Limitations and range limits related to the maximum number of certain components and the amount of time that your data is retained by Secure Access.
Cisco Secure Access sets limitations by component and defines the amount of time that your data is available on our system. These general limitations affect how you configure, deploy, and interact with Secure Access.
Access Policy
For information about the Access policy, see Manage the Access Policy.
-
You can add a maximum of 10,000 access rules in the Access policy.
-
You can add a maximum of 250 sources on each access rule in the Access policy.
The total number of sources accepted in an access rule includes both pre-configured sources (resources) and sources that you enter directly on an access rule (composite sources).
You can add at most 10 composite sources in an access rule.
-
You can add a maximum of 5000 destinations on each access rule in the Access policy.
The total number of destinations accepted on an access rule includes both pre-configured destinations (resources) and destinations that you enter directly on an access rule (composite destinations).
You can add at most 10 composite destinations in an access rule.
Zero Trust Access
The components of Zero Trust Access (ZTA) support the following limits:
-
You can create a maximum of 100 ZTA profiles per organization.
-
You can add a maximum of 100,000 steering destinations per ZTA profile, and 1 million steering destinations per organization.
For an in-depth list of limitations specific to Zero trust access, see Zero Trust Access Requirements and Limitations.
Cisco Secure Client
-
Secure Access checks the Cisco Secure Client Zero Trust Access (ZTA) posture profile every 5 minutes.
-
Secure Access applies private application configuration changes to the Cisco Secure Client every 10 minutes. However, on iOS this is every 4 hours.
-
Secure Client version 5.1.13 and later supports both IPv4 and IPv6.
Data Retention
-
DNS logs—Summary data (such as queries per identity or domain) is available for one calendar year.
-
DNS, Web proxy, firewall logs—Data retained for 90 days.