Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Application Lists

Want to summarize with AI?

Log in

Describes Manage Application Lists in Cisco Secure Access. Secure Access organizes application-based resources into categories based on the type of process or service provided, for example: shopping, education, or human resources.


Secure Access organizes application-based resources into categories based on the type of process or service provided, for example: shopping, education, or human resources. You can add applications or application categories to an application list. Once saved, application lists are available to choose as destinations in your internet access rules.

Use application lists to simplify destination management and apply access rules consistently. However, you can also choose individual applications and entire application categories directly in internet access rules.

For some applications, you can allow access to the application but block activities such as uploads, downloads, or posting. For more information and a list of applications that support these blocks, see Advanced Application Controls.

When a new application is added to a category, Secure Access automatically adds that application to all configuration settings that include that entire category. For each application list, the new application will use the same default action as that applies to the Application category as a whole.

Note: It is not possible to search for an application with fewer than three letters in its name—for example, "QQ" or "YY". These applications must be manually picked from the tree under their respective categories or wildcarded in search—for example, "QQ*". This behavior is by design.

To prevent decryption of traffic to specified applications, see Important Information About Do Not Decrypt Lists.


Add an Application List

Cisco Secure Access application lists organize application-based destinations into categories. Categories are organized by the type of processes or services provided. Application lists can also include application protocols, which transport the traffic from your organization's sources to internet destinations. An application list may include a single application protocol or a list of application protocols.

To control the traffic to applications, add application categories and application protocols to an Application list. Then, select the application list in an internet rule. You can reuse application lists in multiple internet rules. For information about internet rules, see Components for Internet Access Rules.

Add an application list with applications and application protocols.

Note

When a new application is added to a category, Secure Access automatically adds that application to all configuration settings that include that entire category. For each application list, the new application will use the same default action as that applies to the Application category as a whole.

Before you begin

Procedure

  1. Navigate to Resources > Internet and SaaS Resources > Application Lists.


    Accessing Application Lists tab in the Internet and Saas Resources page
  2. Click Add application list.


    The Add New Applist interface.

  3. For List name, enter a descriptive name for the application list.


    Add Application List section with field to enter a name for the application list
  4. Select applications and application protocols for the application list.

    1. Search for applications and then select applications, or expand each application category and choose the applications within the category. You can also select a category checkbox to include the entire category, or use Select All to select the full catalog.

      Note
      When you select only a few apps within a category, the category is marked with a dash. When you select an entire category, it is marked with a check. You can select the category row to view its applications. For information about the available categories, see Application Categories.
      Applications section with options to select applications within each application category
    2. Select all application protocols or choose the application protocols to add to the application list.

      Section for adding application protocols to an application list
    Note
    Click Internet Applications to return to the category level. Closing the drawer retains the page draft, instead of saving or cancelling the changes you have made. Use the page level Save button to save your changes.
  5. Click Save.


    Viewing available applications in Secure Access

  6. To view an application list, click the three dots on the right side of your selected list and select View details.


    The View App Details interface.

What to do next

After you add the application list, you can select the application list as a destination in an internet rule. For more information, see Add an Internet Access Rule.

For some applications, you can allow access to the application but block activities such as uploads, downloads, or posting. For more information and a list of applications that support these blocks, see Advanced Application Controls


Application Categories

The system is capable of discovering thousands of apps; these are divided into categories for ease of reference. Categorization of discoverable apps is conducted by a team of researchers, and based on similarities among apps as well as a number of other quantitative application feature sets.

Category Descriptions

Discovered apps are assigned to the following categories:

  • Ad Publishing—Applications that enable publishers and ad networks to manage ad serving and trafficking.
  • Anonymizer—Services that provide an anonymous proxy tool that attempts to make activity on the Internet untraceable.
  • Application Development and Testing—Applications suited for application development and testing cycles, or for building integration applications in the cloud and within the enterprise.
  • Application Protocols —Application layer protocols that govern how data is transmitted and received over a network, enabling different services such as web browsing, email, file transfer, and online transactions as well as allowing software applications to communicate with each other. These include SSH, FTP, SMTP and other such applications.
  • Backup and Recovery—Applications for backup and recovery of file systems and raw data stores on servers and desktop systems.
  • Business Intelligence—Applications for analytics such as dashboards, reporting systems, scenario modeling, and data analysis.
  • Cloud Broker—Applications that manage the use, performance, and delivery of cloud services and negotiate relationships between cloud providers and cloud consumers.
  • Cloud Carrier—Intermediary that provides connectivity and transport of cloud services between cloud consumers and cloud providers through a network, telecommunication, and other access devices.
  • Cloud Service Provider—Based on NIST definition of a cloud service, which we believe is being (slowly) adopted as the industry standard. The NIST definition includes the following criteria: on-demand self-service, rapid elasticity, and measured service. CASI additionally adds vendor intent to provide computing-related services (Compute, Network, Storage and/or Software Application). If in doubt whether web or cloud, we will be conservative and assume cloud until we can prove otherwise.
  • Cloud Storage—Applications that offer massively scalable storage capacity that can be used for applications, and file storage.
  • Collaboration—Applications that enhance communication and collaboration in workgroups, within enterprises, and across enterprises.
  • Compute—Fundamental computing resources for running cloud-based systems that can be dynamically provisioned and configured as needed.
  • Content Delivery Network (CDN)—Applications that store content and files to improve the performance and cost of delivering content for web-based systems by offering a large distributed system of servers deployed in multiple data centers across the Internet.
  • Content Management—Applications for managing the production of and access to content, enforcing document production workflows, and providing workspaces for groups or enterprises to find and access documents.
  • Customer Relationship Management (CRM)—Applications that manage interactions with current and future customers, including organization and automation across sales, marketing, and customer service functions.
  • Database Management—Applications offering scalable data management solutions for structured or unstructured data, relational database solutions or scalable non-SQL datastores.
  • E-Commerce—Applications that facilitate the buying and selling of products or services.
  • Education—Applications that provide educational or training courses, general learning opportunities or specific employee training independent of their location.
  • Enterprise Resource Planning (ERP)—Applications that manage operations or management of a business; which can include internal and external resources, including tangible assets, financial resources, materials, and human resources.
  • Financial Services—Applications for managing financial processes and information.
  • Games—Online and mobile games.
  • Generative AI—Applications that enable access to large language models (LLM) and artificial intelligence (AI) tools.
  • Healthcare—Applications that provide access to health, medical, and personal fitness systems.
  • Hosting Services—Applications that enable corporate or individual websites or other content to be accessible over the internet.
  • Human Resources—Applications for managing human resources and HR functions.
  • IT Service Management—Applications that support specific IT functions to plan, deliver, operate and control IT services.
  • Legal—Applications that provide access to legal documents and public records and support legal content.
  • Marketing & Sales—Applications that are specifically designed for marketing and sales functions.
  • Media—Applications that host or stream media as a service.
  • Office Productivity—Applications for producing information and other standard office-oriented tasks such as documentation, presentations, project management, and so on.
  • Others—Used for those services where no existing categorization would fit.
  • P2P—Peer to Peer torrents like apps and protocols.
  • Search—Web or app-based search.
  • Security—Applications that support security activities to ensure adherence to regulatory compliance rules and protect information, data applications, and infrastructure.
  • Service Management—Applications that support general operational activities outside of the IT function.
  • Shopping—Web or app-based basic online shopping.
  • Social Networking—Applications that establish and maintain a connection among users that are tied in one or more specific types of interdependency.
  • Software Repository—Software repositories.
  • Support—Applications that provide access to customer support services.
  • Travel—Applications that provide travel management services.
  • Web Content—Mostly app-based services that provide content. It can be through a login or paid portal.

For some applications, you can allow access to the application but block activities such as uploads, downloads, or posting. For more information and a list of applications that support these blocks, see Advanced Application Controls.


Edit an Application List

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Navigate to Resources > Internet and SaaS Resources > Application Lists.


    The App List interface.

  2. Select the three dots Actions menu on the right side of your chosen application list.

  3. Click Edit.


    The Edit Applist interface.

  4. Perform any of the following actions:

    • Edit the list name.
    • Search or filter the current applications.
    • Remove applications.
    • Select Add Applications.


  5. Select Save to save your changes to the application list.

    (Optional) Select Cancel to discard your changes.
    (Optional Select Delete to delete the selected application list.

Delete an Application List

After you create an application list, you can delete the list from Secure Access.

Before you begin

Procedure

  1. Navigate to Resources > Internet and SaaS Resources > Application Lists.


    The App List interface.

  2. Select the three dots Actions menu on the right side of your chosen application list.

  3. Click Delete.


    The Delete Applist interface.

    Note
    If the list is used in any rules, you will see a list of those rules. You cannot delete the list if it is used in rules. Delete the list from the rules or delete the rules, then try again.