic IP address, or a range of IP addresses. Cisco Secure Access supports both IPv4 and IPv6 for static IP addresses and only IPv4 for dynamic IP addresses. In Secure Access, all traffic originating from the public IP space is identified as coming from that network. The public IP space or IP range defines the scope of the network resource.

To start protecting your public networks managed by your organization, add network resources to Secure Access. Once you've configured and added a network resource, build policy rules to extend Secure Access's protection to any device that connects to the internet from behind that network. For more information about Secure Access policy rules, see Manage the Access Policy.

Note
The Secure Access policy supports the use of PAC files with a public static network. For more information about PAC files, see Manage PAC Files.

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.
  • Your network's IP address is unique within Secure Access.

Dynamic IP Address—IPv4 Only

Secure Access supports dynamic IP addresses only over IPv4. Most home, small school, and small business networks are provisioned typically by Internet Service Providers (ISPs) with a dynamic IP address (IPv4) when defining each unique internet network.

If you have a dynamic IP address, the public IP of your network changes over time when the lease for that IP address changes. An internet service provider (ISP) provides a dynamic IP address to your device temporarily. Your IP may stay the same for some time period, but the lease eventually expires and is given to another customer of your ISP. When your IP address registered with Secure Access changes, Secure Access's security settings no longer apply. These settings no longer match your account information and you must update the network resource's IP.

Secure Access allows networks with dynamic IPv4 addresses but does not automatically track or update IP changes. When the public IP changes for a dynamic IPv4 address, the access rules in the Access policy no longer apply to the network traffic. You must update a dynamic IPv4 address manually or use a public static IP address.

Note
You cannot use the Umbrella Dynamic Network Update API to modify a dynamic IP address for a Secure Access network resource. Secure Access does not support integrations with Dynamic DNS (DDNS) clients.

Get Started with Network Resources

Add a network resource where the network has a public static IP address or IP address range, or a dynamic IP address.

Note
We recommend that you register all of your organization's networks with Secure Access at the same time. Pre-registering networks ensures that all IP spaces that belong to your organization are added to Secure Access. If you have more than one public egress IP in your organization, configure a network resource for each IP address. You must point your network's DNS to the Secure Access DNS global resolvers. Until your DNS traffic is connected to the Secure Access DNS resolvers, your networks are not protected and traffic is not logged in the Activity Search report.

Step 1 – Select the Network

First, determine the IP address of your network.

Procedure

  1. Go to http://www.whatismyip.com.

    Your IPv4 and IPv6 IP addresses and location are displayed.

  2. Use the IP addresses of your network in Step 2 – Configure the Network Resource.

What to do next

Note
Depending on your package, if you attempt to add a network other than the one currently being used to access Secure Access, Secure Access may prompt you to contact Support for manual verification. If this occurs, you'll also need manual verification from Support for IPv4 ranges larger than a /29 network and IPv6 ranges larger than a /56 network. Verification cases are created automatically and you'll receive an update as soon as it's reviewed. For more information about your current package, see Determine Your Current Package.

Step 2 – Configure the Network Resource

Secure Access only supports dynamic IP addresses for IPv4. Most home, small school, and small business networks are provisioned typically by Internet Service Providers (ISPs) with a dynamic IP address (IPv4) when defining each unique internet network.

Note
If possible, add the network resource from the IP address used to sign into Secure Access. Otherwise, Secure Access sends an email to the user account and requires that you visit a link from the IP address of the network that you are registering.

Before you begin

  • Full Admin user role. For more information, see Manage Accounts.
  • Your network's IP address is unique within Secure Access.
  • Determine if you have an IPv4 address. For more information, see Add Network Resources.

Procedure

  1. Navigate to Resources > Registered Networks and click Add.

  2. Give your network resource a descriptive Network Name.


    Add a new network page with option for adding network name for network resource
  3. Choose an internet protocol: IPv4, IPv6, or Mixed IPv4 & IPv6.

    Select a protocol based on the IP address where you have configured your router.
  4. Add the network's IP address and choose a subnet mask.

  5. For IPv4 only, if you have a dynamic IP address, check This network has a dynamic IP address.

  6. Click Save.

    Once Secure Access validates your IP address, the network resource is listed at Resources > Registered Networks. Initially, Secure Access lists the status of your network as Inactive. When Secure Access receives DNS traffic from the network, the network resource's status changes to Active.


    Secure Access displaying status of registered networks

Step 3 – Change the DNS Settings on Your Relevant Network Device

You only need to change the DNS settings on your edge DNS equipment, typically a DNS or DHCP server, or a router—a DSL router or cable modem if that's the only router in your network. For information about how to configure devices including laptops or routers, see Point Your DNS to Cisco Secure Access.

Note
The device where you test the network must have retrieved a new set of DNS servers from the DNS/DHCP server or router, or you must change the device's DNS settings manually before verifying the configuration of the network resource.

Step 4 – Apply a Policy Rule to the Network Resource

Add the network resource to an existing Secure Access policy rule or create a new policy rule and apply the rule to the network resource. If you do not add the network resource to a policy rule, Secure Access applies the Default policy rule to protect the network resource.


Step 5 – Test Your Network

Verify that your network's DNS connections are routed through Cisco Secure Access's global network.

Note
You may need to restart your client's network interface or your device.

Update a Network Resource

After you add a Registered Network resource—a public static or dynamic IP network—to Cisco Secure Access, you can update the resource.

Prerequisites


Edit the Registered Network Resource Name

Procedure

  1. Navigate to Resources > Registered Networks.

  2. Click the pencil icon to edit the Network resource Name.

  3. Enter a descriptive name for the network and then click Save.


Update the Registered Network Resource

Procedure

  1. Navigate to Resources > Registered Networks.

  2. Hover over a network resource and click the + to open the configuration dialog.

    The + icon does not appear until you hover over the Network resource.


