Cisco Secure Access Help

PDF

Cisco Secure Access Help

Geolocation Sources and Internet Access Rules

Want to summarize with AI?

Log in

Describes Geolocation Sources and Internet Access Rules in Cisco Secure Access. Geolocation sources enable organizations to monitor and control the traffic from end users in specific geographic regions.


Geolocation sources enable organizations to monitor and control the traffic from end users in specific geographic regions. The Geolocation source component is available on the internet and private access rules in the Access policy.

The Geolocation source component is a list of continents and the countries in these continents where Secure Access can manage the network traffic sent from these geographic locations.

Note
DNS resolution does not is not supported in source based geolocation policies. The geolocation source of a DNS lookup is not an indicator of where content is being delivered and as such source based geolocation checks and matches are enforced at other enforcement layers as part of unified policy based on your policy configuration.

You can select the Geolocation sources with the AD Users or AD Groups or only add the Geolocations on the access rules. Administrators of the organization are responsible for provisioning the AD Users and AD Groups. For more information, see Provision Users, Groups, and Endpoint Devices from Active Directory.

When you select the Geolocations on an access rule, Secure Access shows the AND option and the AD Users or AD Groups. When you select the AD Users and AD Groups for the source on an access rule, Secure Access shows the AND option and the list of continents and countries. Secure Access combines the selected AD Users or AD Groups and the geolocations with the boolean AND operator. You can only combine the Geolocation source component with the AD Users or AD Groups.

Monitoring Internet Traffic from Geolocations

Set up the attributes and conditions on the access rules in the Access policy to monitor and protect the network traffic from the end users located in specific geographic regions. To enforce the security controls on a rule, the network traffic must match the selected sources.

Note
Secure Internet Access (SIA) in Cisco Secure Access, policy enforcement passes through Zero Trust Access (ZTA) or through the firewall/secure gateway (SGW) depending on the traffic type and configuration; traffic is then tunneled to and inspected by the firewall.

For internet access rules, choose to allow or block all traffic from the geolocations or all traffic from the selected AD Users or AD Groups located in the countries and continents.

  • The SWG detects and enforces the web traffic (TCP/80, TCP/443) sent from the end users located in the selected continents and countries.

  • The Secure Access cloud-delivered firewall detects and enforces the network traffic on non-standard web ports sent from the end users located in the selected continents and countries.

  • For internet traffic on Zero Trust Access connections, the Secure Acces cloud-delivered firewall and Secure Web Gateway detects and enforces the traffic.

You can view the events and logs recorded by Secure Access for the traffic sent from the end users in the organization in certain geolocations. Secure Access reports on the traffic on standard web ports and non-web ports. For more information, see:


Sources

Sources on internet rules are either pre-configured, Geolocations, or composite components.

Pre-configured source components such as Registered Networks and Network Tunnel Groups acquire and manage the web traffic in your organization. For information about pre-configured source components, see Reusable Sources in Internet Access Rules.

Composite sources may include IP addresses, CIDR blocks, and wildcard masks, and ports and port ranges. For information about composite source components, see Composite Sources in Internet Access Rules.

About Selecting Sources on an Access Rule

If you select Network Tunnel Groups, Secure Access secures and controls the traffic access from the IPsec tunnels established by your supported network devices. If you need to know what tunnels are included in a group, navigate to Connect > Network Connections > Network Tunnel Groups and look at the group configuration.

If you select a Network Tunnel Group, the destination also includes IP addresses configured in the network tunnel group for routing, in addition to all associated Internal Networks. IP addresses include routes advertised using Border Gateway Protocol, if that option is selected in the network tunnel group configuration.

If you see an option to Select All, this selects all existing items in the group at the time you select it, but the rule will not include items added to the group in future.

Number of Sources Supported in a Rule

You can add up to 250 sources in an internet access rule. The total number of sources accepted in an access rule includes both pre-configured sources (resources) and sources that you enter directly on an access rule (composite sources).

You can add at most 10 composite sources in an internet access rule.


