Cisco Secure Access Help

PDF

Cisco Secure Access Help

Deploy the Android Client

Want to summarize with AI?

Log in

Describes Deploy the Android Client in Cisco Secure Access and explains Download Configuration, MDM Configurations, and Secure Access Certificate. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.


The process of deploying the Android client consists of three tasks:

  • Download the Android Configuration

  • Configure the mobile device manager (MDM) you use

  • Push the Secure Access certificate

Note

DNS Policies Only

Android Mobile Security is only supported in Secure Access for DNS policies.

Download Configuration

Android Configuration Download

MDM Configurations

Secure Access Certificate

Push the Secure Access Certificate to Devices


Android Configuration Download

By downloading an XML file from Secure Access and adding this file to your MDM system, your MDM system is able to push configuration information to both Cisco Security Connector (CSC) and Secure Access so that your Android device is registered with Secure Access. The result is that your Android device is protected by Secure Access.

For information about configuring your specific MDM system, see your MDM system's documentation.


Procedure

Procedure

  1. Navigate to Connect > End User Connectivity and click Internet Security. Click the Android tab.


    The Android Configuration Download interface.
  2. Under the MDM Managed Devices section, click Download.

    The downloaded configuration file contains details that are required to enable Secure Access security on your Android device. For example, it includes the organization ID and unique registration token associated with your Secure Access organization.

    {"organizationInfo":{"Value":{"organizationId":<orgid>,"productId":<product id>"regToken":"<reg token>"}}}
    If the deployment key is enabled, the configuration file includes the deployment key, deployment key name, and MDM ID in addition to other attributes. For more information on the deployment key, see Manage Device Deployment.
    {"organizationInfo":{"Value":{"deploymentKey":"<deploymentkey>","deploymentKeyName":"<deployment key name>","mdmId":"<mdm id>, "organizationId":<ordgid>,"productId":<product id>,"regToken":"<reg token>"}}}

    Only one administrator is required to download the config file.

  3. Save the file securely; you will use it in deploying your mobile device manager (MDM).


Fail Close/Open Scenario

Navigate to Cisco Secure Client settings > Advanced, and enable the Mobile devices DNS Fail-open field to egress DNS traffic directly to the internet when Secure Access is unreachable.


The Mobile Device Setting interface.
Note
The Mobile Device Settings are the only settings applicable for Android devices under the Secure Access Security Settings.

In case of internal errors, such as the Secure Access Resolver is not reachable or the DNSCrypt Certificate is not available, the Secure Access UI displays the following:


The Cisco Secure Client interface.

Manage Device Deployment

The Deployment Key feature provides an effective way to manage device registration within organizations while mitigating unauthorized access. This feature introduces the concept of a deployment key that can be activated, deactivated, and revoked. By utilizing deployment keys, administrators gain control over the credentials used by devices during registration for Secure Access protection. A deployment key is a field in the Android configuration file (mobileconfigAndroid.txt), which is used when registering devices to your organization's network. This feature ensures that only authorized devices are enrolled by requiring an active deployment key for registration.

Note

Devices that are deleted from the dashboard will automatically get reregistered when the Umbrella module is restarted, provided the deployment key in their mobileconfigAndroid.txt file is active.

This feature facilitates seamless device registration and ongoing validation while offering the flexibility to deactivate keys when necessary. If any unauthorized devices try to connect, administrators can swiftly deactivate the current deployment key and delete the suspected devices from the dashboard, ensuring a secure and efficient network environment. The devices will not be able to reregister with the now-deactivated deployment key. Administrators can then activate a new deployment key. This allows IT teams to maintain operational continuity while safeguarding against unauthorized access.

If your Secure Access deployment requires a deployment key, or if your organization has already enabled them, the Android configuration file can only be downloaded when there is an active deployment key (see image below). Then, register your supervised Android device through your Mobile Device Manager (MDM) to Secure Access. For more information, see Android Configuration Download.


