Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Internet Security

Want to summarize with AI?

Log in

Describes Manage Internet Security in Cisco Secure Access. You can manage the Cisco Secure Access Internet Security settings in Secure Access to protect the user devices in your organization.


You can manage the Cisco Secure Access Internet Security settings in Secure Access to protect the user devices in your organization.

Note
User devices must have the Cisco Secure Client deployed with the Umbrella Roaming Security module or deploy a PAC file for the browsers in the environment.

Download Cisco Secure Client or Copy Secure Access PAC File URL

To deploy the Secure Access Internet Security on user devices, first download and install the software package for the Cisco Secure Client or copy the URL for the Secure Access PAC file from Secure Access.

You can also install custom PAC files in your environment. For more information about deploying PAC files, see Manage PAC Files.

Add Bypass Domains and Set Up Internet Security

Once you install and deploy the Cisco Secure Client or the Secure Access or custom PAC files in the environment, add bypass domains in Secure Access. Then, configure DNS and web security settings for the user devices in the organization.

Next Steps


Set Up Internet Security on User Devices

Before you add DNS and web security in Cisco Secure Access for end users, deploy the Cisco Secure Client or the Secure Access or custom PAC files in your environment. User devices with the Cisco Secure Client installed must also deploy the Umbrella Roaming Security module.

This guide describes the steps to download the software package for the Cisco Secure Client or copy the URL for the Secure Access PAC file to your environment.

To complete the setup, we recommend that you provision users and groups from the organization in Secure Access. For more information, see Manage User Directories and Device Management.

Prerequisites

Visibility of User Identities in Policy Rules


Procedure for Setting Up Internet Security on User Devices

Download the Secure Access OrgInfo.json file for the organization or copy the Secure Access PAC file URL. Use the deployment configuration files to set up the Cisco Secure Client or browsers on the user devices.

For more information about deploying PAC files with Secure Access, see Manage PAC Files.


Download the OrgInfo.json File

You can deploy various modules with the Cisco Secure Client. The Cisco Secure Client may require a certain profile present to install a module successfully.

The Cisco Secure Client Umbrella Roaming Security module (DNS-layer and Web security) requires the Secure Access OrgInfo.json file. The Secure Access OrgInfo.json file associates a Cisco Secure Client deployment with the Umbrella Roaming Security module to a Secure Access user and organization. Once the module is deployed on the Cisco Secure Client, Secure Access applies the organization's configured policy rules to the device. The device's traffic events are visible in the Activity Search report.

If you use another OrgInfo.json file from a different organization in Secure Access to install the Cisco Secure Client Umbrella module, the roaming device is managed by that instance of Secure Access instead.

To deploy the Cisco Secure Client with the Umbrella Roaming Security module on a user device, download the OrgInfo.json file from Secure Access to the device.

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. For Cisco Secure Client, click Download profile. Download the Secure Access OrgInfo.json file to the user devices where you have deployed the Cisco Secure Client.

    Download Secure Access OrgInfo.json file to deploy Internet Security module

Copy the PAC File URL

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. For Secure Access PAC file, click Copy to get the Secure Access PAC file URL. For more information about the Secure Access PAC file and deploying custom PAC files, see Manage PAC Files.


    Copy option to obtain Secure Access PAC file URL

Manage Internet Security Bypass

You can configure Internet Security Bypass for web requests to destinations from end users in your organization. In Secure Access, add IP addresses, CIDR blocks, or domains for Internet Security Bypass. For more information, see Add Destinations for Internet Security Bypass.

Secure Access supports Internet Security Bypass for user devices with the Cisco Secure Client (formerly known as AnyConnect) and Umbrella Roaming Security module, or user devices with browsers that are configured with the Secure Access PAC file or a custom PAC file.

About Internet Security Bypass

Add destinations for Internet Security Bypass in Secure Access to either bypass the Secure Access DNS resolvers and Secure Web Gateway, or bypass the Secure Web Gateway only.

To bypass the Secure Access DNS resolvers and Secure Web Gateway, add the domains that are local to your organization or domains that should route to your organization's DNS resolvers only and not route to the Secure Access DNS servers. Your local DNS servers will resolve the DNS requests that are sent from end users in the organization. DNS requests for the destinations do not route to the Secure Access DNS servers and Secure Web Gateway.

To bypass the Secure Access Secure Web Gateway only, add destinations for trusted applications, applications that are not reachable through web proxies, or applications that end users can access only from specific public IP addresses. If you bypass the Secure Web Gateway only, the DNS requests from end users will be resolved by the Secure Access DNS servers. For more information about Reserved IP, see Secure Access NAT as a Service.


Add Destinations for Internet Security Bypass

Add destinations in Secure Access to bypass internet security. Traffic for destinations that are added in Secure Access bypass the Secure Access DNS resolvers and Secure Web Gateway or the Secure Web Gateway only.

If you configure destinations to bypass the SWG and Secure Access DNS servers, the DNS requests are sent to the organization's local DNS resolvers.

If you configure destinations to bypass the SWG only, the DNS requests are sent to the Secure Access DNS servers and directly to the Internet.

Before you begin

  • Full Admin user role. For more information, see Manage Accounts.

  • User devices must have the Cisco Secure Client and Umbrella Roaming Security module or deploy the Secure Access PAC file or a custom PAC file on the browsers in the environment.

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security , and then click Add Destination.

    Internet security bypass section with option to add destination to bypass Secure Access
  2. Choose Bypass Secure Access to bypass the Secure Access SWG and DNS servers.

    Add the domains that are local to your organization or domains that should route to your organization's DNS resolvers and not route to the Secure Access DNS servers.

    DNS requests for the destination will be resolved by the organization's local DNS servers.

    Add Destination page with option to bypass Secure Access SWG and DNS Servers
    1. For Destination, enter a domain name.
    2. (Optional) For Description, enter text that describes why the domain will bypass the Secure Web Gateway and DNS servers.
    3. For Applies To, select the Secure Access Sites for all devices that should bypass Secure Access when requesting the domain. If you happen to select multiple sites and need to remove them from the configuration prior to saving, the "x" icon inside the drop-down bar of this step allows you remove all of the selected sites.
  3. Choose Bypass web proxy only to bypass the Secure Web Gateway (SWG) only.

    Add destinations for trusted applications, applications that are not reachable through web proxies, or applications that end users can access only from specific public IP addresses.

    Add Destination page with option to bypass Secure Web Gateway (SWG) only
    1. For Destination, enter a domain name.
    2. (Optional) For Description, enter text that describes why the domain will bypass the Secure Web Gateway.
  4. Click Save.


View Destinations for Internet Security Bypass

After you add the destinations in Secure Access to bypass internet security, you can view the details about the destinations.

Before you begin

  • A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. View the domains that you added to the bypass internet security list in Secure Access.

    List of domains in Secure Access added for bypassing Internet Security
    • Domain Name—The name of the domain.
    • Description—The text that describes the domain.
    • Intent—The type of domain, for example: Bypass Secure Access.
    • Applies to—The name of a Site or the location of the Secure Access Virtual Appliance (VA) where the domain is bypassed.
    • Actions—The actions taken to manage the destination in Secure Access.

Edit Destination for Internet Security Bypass

After you add a destination in Secure Access to bypass internet security, you can edit the destination. You can modify the internet security information for destinations that bypass the Secure Access Secure Web Gateway (SWG) and Secure Access DNS resolvers, or only bypass the Secure Web Gateway.

Before you begin

  • Full Admin user role. For more information, see Manage Accounts.

  • User devices must have the Cisco Secure Client and Umbrella Roaming Security module or deploy the Secure Access PAC file or a custom PAC file on the browsers in the environment.

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. Navigate to Internet security bypass, navigate to a destination in the internet security bypass table, and then click the ellipsis (...).

  3. Click Edit to modify the bypass information for the destination.

    Edit option to modify bypass information for destination
  4. Choose Bypass Secure Access to bypass the Secure Access Secure Web Gateway and Secure Access DNS servers.

    Note
    DNS requests will be resolved by the organization's local DNS servers.
    Add Destination page with option to bypass Secure Access SWG and DNS Servers
    1. For Destination, enter a domain name.
    2. (Optional) For Description, enter text that describes why the domain will bypass the Secure Web Gateway and Secure Access DNS servers.
    3. For Applies To, select the Secure Access sites for all web requests on the devices that should bypass Secure Access. If you need to remove multiple sites, the "x" icon inside the drop-down bar of this step allows you remove all of the selected sites.
  5. Choose Bypass web proxy only to bypass the Secure Web Gateway (SWG) only.

    Add Destination page with option to bypass Secure Web Gateway (SWG) only
    1. For Destination, enter a domain name.
    2. For Description (optional), enter text that describes why the domain will bypass the Secure Web Gateway.
  6. Click Save.


Delete Destinations for Internet Security Bypass

After you add a destination to bypass the Secure Access internet security, you can remove the destination. As a result of removing the destination, the DNS requests for the destination will resolve to the Secure Access DNS servers.

Before you begin

Procedure

  1. Navigate to Connect > End User Connectivity > Internet Security.

  2. Navigate to Internet security bypass, navigate to a destination in the internet security bypass table, and then click the ellipsis (...).

  3. Click Delete.

    Delete option to delete destination for Internet Security bypass
  4. Click Delete to confirm the removal of the destination.


Configure Cisco Secure Client Settings

You can configure the Cisco Secure Access Internet Security in Secure Access for end users.

Note
User devices must have the Cisco Secure Client deployed with the Umbrella Roaming Security module or deploy a PAC file for the browsers in the environment.

This guide describes the steps to enable the DNS and web security settings and advanced internet security settings in Secure Access for the end user devices in the organization.


Procedure

Configure the Cisco Secure Client internet security settings. The advanced internet settings contains several fields that provide additional control over user authentication, traffic bypass, and VPN compatibility.

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Navigate to Connect > End User Connectivity.

  2. On the End User Connectivity page, click the Internet Security tab.

    The Cisco Secure Client interface.
  3. Select a tab and then options on that tab:


Configure Security Settings


Configure DNS and Web Security

Configure DNS and web security settings for the Cisco Secure Client.

Note
The Secure Access DNS-layer security is always enabled on the Cisco Secure Client.

The Cisco Secure Client with the Umbrella Roaming Security module steers web traffic on ports 80/443 to the Secure Web Gateway (SWG). All web traffic is evaluated against the organization's policy and Internet Access rules when a VPN connection is not established.

Note
You can override this option on individual roaming devices.

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

Enable the Web Security (port 80/443 traffic only) toggle button.

The End User DNS Web Security interface.

Configure Advanced Security Settings


Use Active Directory for Access Policy

Enable the Cisco Secure Client to synchronize users and groups identities with the Secure Access Active Directory (AD) Connector. Secure Access applies Access rules for user identities, which are associated with devices that have deployed the Cisco Secure Client.

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

Enable the Use Active Directory for Access Policy toggle button.

The End User Identity Enable interface.

Third Party VPN Compatibility

Improve compatibility for third-party VPN clients on Windows 10 only, or if the local DNS is not resolving resources.

The Cisco Secure Client with the Umbrella Roaming Security module works with most VPN software. However, the Cisco Secure Client with the Umbrella Roaming Security module and other VPN profiles may not resolve local DNS queries correctly on a VPN connection with Windows 10. The local LAN may bind above the VPN, failing to resolve local DNS requests over the tunnel. Select this setting to apply the legacy binding order behavior.

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

Enable the Third Party VPN Compatibility toggle button.

The Third Party VPN Compat interface.

DNS Protection

Choose one of the following options to provide DNS protection:

  • Full Protection: Provides protection for single stack IPv4 network, dual stack IPv4 and IPv6 network, and single stack IPv6 network.

  • Limited Protection:Provides protection for single stack IPv4 network, and dual stack IPv4 and IPv6 network.

  • Legacy Protection:Provides protection for single stack IPv4 network only.


    The New UI SSE DNS Protection interface.

The previous dashboard configuration for IPv6 DNS protection allowed enabling protection over IPv6.


The Ipv6 Toggle Button interface.

This earlier configuration is now replaced with the new DNS protection options described above.

  • If the earlier IPv6 DNS protection configuration was disabled, the new configuration defaults toLegacy Protection.

  • If the earlier IPv6 DNS protectionconfiguration was enabled, the new configuration defaults to Limited Protection.

Note
For optimal security, we recommend using the Full Protection configuration, available in Cisco Secure Client 5.1.10.233 (MR 10) or later.

Alternate Resolver IPs

Select an alternate resolver to handle DNS queries within a specific network region. Ensure that the latest version of Client is installed on your remote device.

Note

Minimum client platform version requirement for:

Android: Cisco Secure Client 5.1.8 or later
iOS: Cisco Secure Client 1.7.3 or later
Windows and macOS: Cisco Secure Client 5.1.9 or later
The Alternate Resolver interface.

For remote devices running ChromeOS, ensure that you deploy the Cisco Security for Chromebook client 2.2.0 or later in the Google Admin console after setting the Alternate DNS resolver IPs. For more information, see Deploy the Cisco Security for Chromebooks Client.


DNS Backoff Settings

Bypass DNS traffic from Secure Access for the following contexts:

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Select Backoff behind Virtual appliance. When enabled and the Cisco Secure Client detects a Secure Access Virtual Appliance (VA), DNS traffic goes through the local network instead of redirecting to Secure Access.

  2. Select AnyConnect Trusted Network Detection (TND) to disable DNS traffic forwarding from an endpoint to Secure Access if the network is trusted. This setting requires that you have the Trusted Network Detection (TND) setting enabled in the AnyConnect VPN profile for the user devices.

  3. Select AnyConnect VPN Detection to disable DNS traffic forwarding to Umbrella when endpoint detects that a full-tunnel VPN session is active. This is specific to Cisco VPNs. Currently this feature is not compatible with Cisco Secure Access remote access VPN. However, this feature is compatible with other Cisco products that support full-tunnel VPN, such as the Cisco Adaptive Security Appliance (ASA).

  4. Select DNS protected network to disable DNS traffic forwarding while on a network protected by Secure Access. Relies on the protection of the network. To trigger this setting, you must register the public network in Secure Access and add the network to a rule that has a higher priority than the roaming devices. In addition, the local DNS server egress network must have the same network registration as straight out from the computer to 208.67.222.222.

  5. Select Customer trusted network to disable DNS redirects to Secure Access if the domain name added to the Subdomain field is found on the network and resolves to an RFC-1918 local IP address.

    • For Subdomain—enter a domain that Secure Access uses to query the local DNS server.

      Note
      You must enable Customer trusted network to add the subdomain.

      The DNS Backoff Settings interface.

Secure Web Gateway Backoff Settings

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Select Follow compatible DNS backoff settings. Enable this option to allow the Cisco Secure Client with the Umbrella Roaming Security module to follow the DNS backoff behavior for any of these DNS backoff settings: Customer trusted network or AnyConnect Trusted Network Detection (TND).


    The SWG Backoff Settings interface.
  2. Select Follow independent backoff settings (Advanced).

    Note
    The AnyConnect Trusted Network Detection (TND) and Your trusted network options are only supported with user devices that have version 5.1.3.62 or higher of the Cisco Secure Client with the Umbrella Roaming Security module deployed. For information about downloading the Cisco Secure Client software packages, see Cisco Secure Client Version 5.1.3.62 .

    Bypass Web traffic from Secure Access for the following contexts:

    • Select AnyConnect Trusted Network Detection (TND) to disable web traffic forwarding from an endpoint to Secure Access if the network is trusted. This setting requires that you have the Trusted Network Detection (TND) setting enabled in the AnyConnect virutal private network (VPN) profile for the user devices.

    • Select AnyConnect VPN Detection to disable web traffic forwarding to Umbrella when the endpoint detects an active, full-tunnel VPN session. This is specific to VPNs within the Cisco VPN infrastructure with certificates and configurations issued and validated by Cisco VPN servers.

    • Select Your Trusted network to enable endpoints to detect an organization's trusted network, which is identified by the Trusted server and Trusted server SHA256 hash fields. When the endpoint detects trusted networks, traffic from the endpoints bypass Secure Access and the endpoints rely on the network protections.

      • For Trusted server, enter the URL (<domain>:<port>) of the trusted network server, which hosts the trusted server certificate. This option disables redirects to Secure Access when on the trusted network identified by the trusted network server.

      • For Trusted server SHA256 hash, enter the SHA256 hash for the trusted network server's certificate. The ID of the trusted network server's certificate must match the configured SHA256 hash.


    The SWG Backoff Settings Advanced interface.