Describes Geolocation Sources and Internet Access Rules in Cisco Secure Access. Geolocation sources enable organizations to monitor and control the traffic from end users in specific geographic regions.
Geolocation sources enable organizations to monitor and control the traffic from end users in specific geographic regions. The Geolocation source component is available on the internet and private access rules in the Access policy.
The Geolocation source component is a list of continents and the countries in these continents where Secure Access can manage the network traffic sent from these geographic locations.
DNS resolution does not is not supported in source based geolocation policies. The geolocation source of a DNS lookup is not an indicator of where content is being delivered and as such source based geolocation checks and matches are enforced at other enforcement layers as part of unified policy based on your policy configuration.
You can select the Geolocation sources with the AD Users or AD Groups or only add the Geolocations on the access rules. Administrators of the organization are responsible for provisioning the AD Users and AD Groups. For more information, see Provision Users, Groups, and Endpoint Devices from Active Directory.
When you select the Geolocations on an access rule, Secure Access shows the AND option and the AD Users or AD Groups. When you select the AD Users and AD Groups for the source on an access rule, Secure Access shows the AND option and the list of continents and countries. Secure Access combines the selected AD Users or AD Groups and the geolocations with the boolean AND operator. You can only combine the Geolocation source component with the AD Users or AD Groups.
Monitoring Internet Traffic from Geolocations
Set up the attributes and conditions on the access rules in the Access policy to monitor and protect the network traffic from the end users located in specific geographic regions. To enforce the security controls on a rule, the network traffic must match the selected sources.
Secure Internet Access (SIA) in Cisco Secure Access, policy enforcement passes through Zero Trust Access (ZTA) or through the firewall/secure gateway (SGW) depending on the traffic type and configuration; traffic is then tunneled to and inspected by the firewall.
For internet access rules, choose to allow or block all traffic from the geolocations or all traffic from the selected AD Users or AD Groups located in the countries and continents.
-
The SWG detects and enforces the web traffic (TCP/80, TCP/443) sent from the end users located in the selected continents and countries.
-
The Secure Access cloud-delivered firewall detects and enforces the network traffic on non-standard web ports sent from the end users located in the selected continents and countries.
-
For internet traffic on Zero Trust Access connections, the Secure Acces cloud-delivered firewall and Secure Web Gateway detects and enforces the traffic.
You can view the events and logs recorded by Secure Access for the traffic sent from the end users in the organization in certain geolocations. Secure Access reports on the traffic on standard web ports and non-web ports. For more information, see: