Cisco Secure Access Help

PDF

Cisco Secure Access Help

Secure Access Onboarding Workflow

Want to summarize with AI?

Log in

The Get Started with Secure Access onboading workflow guides you through the initial setup of Secure Access.


The Get Started with Cisco Secure Access workflow guides you through the initial setup of Secure Access.

Sign in to Secure Access and navigate to Workflows. The first step in the Get Started workflow takes you through the setup of your organization's network connections—network tunnel groups and network tunnels. At the same time, you can provision users and groups from your organization in Secure Access and set up integrations with Security Assertion Markup Language (SAML) identity providers (IdPs).

After you establish network connections, begin the Secure resources and access step in the workflow that includes:

  • designing endpoint posture profiles
  • IPS and security profiles
  • policy rules

Then, in the Configure end user connectivity step, define traffic patterns for remote user connections to resources—configure DNS servers, Zero Trust, virtual private networks (VPNs), and internet security settings.


The Get Started First Workflow interface.

As an administrator, review and audit connections and traffic events in the Secure Access logs and reports. Start with the Secure Access Overview Dashboard. For more information, see Secure Access Overview Dashboard.


Step 1 – Configure network connections

The Get Started with Cisco Secure Access workflow guides you through the tasks in the Configure Infrastructure step—configure Resource Connector Groups and Resource Connectors, and configure Network Tunnel Groups and establish network tunnels to Secure Access. After you complete the network connections deployment steps, provision users and groups from your organization in Secure Access and configure integrations with SAML identity providers (IdPs). For more information, see Manage Network Connections.

Prerequisites


Task 1 – Add Network Connections

Add Network Tunnel Groups

Add Network Tunnel Groups to your organization and deploy and manage IPsec tunnels. A deployed IPsec tunnel supports connections over a virtual private network (VPN) to resources on the network, or connections secured by Zero Trust Network Access (ZTNA) to the private resources on the network.

Add Resource Connectors and Connector Groups

Add Resource Connector Groups to your organization where a connector group includes at least two Resource Connectors. A Resource Connector Group supports remote network connections using Zero Trust Network Access (ZTNA) to private resources running in private clouds or on-premises data centers.


Task 2 – Provision Users and Groups

Provision users and groups from your organization in Secure Access. You can configure users and groups though integrations with identity providers (IdPs) or by manually importing a list of users and groups from a comma-separated values (CSV) file. Once you provision users, you can configure and manage users in profiles that secure and route traffic from user devices. For more information, see Manage Users, Groups and Endpoint Devices.


Task 3 – Configure Integrations with SAML Identity Providers


Step 2 – Configure access to resources

The Get Started with Secure Access workflow guides you through the tasks in the Secure Resources and Access step—secure your private resources, enable access controls on resources, and create policy rules. For more information, see Manage Private Resources.


Secure resources and access section with options to secure and manage private resources

Prerequisites


Task 1 – Set Up Private Resources

Configure access to private resources for your users. Private resources are private subnets (IPv4 routes) and applications deployed and managed by your organization.


Task 2 – Configure Rule Defaults and Global Settings

Set up Secure Access rule defaults and global settings to access private resources.

Manage Rule Defaults

Manage Global Settings

Manage the settings that apply to all policy rules. The Secure Access policy has both global and default settings.

Global Settings:

Default Settings:


Task 3 – Add a Policy Rule


Step 3 - Configure end user connectivity

The Get Started with Secure Access workflow guides you through the tasks in the Configure End User Connectivity step—configure DNS servers, internet security, virtual private networks (VPNs), and Zero Trust (ZT) access for user devices.


The Client Connectivity Steps interface.

Prerequisites

Task 1 – Configure Zero Trust

Configure connections to private resources from user devices.

Task 2 – Configure Virtual Private Networks

Set up virtual private networks (VPNs) settings.

Task 3 – Configure Internet Security

Add DNS servers, add domains to internal domains list, configure internet security settings for the Cisco Secure Client.

Configure Endpoints and Networks


Step 4 – Configure endpoints and network sources

The Get Started with Secure Access workflow guides you through the tasks in the What's Next step—configure your organization's user devices, add registered and internal networks to Secure Access, and configure IPS and endpoint posture profiles in policy rules.


What's Next page showing stepst to create and configure Cisco Secure Access

Prerequisites

Add Networks to Secure Access

Set Up the Cisco Secure Client

Add IPS Profiles

Configure Rule Profiles