Cisco Secure Access Help

PDF

Cisco Secure Access Help

About Isolated Destinations

Want to summarize with AI?

Log in

Describes About Isolated Destinations in Cisco Secure Access and outlines Browser Prerequisites and Secure Access Prerequisites. It summarizes the related concepts, procedures, and operational details presented throughout the topic.


Note
Secure Access Packages and Feature Availability

Not all of the features described here are available to all Secure Access packages. Information about your current package is listed on the Admin > Licensing page. For more information, see Determine Your Current Package. If you encounter a feature here that you do not have access to, contact your sales representative for more information about your current package. See also, Cisco Secure Access Packages

Remote browser isolation (RBI) protects identities from potential malware and other threats by redirecting browsing to a cloud-based host. Destinations and threat categories supported by RBI can be isolated when added to an Internet access rule in a Secure Access policy. When you add a rule and specify an Isolate rule action, the selected destination or threat category in the rule will create a remote browser when users attempt to access the content. Instead of blocking identities from the endpoints, a cloud-based browser hosts the browsing session for that destination or threat category.

Note
RBI does not support mobile devices such as iOS and Android.

The Graphic for Docs1 interface.

Before you can successfully isolate destinations, you must meet the prerequisites for Secure Access and the prerequisites for the use of RBI with the browsers deployed in the organization.

Browser Prerequisites

  • Access to third-party cookies enabled.

    Note
    By default, most browsers (for example, Google Chrome) have third-party cookies blocked in incognito mode. You must update this setting to allow access to third-party cookies for isolation to work.
  • Minimum supported browser versions:

    • Apple Safari 9

    • Google Chrome 34

    • Microsoft Edge 12

    • Mozilla Firefox 17

    • Samsung Internet 11

  • The Cisco Secure Access root certificate or customer CA-signed certificate must be installed. For more information, see Manage Certificates.

  • RBI does not support mobile devices such as iOS and Android.

Note
Browser extensions and plugins are not supported and browser-specific features are not guaranteed to work. Regardless of the browser the user initiates the browsing session with, the cloud-based browser for isolation will always be Google Chrome.

Secure Access Prerequisites

  • Decryption must be enabled for the rule. Make sure it is enabled in the security profile selected in the rule.

  • If a Do Not Decrypt list is specified in the security profile, the list cannot include destinations (within destination lists, content categories, or application settings) that are required for isolation to ensure those domains and URLs can be decrypted.

  • Destinations required or intended for isolation should not be included your bypass lists. For more information see Manage Domains and Manage Internet Security.


Secure Access Package Support for RBI and Isolation Rules

Secure Access remote browser isolation (RBI) provides an added layer of protection against browser-based security threats. RBI moves the most dangerous part of browsing the internet away from the end user's device and into the cloud. This makes it possible for users to visit web destinations safely, enabling users to be productive and access the web destinations they need without negative impacts.

Secure Access provides two levels of RBI support: RBI Advanced and RBI Risky.

RBI Advanced

Supported isolation controls include:

  • Watermarking

  • Copy and Paste

  • Read-only and read/write

  • Document isolation

  • Downloads and uploads

Supported destinations include:

  • All content categories

  • Destination list entries including domains, URLs, IPv4 addresses, and CIDR block.

    Note
    Secure Access does not support RBI and isolation rules for IPv6 destinations.
  • All applications

  • All threat categories

RBI Risky

Supported destinations include:

  • Uncategorized content categories

  • Threat Categories: Malware, Command and Control, Phishing Attacks, and Potentially Harmful Domains

Secure Access Packages and RBI Support

When chosen as the rule action, the availability of isolation controls, destinations, and threat categories is based on your Secure Access package's RBI support.

  • RBI Advanced is bundled with the Secure Access Advantage and available as an add-on for Secure Access Essentials.

  • RBI Risky is available as an add-on for Secure Access Essentials.

Note
Currently, isolation applies only to Internet Access rules.

Verifying Isolation

You can verify isolation by checking for a Cisco logo in the bottom right-hand corner of the browser when isolation is successful.


You can verify isolation by checking for a Cisco logo in the bottom right-hand corner of the browser when isolation is successful.

Limitations of Isolation

  • You can isolate either destinations or threat categories in a Secure Access policy Internet access rule. You cannot specify both in the same rule. You can create a separate rule for each type.

  • Only top-level page requests can be isolated and pages can either be entirely isolated (top-level request and resource requests) or not.

  • 5 GB is the maximum file size that can be downloaded through the isolation environment when RBI is enforced on a browser connection.

  • If your Secure Access package expires or downgrades, any rule with Isolate may no longer work as expected. You should review and update the Action setting for these rules as needed.


Isolate Downgrade

When chosen as the rule action, the availability of isolation controls, destinations, and threat categories is based on your Secure Access package's RBI support.

  • RBI Advanced is bundled with the Secure Access Advantage and available as an add-on for Secure Access Essentials.

  • RBI Risky is available as an add-on for Secure Access Essentials.

Expired or Downgraded Package Support for RBI

If your Secure Access package expires or downgrades from RBI Advanced to RBI Risky, any rule with Isolate may no longer work as expected. When this happens you'll see a Subscription Alert banner on the Access Policy dashboard, as shown below.


The Downgrade Banner interface.

Any rules that are impacted by a package downgrade are flagged in the rule list. You'll need to review the impacted rules and take appropriate action.


Filter Isolate Rules

Note that the Subscription Alert banner for the package downgrade only appears when there is an Isolate rule visible on the current page that lists Access Policy rules. In other words, as you navigate through multiple pages of access rules, the banner appears only on pages that have an Isolate rule.

For ease of review, you can filter the rules by Intent to bring the Isolate rules to the beginning of the rules table.

Before you begin

Note
Prerequisites for internet access rules are similar to but different from prerequisites for private access rules.

Procedure

  1. Navigate to Secure > Access Rules.

  2. In the Search area at the top of the rule list, click Intent and check Isolate to sort the Isolate rules to the top of the rule list.




Duplicate a Downgraded Isolate Rule

You can duplicate a Secure Access internet access rule, which can be helpful in creating a new rule with the same criteria as the original rule. With respect to downgraded rules with unsupported destinations, you can duplicate the rule and then modify it as needed. The rule will be set to Allow only, and you can edit the source, destination, and security controls. Note that you cannot modify the original downgraded Isolate rule.

Before you begin

Note
Prerequisites for internet access rules are similar to but different from prerequisites for private access rules.

Procedure

  1. Navigate to Secure > Access Rules.

  2. In the sorted rule list, you can do a quick search for flagged Isolate rules you want to duplicate. Select the ellipses context menu () and choose Duplicate.