Cisco Secure Access Help

PDF

Cisco Secure Access Help

Limitations and range limits

Want to summarize with AI?

Log in

Limitations and range limits related to the maximum number of certain components and the amount of time that your data is retained by Secure Access.


Cisco Secure Access sets limitations by component and defines the amount of time that your data is available on our system. These general limitations affect how you configure, deploy, and interact with Secure Access.

Access Policy

For information about the Access policy, see Manage the Access Policy.

  • You can add a maximum of 10,000 access rules in the Access policy.

  • You can add a maximum of 250 sources on each access rule in the Access policy.

    The total number of sources accepted in an access rule includes both pre-configured sources (resources) and sources that you enter directly on an access rule (composite sources).

    You can add at most 10 composite sources in an access rule.

  • You can add a maximum of 5000 destinations on each access rule in the Access policy.

    The total number of destinations accepted on an access rule includes both pre-configured destinations (resources) and destinations that you enter directly on an access rule (composite destinations).

    You can add at most 10 composite destinations in an access rule.

Zero Trust Access

The components of Zero Trust Access (ZTA) support the following limits:

  • You can create a maximum of 100 ZTA profiles per organization.

  • You can add a maximum of 100,000 steering destinations per ZTA profile, and 1 million steering destinations per organization.

For an in-depth list of limitations specific to Zero trust access, see Zero Trust Access Requirements and Limitations.

Cisco Secure Client

  • Secure Access checks the Cisco Secure Client Zero Trust Access (ZTA) posture profile every 5 minutes.

  • Secure Access applies private application configuration changes to the Cisco Secure Client every 10 minutes. However, on iOS this is every 4 hours.

  • Secure Client version 5.1.13 and later supports both IPv4 and IPv6.

Data Retention

  • DNS logs—Summary data (such as queries per identity or domain) is available for one calendar year.

  • DNS, Web proxy, firewall logs—Data retained for 90 days.


Destinations for Client-Based Zero Trust Traffic

Secure Access limits the number of Zero Trust traffic steering rules added in an organization for end-user connectivity. In Secure Access, the Zero Trust traffic steering rules appear on Connect > End User Connectivity > Zero Trust. For more information, see Traffic Steering for Zero Trust Access Client-Based Connections.

These limits include:

  • Destinations that are automatically added to the Zero Trust traffic steering page. When an organization enables client-based zero trust connections, Secure Access adds a traffic steering rule for each "Internally reachable address" configured for Private Resources.

  • Wildcard exceptions to the private resource addresses, which you configure on the Zero Trust traffic steering page.

  • Any other destinations configured directly on the Zero Trust traffic steering page, which is not recommended.

To reduce the number of rules, consider using wildcards. For more information, see Using Wildcards to Configure Traffic Steering for Private Destinations.


Domain Names

You can configure various components in Secure Access with domain names, for example:

Note
A domain name can have a maximum of 253 characters. A subsection or label in the domain name must have at least two and no more than 63 characters. Domain names may contain alphanumeric characters and the hyphen.

File Inspection and File Analysis

See Manage File Inspection and File Analysis for details about supported files and limitations for file inspection and analysis performed by Cisco Advanced Malware Protection (AMP), Secure Access antivirus scanner, and Cisco Secure Malware Analytics.


Internet Protocol Versions

Secure Access supports various IP versions to accommodate different network environments. The dashboard and wizards guide you in selecting the appropriate protocol based on your requirements.

Single Stack versus Dual Stack

The terms "single stack" and "dual stack" refer to how a client or network device is configured:

  • Single stack: A configuration that uses only one IP version (IPv4 or IPv6) for communication.

  • Dual stack: A configuration that supports both IPv4 and IPv6.

Secure Access receives traffic from any client configured with single stack IPv4, dual stack, or single stack IPv6 (via Remote Access VPN (RAVPN) or IPsec tunnels).

Upstream connectivity and fallback: For upstream connectivity to web servers and internet-hosted resources, Secure Access connects using either IPv4 or IPv6. In any single transaction, only one IP version is used.

Dual stack configurations provide backward compatibility. If a session transaction cannot be completed using IPv6, the system falls back to IPv4. Clients configured exclusively for single stack IPv6 cannot perform this fallback. In these scenarios, the inability to connect to an IPv4-only resource is a limitation of the client configuration rather than the Secure Access service.

See the table below for what type of internet protocol is supported. Note that this table is not all-encompassing.