Add Geolocation Sources on Internet Access Rules

You can select Geolocation sources only on access rules or combine the Geolocation sources with AD Users or AD Groups using the boolean AND operator.

  • Add the Geolocation sources on the access rule, select the AND button, and then choose the AD Users and Groups.

  • Add pre-configured AD Users and Groups on the access rule, select the AND button, and then choose the Geolocation sources.

For information about Geolocation sources, see Geolocation Sources and Internet Access Rules. For information about AD Users and AD Groups, see Manage Users, Groups, and Endpoint Devices .

Before you begin

Procedure

  1. Navigate to Secure > Access Policy.

  2. Navigate to the rules table and choose an existing access rule to edit, or add a new access rule in the Access policy.

  3. Navigate to Specify Access and then navigate to From.

  4. Navigate to Select sources > Geolocations, choose a continent, which selects all countries in the continent, or choose the countries in each continent.


    The Alert Rules Geolocations Source interface.
  5. (Optional) Click + AND and then add the AD Users or AD Groups.

    1. Navigate to Select sources, and then expand Users or Groups.
    2. Expand Users, and then select AD Users or select Any AD Users.

      The Alert Rules from AD User interface.
    3. Expand Groups, and then select AD Groups or select Any AD Groups.

View Events Report

Use the Events report to view, filter, and analyze the security and network activities across your Cisco Secure Access deployment. The Events report is a comprehensive record of event types, statuses, source and destination details, rule information, and reasons for actions. The Events reports helps you troubleshoot issues, verify policy enforcement, and adhere to compliance requirements.

Procedure

  1. Navigate to Monitor > Reports > Events.

  2. Choose a time frame.

    You can view events over the Last 15 minutes, Last 30 minutes, Last 1 hour, Last 4 hours, Last 12 hours, Last 24 hours (default), Last 7 Days, Last 30 Days, or a Custom range.

    The Events Report Updated Event Type interface.

    For firewall events, the report displays both Connect and Disconnect actions. A Connect event indicates the start of a connection, recorded at the TCP handshake, where application details are typically not yet known by the Firewall. A Disconnect event signifies the close of the session, often containing more comprehensive, application-specific information.

    Specifically for Firewall Disconnect events, the Destination section of the Event Details Card includes the Session Bytes Sent and Session Bytes Received fields. These fields show the total amount of data sent and received during the firewall session, providing clear visibility into overall data transfer for each connection. This allows you to quickly assess the volume of data exchanged in a session and supports investigations into unusual or suspicious network activity.

    The Events Report table displays key information for each event. For a detailed understanding of each event type, including their unique characteristics, specific status values, and relevant behaviors, see Event Type Specific Details.

    • Event Type: Category of the event, for example, DNS, Web, Firewall.

    • Status: Action taken (Allowed, Blocked, or Isolated).

    • Event ID: A unique correlation ID generated for each request received by the policy broker, which is propagated downstream to maintain request tracking across network services.

    • The Event ID is linked to the 5-tuple (source IP address, source port, destination IP address, destination port, and protocol) of each flow. This ensures that all the packets in the same flow share the same Event ID. However, if two different flows use the same 5-tuple within a short time, they too could get the same Event ID. This usually happens if a client quickly reuses the same source port for requests to the same destination.

    • Source: Displays the originating identity for the event. This can be:

      • Source IP address (for network-based traffic).

      • User Identity (for authenticated users).

      • Device IP address (for client-based connections, typically representing the public IP address of the client device).

      • Public IP address of the client device (for ZTNA client-based connections). The ZTNA service also logs a specific ZTNA Device ID (a globally unique identifier) for the client, which is distinct from any IP address and helps identify the specific device regardless of its network location.

    • Destination: The IPv4 or IPv6 address of the destination. Supports both compressed and long-form IPv6 address formats. Applicable to Web, Firewall, and decryption requests.

    • Reason Code: Cause of a particular event, for example, policy match, threat detected.

    • Rule Name: The name of the access rule applied to the request. Applicable to DNS, Web, Firewall, IPS, and ZTNA requests.

    • Click a rule name to view the access policy in which the rule is configured. For more information, see Manage the Access Policy.

