Describes About Isolated Destinations in Cisco Secure Access and outlines Browser Prerequisites and Secure Access Prerequisites. It summarizes the related concepts, procedures, and operational details presented throughout the topic.
Secure Access Packages and Feature Availability Not all of the features described here are available to all Secure Access packages. Information about your current package is listed on the Admin > Licensing page. For more information, see Determine Your Current Package. If you encounter a feature here that you do not have access to, contact your sales representative for more information about your current package. See also, Cisco Secure Access Packages
Remote browser isolation (RBI) protects identities from potential malware and other threats by redirecting browsing to a cloud-based host. Destinations and threat categories supported by RBI can be isolated when added to an Internet access rule in a Secure Access policy. When you add a rule and specify an Isolate rule action, the selected destination or threat category in the rule will create a remote browser when users attempt to access the content. Instead of blocking identities from the endpoints, a cloud-based browser hosts the browsing session for that destination or threat category.
RBI does not support mobile devices such as iOS and Android.
Before you can successfully isolate destinations, you must meet the prerequisites for Secure Access and the prerequisites for the use of RBI with the browsers deployed in the organization.
Browser Prerequisites
-
Access to third-party cookies enabled.
By default, most browsers (for example, Google Chrome) have third-party cookies blocked in incognito mode. You must update this setting to allow access to third-party cookies for isolation to work. -
Minimum supported browser versions:
-
Apple Safari 9
-
Google Chrome 34
-
Microsoft Edge 12
-
Mozilla Firefox 17
-
Samsung Internet 11
-
-
The Cisco Secure Access root certificate or customer CA-signed certificate must be installed. For more information, see Manage Certificates.
-
RBI does not support mobile devices such as iOS and Android.
Browser extensions and plugins are not supported and browser-specific features are not guaranteed to work. Regardless of the browser the user initiates the browsing session with, the cloud-based browser for isolation will always be Google Chrome.
Secure Access Prerequisites
-
Decryption must be enabled for the rule. Make sure it is enabled in the security profile selected in the rule.
-
If a Do Not Decrypt list is specified in the security profile, the list cannot include destinations (within destination lists, content categories, or application settings) that are required for isolation to ensure those domains and URLs can be decrypted.
-
Destinations required or intended for isolation should not be included your bypass lists. For more information see Manage Domains and Manage Internet Security.