Cisco Secure Access Help

PDF

Cisco Secure Access Help

Network Connections

Want to summarize with AI?

Log in

Understand the network connections that Secure Access supports to direct traffic to internet and private resources.


Cisco Secure Access supports multiple ways to direct traffic to internet and private resources. Depending on your deployment, you can configure either method or both methods.

  • Use network tunnel groups to route traffic from remote users, on-premises users, and branch locations to the internet and to private destinations managed by your organization. Network tunnel groups also support branch-to-branch traffic.

  • Use resource connector groups to provide Zero Trust Access connectivity between user devices and your organization's private resources.

For connections to configured private resources, Secure Access supports multiple ways to direct traffic from your users: Network Tunnel Groups and Resource Connector Groups. Both involve virtual machine instances deployed on your network.

For help choosing a connection method, see Comparison of Network Connection Methods.

For configuration tasks, refer to:


Comparison of Network Connection Methods

Secure Access supports two methods for directing user traffic to private destinations:

  • Resource Connectors (deployed in connector groups)

  • Network Tunnels (deployed in network tunnel groups)

Choose the method based on the traffic you need to route, the connection types you support, and your network design.

Feature Resource Connectors Network Tunnels
Traffic destination Private resources only Private resources and internet-bound traffic
Supported connection types Zero Trust Access connections (client-based and browser-based) VPN, branch-to-branch, and Zero Trust Access connections (client-based and browser-based)
Deployment model Virtual machine instances deployed in groups IPsec-capable network devices on supported virtual or hardware platforms
Connectivity requirement Require only outbound connections from your network Require devices that can initiate IPsec IKEv2 tunnels
Routing requirement Additional routing configuration is typically not required Network routing configuration is required
Overlapping IP ranges Supported when the resource is defined and accessed by FQDN See network tunnel documentation for your deployment design
Exposure model Expose only specified private resources to Secure Access Extend your network to the Secure Access cloud
Scaling model Scale by deploying additional connectors in a group Uses your existing tunnel-capable network infrastructure
Best fit Private-resource access with Zero Trust Access Broader traffic routing, including internet-bound and branch-to-branch traffic

If both methods are configured for the same private resource

If both a network tunnel group and a connector group with connectors are properly configured to support the same connection, a connector forwards Zero Trust Access traffic by default.

If all connectors in the connector group are unreachable, the network tunnel routes the traffic.

If the connector group is reachable but the request fails, traffic does not fall back to the tunnel and the connection fails.

For configuration tasks, refer to:


Network Tunnels in Secure Access

Network tunnel groups use IPsec IKEv2 tunnels to connect your network to Secure Access data centers.

Network devices that support IPsec IKEv2 can forward traffic through these tunnels to Secure Access. Use network tunnel groups when you need to route traffic to private resources, route internet-bound traffic, or support VPN, branch-to-branch, or Zero Trust Access connections.

For configuration details, refer to Manage Network Tunnel Groups.


Resource Connectors in Secure Access

Resource connectors are virtual machine instances that you provision in Secure Access and deploy inside your network. You manage resource connectors in groups.

Use resource connector groups to provide Zero Trust Access connectivity between user devices and your organization's private resources.

Resource connectors require only outbound connections from your network and expose only the private resources that you define.

For configuration details, refer to Manage Resource Connectors and Connector Groups.