Cisco Secure Access Help

PDF

Cisco Secure Access Help

Secure Access Overview Dashboard

Want to summarize with AI?

Log in

The Overview dashboard displays status, usage, and health metrics for your organization. Use this information to address security threats and monitor system usage.


The Secure Access Overview dashboard lists the latest information about your organization's traffic and the amount of data that was transferred over your connections and how the data correlates this with security events.

From the Overview dashboard, you can set up Secure Access through the Get Started with Secure Access workflow. If you have established network connectivity, the first workflow is completed and lists your network connections. For more information about Secure Access workflows and how to start, see Begin Secure Access Onboarding Workflow.

Once you configure your organization's network connectivity, confirm that traffic from user devices can reach Secure Access. For information about the Secure Access reports, see Get Started with Reports.

Prerequisites

  • A minimum user role of Read Only. For more information, see Manage Accounts.

Get Started Workflow

The Getting Started with Secure Access Workflow describes the first configuration steps required to begin protecting your systems with Secure Access.


Getting Started with Cisco Secure Access page showing an option to configure the infrastructure to Secure Access

Experience Insights

The Experience Insights section describes the Secure Access feature and its benefits. Click Get Started to begin the process of onboarding and configuring Experience Insights.

  • After you onboard Experience Insights, the section will no longer display.

After you onboard Experience Insights, the section will no longer display.

Network Tunnel Group Usage

The Network tunnel group usage section displays the traffic usage for your organization's network tunnel groups. Use this section to analyze traffic patterns and monitor traffic usage across network tunnel groups for the selected billing period (current billing month, Previous billing month, Last six billing months, or a custom date range).

  • Region: By default, the dashboard displays usage for All regions. You can use the region filter to isolate data for specific geographic areas.

  • Traffic summary: Displays the total traffic transferred for the selected billing period.

  • Top network tunnel group by traffic: Displays the Network tunnel group with the highest traffic usage. Clicking the tunnel group name opens a side panel where you can select a billing period (Current billing month, Previous billing month, Last 6 billing months, or a Custom date range) to view these detailed metrics:

    • Traffic trends: A visualization of inbound and outbound traffic over your selected period. You can hover over the chart to view specific traffic data for any given date.

    • Traffic breakdown: A summary of total inbound (In) and outbound (Out) data volume.

    • Traffic used: The aggregate volume of data transferred through the tunnel group.

    • View: Click View to open the Network tunnel group usage report. For more information, see Network tunnel group usage.

    • Export report: In the side panel, click Export Report to download the usage data for the selected billing period. For more information, see Export Report.

    Note
    The system automatically adjusts traffic units (for example, KB, MB, GB, TB) based on the volume of data to ensure the charts remain readable.

Connectivity


Data Transfer

The Data Transfer section describes the total traffic, and the amount of data received and sent over the networks in your organization. Filter the usage data by the source to identify trends related to the type of connectivity:

  • Branch

  • Roaming client

  • RAVPN

  • Client-based ZTA

  • Browser-based ZTA

Image displaying an example of data transfer overview dashboard

Security

The Security section includes information about the security activity (requests and blocks) and top security categories visited by devices and users in your organization.


Security Activity

The Security> Security Activity section displays the number of access events—requests and blocks. It also displays the number IPS events—signature events.

Image displaying an access events overview dashboard Image displaying an IPS events overview dashboard

The Security > Security Activity > IPS Events section displays an expiry banner when a certificate for Private Resource Decryption has expired or will expire within 90 days.



Users with the Full Admin or Security Administrator role can follow the Certificates link to update the certificate, or close the banner. If the certificate is not updated, a closed banner will reappear the next time the user opens the Overview page.


Top Security Categories

The Top Security Categories displays the number of requests to the top security categories.


The Overview Top Security Categories interface.

File Retrospective

The File Retrospective section lists the SHA256 name, the threat score, the malware name, and the date the file was detected. The threat score is a percentage from 0-100 ranking the likelihood that the file is malicious. The score is generated from the data provided in the Secure Malware Analytics (Threat Grid) Report.


Users and Groups

The Users and Groups section displays the following information:

  • The count of users exhibiting risky behaviour. Clicking the user count opens the Users, Groups, and Endpoint Devices page for more details.

    The Ueba Dashboard 1 1 interface.
  • List of top risky users with the count of risk alert categories detected for each user. Clicking View All opens the Users, Groups, and Endpoint Devices page for more details.

  • The Risky Behaviour Breakdown chart displays the number of events detected for all the risk categories.

    The Ueba Risky Behaviour Breakdown Graph 1 2 interface.
  • The user trust levels chart displays the number of users with each trust level.

  • The number of virtual private network (VPN) connections and Zero Trust Network Access authorization events over time.

    The Ueba Dashboard 3 interface.
  • The list of the top users in your organization who made the greatest number of requests in the selected time period.

    The Ueba Dashboard 4 interface.

Users and Groups displays expiry banners for certificates that impact user authentication and access when:

  • A certificate has expired

  • A certificate will expire within 90 days


The Secure Access Overview Messages Users Groups interface.

Users and Groups certificate expiry banners apply to three certificate types:

Users with the Full Admin or Security Administrator role can follow the Certificates link to update the certificate, or close the banner. If the certificate is not updated, a closed banner will reappear the next time the user opens the Overview page.


Private Resources

The Private Resources section displays the number of times applications are requested, the number of unique active users that request access, and the number of requests that are allowed or blocked over the selected time period.


The Overview Private Resources Data interface.

The Private Resources section also displays the number of times remote users connected to Secure Access and the method of the connection: virtual private network (VPN),client-based ZTNA, or clientless ZTNA. The section also includes the top resources that received traffic.


The Overview VPN Resources interface.