    The List Registered Networks interface.
  3. Follow the steps in Add Network Resources to update the Registered Network resource.


    The Update Network interface.

Delete a Network Resource

Once you add a Registered Network resource—a public static or dynamic IP network—to Cisco Secure Access, you can remove the Network resource from Secure Access. After you delete a Network resource, you can no longer apply a policy rule to the resource and the network is not protected by Secure Access.

Before you begin

Procedure

  1. Navigate to Resources > Registered Networks.

  2. Hover over a network resource and click the trash can icon (Delete).

    Note
    The trash can icon does not appear until you hover over the Network resource.

    Registered Networks list displaying trash icon next to the network resource to be deleted
  3. Click Delete to confirm.

    The Network resource is deleted from Secure Access and is removed from any policy rules.


    Confirm Network Deletion popup asking for confirmation to delete network resource from Secure Access

Point Your DNS to Cisco Secure Access

Configure your DNS to direct traffic from your network to the Cisco Secure Access global network. When a request to resolve a hostname on the internet is made from a network pointed at our DNS addresses, Secure Access applies the security settings configured in your policy rules.

To have Secure Access protect your networks, you need to explicitly change the DNS settings in your operating system or hardware firewall or router to Secure Access's name server IP addresses and turn off the automatic DNS servers provided by your ISP. Secure Access supports both IPv4 and IPv6 addresses.

Note
Several systems allow you to specify multiple DNS servers. We recommend that you only use the Cisco Secure Access DNS servers and do not include any other DNS servers.

Prerequisites

  • Administrative privileges on the device or server where the DNS is configured.
Note

We recommend that only users who have administrative access to the router, DNS server, or their own computer attempt to use these instructions as you need this level of access to complete these steps.


Cisco Secure Access DNS Resolvers – IP addresses

IPv4 IPv6
208.67.222.222 2620:119:35::35
208.67.220.220 2620:119:53::53

Cisco Secure Access DNS Resolvers – Anycast IP Addresses

North America (USA-only) DNS resolvers guarantee only that DNS queries are resolved by a USA-based Secure Access data center. Block pages use global Anycast and may go to any data center, including one located outside of the USA.

IPv4 IPv6 Port/Protocol Description
208.67.222.222 2620:119:35::35 53 TCP/UDP Primary
208.67.220.220 2620:119:53::53 53 TCP/UDP Secondary
208.67.220.222 n/a 53 TCP/UDP Tertiary
208.67.222.220 n/a 53 TCP/UDP Quaternary
208.67.221.76 2620:119:17::76 53 TCP/UDP USA only Primary
208.67.223.76 2620:119:76::76 53 TCP/UDP USA only Secondary

Procedure for Pointing Your DNS to Cisco Secure Access

Change the DNS server addresses to Cisco Secure Access DNS server addresses.

Prerequisites

  • Administrative privileges on the device or server where the DNS is configured.
Note
We recommend that only users who have administrative access to the router, DNS server, or their own computer attempt to use these instructions as you need this level of access to complete these steps.

Step 1 – Identify Where Your Public DNS Server Addresses are Configured

Determine which device or server on your network maintains the addresses of your public DNS servers—most often a router or DNS server. Typically, the device that provides an internal non-routable IP address (DHCP) or the device that serves as your default gateway is also where you configure public DNS servers.


Step 2 – Log Into the Server or Router Where DNS is Configured

Procedure

  1. Log into the server or router where the DNS settings are configured.

  2. Locate the DNS settings for this device. If you are unsure of where these settings are and require guidance on configuring a server or router, see Step 3 – Change Your DNS Server Addresses.


Step 3 – Change Your DNS Server Addresses

Before you change your DNS settings to use Secure Access, record the current DNS server addresses or settings (for example, write them down on a piece of paper). Retain a copy of these DNS settings in case you need to revert to them at a later date.

Some ISPs hard-code their DNS servers into the equipment they provide. If you are using such a device, you can not configure it to use Secure Access. Instead, you can configure each of your computers by installing the Cisco Secure Client or configuring the DNS server addresses on each computer. For more information about configuring a Windows, macOS, or Linux computer, see Computer Configuration.

The process for changing your DNS settings varies according to the operating system and version (Windows, Mac, or Linux) or the device (DNS server, router, or mobile device). This procedure might not apply to your OS, router, or device. For authoritative information, see the vendor documentation.

To change your settings on a typical router:

Procedure

  1. In your browser, enter the IP address to access the router's user interface and enter your password.

  2. Find the area of configuration in which DNS server settings are specified and replace those addresses with the Cisco Secure Access IP addresses.

    IPv4 IPv6
    208.67.222.222 2620:119:35::35
    208.67.220.220 2620:119:53::53

Primary and Secondary Servers

You can use either an IPv4 or IPv6 DNS address as your primary or secondary DNS server. You must use both numbers and not the same IP address twice. If your router requires a third or fourth DNS server setting, you can use 208.67.220.222 and 208.67.222.220 or 2620:119:35::35 and 2620:119:53::53 as the third and fourth entry respectively.

Procedure

  1. Save your changes and exit your router's user interface.

  2. Flush your DNS cache.

  3. Confirm that your DNS is set as static.

  4. Test that your setup is working correctly. See Step 4 – Test Your New DNS Settings.

    Tip
    When you make changes to DNS, you may have cached results that affect service. Flush your DNS cache to ensure that you're receiving only the latest DNS results. For information on how to flush your DNS cache, see Clear Your DNS Cache.
    Note
    Email servers have unique DNS configurations. We don't recommend that you configure your email servers to point to Secure Access DNS.

Step 4 – Test Your New DNS Settings