    • Time: Date and time at which the event occurred.

    • Settings: Gear icon to access table display settings, including options to adjust table density and to show or hide columns in the table.

      Column Behavior:

      • Sorting: Most columns can be sorted in ascending or descending order by clicking their header. Columns that are sortable will display an arrow icon (or similar visual indicator) in their header. Some columns, such as Destination and Reason Code, are currently not sortable to ensure optimal performance.

      • Resizing: Column widths can be adjusted by dragging the dividers between column headers.

      Note

      Note that the resize functionality is active across the entire column header area.

    Note

    If you have a block rule, for example, to block social media, and a user tries to access a blocked site such as facebook.com, the Events report will only display a Web block event. The Firewall does not log an event in this scenario because logging both a Firewall allow and a Web block could be confusing. This is intentional. When the Firewall allows the traffic, but the Secure Web Gateway (SWG) blocks it, only the Web block action is shown in the report.

    As a result, if you are looking to correlate events between the Firewall and Web layers for this type of traffic, you will not see a corresponding Firewall event. This is expected behavior and does not indicate a system issue.

  3. Select which security event types you want to view in the report. By default, all event types are selected to display activity for all event types.

    The Events report supports partial results if one or more event type queries (such as Proxy, Firewall, IP, Intrusion, or Decryption) fail due to an internal error. The report displays all available results from the successful queries, rather than showing an error for the entire request. Any unavailable event types will be clearly indicated in a message displayed on the screen.

    Note
    This feature update ensures continued visibility into available security data, even when certain backend services encounter issues. All retrieved data remains accessible for review and export.
  4. Click the > icon next to an event to view its Event Details Card.

    This card provides a comprehensive, correlated view of the event, grouped by Source, Connection, Security Controls, and Destination. The card also details applied security controls and the final rule action (e.g., blocked or allowed) for the specific event.

    The Events Destination Card interface.
    Note
    Interactive elements within the Event Details Card may display additional information upon hover or click.

    Click on an Event ID within the table to automatically filter the report and display all correlated events.

    The Event Correlation interface.
  5. (Optional) Refine your search using advanced filters. For detailed information on all available filtering and search options, see Filtering and Search Options.

  6. (Optional) To export the events report, click the Export CSV button at the top-right corner of the table. This downloads the current view of the report in CSV format for further analysis or record-keeping. For detailed instructions on exporting report data, see Export Report Data to CSV.


Filter the Report by Firewall Requests

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Choose a time frame to view the report. You can view events from the last 24 hours (default), Yesterday , Last 7 Days, Last 30 Days, or a Custom range.

    The label FW in the Request column indicates a Firewall event.
  3. Select the Firewall option from the dropdown menu at the top right to filter the report for Firewall events. Columns and Filter options update to those that are relevant to Firewall events.


    Firewall option from the dropdown menu at the top right to filter the report for Firewall events. Columns and Filter options update to those that are relevant to Firewall events.
  4. Click the row to view Event Details.

    The Activity Search Report displays Event Details for each search result in a navigation drawer on the right. For more information, see View Activity Search Report Actions.

    Firewall event details include the following fields that are also available as Activity Search report columns. For more information about these fields, see View and Customize the Activity Search Report.

    • Action

    • Time

    • Rule Name

    • Source Geolocation

    • Source

    • Destination IP

    • Categories

    • File Name

    • Protocol

    • Application Protocol

    Firewall event details also include the following fields that do not appear as Activity Search report columns.

    Field Name Description
    Source IP The source IPv4 or IPv6 address. Supports both compressed and long-form IPv6 address formats.
    Source Port The network port number on the source host from which the request originated.
    Destination Port The TCP or UDP port number on the destination host to which the request was sent. This field identifies the specific service or application targeted by the connection (for example, port 80 for HTTP or port 443 for HTTPS).
    Resource/Application The name of the resource or application.
    Session Bytes Sent The total number of bytes sent during the Firewall session. This value is reported at session disconnect and reflects the cumulative amount of data sent from the source to the destination for the event session.
    Session Bytes Received The total number of bytes received during the Firewall session. This value is reported at session disconnect and reflects the cumulative amount of data received from the destination by the source for the event session.
    File Status (Disposition) The file's Cisco AMP disposition:
    • Clean: Indicates that the AMP cloud categorized the file as clean.