Table 1. Internet Protocol support by Function
Function in Secure Access IPv4 IPv6

Remote Access VPN

Dual stack IPv6 traffic forwarding

IPsec tunnel (Network Tunnel Group)

Dual stack IPv6 traffic forwarding

Remote Security Module

Dual stack Dual stack

Secure Client Zero Trust Access (ZTA) - Private Access

Dual stack Dual stack (Resource only)
Note
You can only configure IPv6 as a private resource, not a private destination.

Secure Client Zero Trust Access (ZTA) - Internet Access

Single stack Not supported

DNS

Dual stack Supported

IP Address Restrictions

The following networks/addresses are not valid for use as:

  • Client IP pools

  • System IP pools

  • DNS and DDNS servers

  • RADIUS servers

  • Private resources

Using these addresses in the specified contexts can cause conflicts, routing issues, or operational failures.

Table 2. Restricted Networks/Addresses:
Network/Address Description
0.0.0.0/8 Addresses in this block identify source hosts on 'this' network
127.0.0.0/8 Loopback
127.0.53.53 Name collision occurrence
169.254.0.0/16 Link local
192.0.0.0/24 IETF protocol assignments
192.0.2.0/24 TEST-NET-1 (Documentation and examples)
198.18.0.0/15 Network interconnect device benchmark testing
198.51.100.0/24 TEST-NET-2 (Documentation and examples)
203.0.113.0/24 TEST-NET-3 (Documentation and examples)
224.0.0.0/4 Multicast
240.0.0.0/4 Reserved for future use
255.255.255.255/32 Limited broadcast

For more information, refer to the following documentation topics:


Other Components

Feature Limit Description
Block Page Bypass You cannot use the Block Page Bypass feature with a redirected block page. If configured, Secure Access uses the default appearance of the block page.
Bypass Domains No more than 2000 bypass domains may be added to Secure Access. The number of bypass domains can be increased upon request.
Customer CA Signed Root Certificate Six certificates per organization.
Destination Lists
  • A destination list is not active until you set an access rule that includes the destination list.

  • A destination list's comment string can contain at most 256 characters.

  • A destination list does not support regular expressions in URL paths.

  • No more than 250K destinations may be added to the Secure Access across all the destination lists.

Destination lists may contain fully qualified domain names (FQDN), URLs, or IP addresses.
File Download The maximum file size that can be downloaded is 5 GB, which applies only for access rules with the Isolate action. If the access rule does not specify the Isolate action, Secure Access will permit downloads of files greater than 5 GB. Secure Access scans the downloaded files.
File Scanning (Antivirus, Threat Grid, and AMP)
  • A file must be less than 50 MB.

  • Compressed file scanning supports no more than 16 levels of recursion.

  • AMP: The system computes only the archive hash, not hashes for files inside archives.

File Transfer The maximum file size that the Secure Web Gateway (SWG) can upload is 20 GB.
Internal Networks No more than 5000 internal networks may be added to Secure Access.
Network Tunnel Groups
  • Static Traffic Selector Prefixes must not exceed 100

  • BGP prefixes must not exceed 10,000

  • The combination of local and remote traffic selector prefixes (those configured dashboard in the dashboard plus transmitted via IKE) must not exceed 100. Customers should utilize BGP for more complex or dynamic networks.

  • Network Tunnel Groups with BGP can support up to 10,000 prefixes.

Reserved IP 20 reserved IP addresses per organization per DC or Secure Access region. Reserved IP supports 20 IPs per organization per region (sufficient for 160 Gbps of throughput).
WebSockets and HTTP PATCH For WebSockets or HTTP PATCH requests, the Secure Access Secure Web Gateway does not perform file inspection.

Reports

For details on data retention periods for each report type, see Report retention.

Feature Limit
  • Scheduled Report (email attachment)

Accepts up to 10,000 rows of data.
  • Exported Report (CSV export)

Exports no more than 100,000 rows of data.

Resource Connectors and Resource Connector Groups

Feature Limit
Maximum number of connector groups per organization 50
Maximum number of connectors per connector group 50

Service Connections

The number of total, concurrent browser-based Secure Shell (SSH) and Remote Desktop Protocol (RDP) sessions supported is limited to the total number of Secure Access Advantage, Secure Private Access (SPA) licenses purchased, regardless of the number of configured applications.


Users and Groups

For general information about adding users, groups, and endpoint devices, see Manage Users, Groups, and Endpoints Devices.

Cloud Identity Providers

Secure Access supports provisioning up to 1000 groups from a supported cloud identity provider (IdP). For information about provisioning users and groups, see Manage Cloud Identity Providers.

Note
If you have more than 1000 groups in the organization, contact Support to get assistance with importing the groups in Secure Access. For more information, see Cisco Support.

Users and Private Applications

For access to private applications, configure the user and private applications to use the same data center.