Cisco Secure Access Help

PDF

Cisco Secure Access Help

Quickstarts

Want to summarize with AI?

Log in

Quickstarts walk you through the recommended order of tasks to set up a specific deployment, linking out to the procedures for completing them.


Quickstart tasks are designed as individual onboarding workflows. A workflow describes how to connect users in your organization securely to private, Software as a Service (SaaS), and public internet resources using various deployments.

A user device can connect securely to resources through the following types of deployments:

Prerequisites for Quickstarts


Quickstart – Cisco Secure Client with Zero Trust Access

The Cisco Secure Client with Zero Trust Access connects user devices securely to private resources in on-premises data centers managed by your organization and resources in private and public clouds. Cisco Secure Access Zero supports visibility into user and device identities, network connectivity, and security posture.

User devices must have the Cisco Secure Client with Zero Trust Access deployed and configure a Secure Access Zero Trust Access endpoint posture profile. Users are members of the organization who manages their devices. An administrator must configure the Zero Trust Access endpoint posture profiles in Secure Access and apply a policy rule that includes the Zero Trust Access profiles to the user devices.

The procedure to start onboarding user devices in an organization with the Secure Client and Zero Trust Access should take no more than ten minutes.

Before you begin

Procedure

  1. Deploy network connectors in Secure Access.

  2. Provision users and groups in Secure Access. For more information, see Manage Users and Groups.

  3. Configure SAML integrations with identity providers (IdPs). For more information, see Configure Integrations with SAML Identity Providers.

  4. Create Zero Trust (ZT) posture profiles for the user devices in the organization. For more information, see Manage Zero Trust Access Posture Profile.

  5. Create a policy rule or add an ZT posture profile to an existing Secure Access rule. For more information, see Manage the Access Policy.

  6. Deploy Cisco Secure Client with Zero Trust on user devices.

What to do next

  • Check that you can reach private resources protected by Secure Access.

Quickstart – Cisco Secure Client with Virtual Private Network

Cisco Secure Client with VPN connects user devices securely to private resources in data centers managed by your organization and software as a service (SaaS) resources in private and public clouds. The procedure to start onboarding user devices in an organization with the Cisco Secure Client and VPN access should take no more than ten minutes.

A VPN provides a point-to-point, private network between a user device and a resource where the traffic sent over the network is encrypted and the IP address of the source is hidden.

User devices must have the Secure Client deployed with the VPN module and VPN XML metadata file, and configure a Secure Access VPN endpoint posture profile. Users are members of the Secure Access organization that manages their devices. An administrator must configure the network connections—Network Tunnel Groups or Resource Connector Groups—for the organization.

Before you begin

Procedure

  1. Deploy network connectors in Secure Access.

  2. Provision users and groups in Secure Access. For more information, see Manage Users and Groups.

  3. Configure SAML integrations with identity providers (IdPs). For more information, see Configure Integrations with SAML Identity Providers.

  4. Create a VPN endpoint posture profile for the user devices. For more information, see Add a VPN Connection Posture Profile.

  5. Create a policy rule or add a VPN endpoint posture profile for the user devices to an existing Secure Access rule. For more information, see About the Access Policy.

  6. Deploy Cisco Secure Client with VPN on user devices in the organization.

What to do next

  • Check that you can reach private, SaaS, and internet resources protected by Secure Access.

Quickstart – Cisco Secure Client with Internet Security

The Cisco Secure Client with Internet Security—DNS-layer security and Secure Web Gateway (SWG)—connects user devices securely to internet resources. The procedure to start onboarding user devices in an organization with the Cisco Secure Client and Internet Security access should take no more than ten minutes.

User devices must have the Cisco Secure Client deployed with the Umbrella module. Users are members of the organization that manages their devices. An administrator must configure the network connections—Network Tunnel Groups—and add Registered Networks and Internal Networks to their Secure Access organization.

Before you begin

Procedure

  1. Deploy network connectors in Secure Access.

  2. Provision users and groups in Secure Access. For more information, see Manage Users and Groups.

  3. Configure SAML integrations with identity providers (IdPs). For more information, see Configure Integrations with SAML Identity Providers.

  4. Create a Web posture profile for the user devices. For more information, see Add a Web Profile.

  5. Create a policy rule or add a Web profile for the user devices to an existing Secure Access rule. For more information, see Manage the Access Policy.

  6. Deploy Cisco Secure Client with Umbrella on user devices in the organization.

What to do next

  • Check that you can reach internet resources protected by Secure Access.


Quickstart – Browser with SAML Authentication

This Quickstart guide describes how to connect user devices securely to internet resources from a browser. The onboarding procedure should take no more than 10 minutes.

User devices must have a browser installed and configure a Secure Access Web profile. Users are members of the organization that manages their devices.

Before you begin

Procedure

  1. Provision users and groups in Secure Access. For more information, see Manage Users and Groups.

  2. Configure SAML integrations with identity providers (IdPs). For more information, see Configure Integrations with SAML Identity Providers.

  3. Create a Secure Access Web profile that includes the user devices. For more information, see Add a Web Profile.

  4. Set up a Secure Access PAC file. For more information, see Manage PAC Files.

  5. Create a policy rule or add a Web profile to an existing Secure Access rule. For more information, see Manage the Access Policy.

What to do next

  • Check that you can reach internet resources protected by Secure Access.

Quickstart – Bring Your Own Device with Zero Trust

Cisco Secure Access Zero Trust Access can connect unmanaged devices securely to private resources in on-premises data centers managed by your organization and in private and public clouds. Secure Access ZT provides visibility into user and device identities, supports network connectivity, and manages the security posture of unmanaged devices.

Bring your own devices (BYODs) are devices that are not managed by your organization, but are devices that are permitted by your organization to connect to certain private resources. An administrator shares an organization's private resource URL to the user of a BYOD device. An administrator must include the BYOD device in the Secure Access ZT endpoint posture profile and users of the devices are members of the organization.

The procedure to start onboarding unmanaged devices with Secure Access Zero Trust in an organization should take no more than ten minutes.

Before you begin

Procedure

  1. Deploy network connectors in Secure Access.

  2. Provision users and groups in Secure Access. For more information, see Manage Users and Groups.

  3. Configure SAML integrations with identity providers (IdPs). For more information, see Configure Integrations with SAML Identity Providers.

  4. Create Zero Trust (ZT) posture profiles for the user devices in the organization. For more information, see Manage Zero Trust Access Posture Profile.

  5. Provide Secure Access private resource URLs to users on unmanaged devices.

  6. Create a policy rule or add an ZT posture profile to an existing Secure Access rule. For more information, see Manage the Access Policy.

What to do next

  • Check that you can reach private resources protected by Secure Access.