    • Malware: Indicates that the AMP cloud categorized the file as malware, or local malware analysis identified malware.

    • Unknown: Indicates that the system queried the AMP cloud, but the AMP cloud has not assigned the file a disposition.

    SHA256 Hash The checksum of the file, if available and the event matched rules with File Type Control or File Inspection enabled.
    File Transfer Direction DOWNLOAD, UPLOAD, or UNKNOWN, if the event matched rules with File Type Control or File Inspection enabled.
    Identified Threat The name of the detected malware.
    Malware Analysis Detected If the event matched rules with File Inspection enabled, this field shows one of the following values as a result of file analysis by Cisco Secure Malware Analytics. For more information, see Enable File Analysis by Cisco Secure Malware Analytics.
    • UNKNOWN

    • NOT ANALYZED

    • ANALYSIS COMPLETE NO VIRUS

    • ANALYSIS FAILED

    • ANALYSIS COMPLETE MALWARE DETECTED

    Threat Severity Score The threat score most recently associated with this file. This is a value from 0 to 100.
    File Type Identifiers The type of file. For example, PDF or MSEXE.
    File Size (bytes) The size of the file in bytes, if the event matched rules with File Type Control or File Inspection enabled.
    Archive File Name The name of the archive file involved with the activity, if the event matched rules with File Type Control or File Inspection enabled.
    Archive Extraction Depth The level (if any) at which the file was nested in an archive file.
    Archive SHA-256 Hash The checksum of the archive file, if the event matched rules with File Type Control or File Inspection enabled.

Filter the Report by Web Requests

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Choose a time frame to view the report. You can view the results for the last 24 hours (default), Yesterday, Last 7 Days, Last 30 Days, or a Custom range.

  3. From the drop-down menu at the top-right of the table, choose the Web option to filter the report for web events.


    Yesterday, Last 7 Days, Last 30 Days, or a Custom range. From the drop-down menu at the top-right of the table, choose the Web option to filter the report for web events.
  4. Click the ellipsis (...) and choose the View Full Details option to view web event details in the side panel.


    The View Full Details interface.
  5. The event details are displayed in the side panel. For more information, see View Activity Search Report Actions.


    The Activity Search interface.

    Web event details include the following fields that are also available as Activity Search report columns. For more information about these fields, see Customize the Activity Search Report.

    • Action

    • Time

    • Rule Name

    • Source Geolocation

    • Source

    • Rule Identity

    • Internal IP Address

    • External IP Address

    • Destination

    • Categories

    • Resource/Application

    • Application Category

    • Content Type

    • Request Method

    • Referrer

    • Status Code

    Web event details also include the following fields that do not appear as Activity Search report columns.

    Field Name Description
    Hostname Fully Qualified Domain Name (FQDN) of the machine or container from which the event originated.
    File Action (Remote Browser Isolation) Action taken on a file, such as Viewed, Original File Downloaded, Sanitized PDF File Downloaded.
    Total Size, in Bytes The number of bytes sent from the client for all the requests, including HTTP headers, for example, 234.
    User Agent The user agent string as captured by the proxy, for example, Mozilla 5.0 (X11; Linux x86_64; rv:12.0) Gecko 20100101 Firefox 21.0.
    SHA256 Hash This represents the SHA-256 hash of the response body.
    Egress IP Address The IP address is used by the proxy to communicate with the origin server. Dot notation is used for IPv4 and RFC 5952 is used for IPv6 , for example, 1.2.3.4, 2001:db8::1.
    Egress Data Center The data center that processed the request.
    YouTube Channels The YouTube channel name, such as @Cisco in the Cisco YouTube channel (https://www.youtube.com/@Cisco).
    YouTube Categories The set of YouTube categories, such as Education, Entertainment, Animation.