The Android Configuration File Download interface.

Prerequisites for Device Deployment Management

  • For the Global deployment, the Deployment key feature is optional. Enable the Deployment Keys feature (Connect > End User Connectivity > Internet Security) if it is disabled.


The Deployment Disabled interface.

Add and Activate Deployment Key

Procedure

  1. Navigate to Connect > End User Connectivity.

  2. Click Internet Security.


    The Deployment Mgt Android interface.
  3. In the Deployment Management section, expand the device type (Android).


    The Managed Android Add Deployment Key interface.
  4. Click Add deployment key.

  5. In the Add deployment key window, click Add & activate deployment key to create and activate a deployment key for inclusion in your organization's Android configuration file.


    The Add Deployment Key interface.

What to do next

You can choose to add the deployment key immediately, but activate it later. In such a scenario, click Add deployment key. The deployment key is added to the table. When you are ready to activate the deployment key, click Activate in the Action column.

  • Only one deployment key can be active at a time for each device type.

  • You can add up to five deployment keys per device type. To remove a key, contact Cisco support or your Account Manager.

  • The deployment key name includes a random number to ensure its uniqueness.


Manage Deployment Key Compromise

If you determine that a key has been compromised, take action to protect your network's integrity and security. Compromised keys can pose significant risks, as they may allow unauthorized access to your network.

This section outlines the necessary actions to be taken to ensure network security and continuity, including deactivating compromised keys, understanding the effects on existing clients, and steps for activating and distributing a new key for secure device registration.

Procedure

  1. Deactivate the Compromised Key: Deactivate the compromised key. This action prevents any further device registrations using the deactivated key, ensuring that your network remains secure.

    To deactivate a deployment key, perform the following steps:

    1. Navigate to Connect > End User Connectivity.

    2. Click Internet Security.

    3. In the Deployment Management section, expand the device type.

    4. Click Deactivate in the Action column. Upon deactivating the compromised deployment key, it is important to consider its implications on both existing clients and the registration of new devices:

    • Effect on existing clients: It's important to note that deactivating a key will not disrupt the operation of clients already using it. These clients will continue to function normally, minimizing any potential impact on your current network operations.

    • Limitations for new devices: However, deactivated keys cannot be used for registering new devices. This means that any device attempting to register itself with the deactivated key will be unable to do so.

    Note

    Devices that are deleted from the dashboard will automatically get reregistered when the Umbrella module is restarted, provided the deployment key in their mobileconfigAndroid.txt file is active.

  2. Activate the new deployment key: To facilitate the registration of new devices, you must activate a different deployment key. This new key will replace the compromised one and will be used for future device registrations.

  3. Download a new profile: After the new key is activated, download a new profile, specifically the Android configuration file. This file contains the updated information, including the new active deployment key.

  4. Distribute the new profile to new devices: Distribute the updated Android configuration profile to any new devices that need to connect to your network. This ensures that they have the correct and secure credentials to register and operate within your network environment.

  5. Update the Android configuration file for registered Devices: Devices that are already registered and require an update to the Android configuration file will automatically receive changes once the configuration is updated in the mobile device manager (MDM).


Delete a Deployment Key

To delete a deployment key, submit a support ticket to Cisco support or contact your Account Manager.


Reverting to Using Legacy Deployment Implementation

If needed, you can revert to the legacy registration mechanism by disabling the Deployment Keys feature (Connect > End User Connectivity > Internet Security).


The Deployment Disabled interface.
  • After disabling the Deployment Keys feature, devices that are currently using the last activated deployment key will continue to be protected by Secure Access. However, new devices will not be able to register with the deactivated deployment key.

  • To revert to the legacy registration mechanism, download the updated Android configuration file (mobileconfigAndroid.txt), which will no longer include the deployment key. New devices can now register using the legacy method.


Backward Compatibility

This feature is designed for backward compatibility, allowing organizations to adopt the new deployment key functionality at their own pace without disrupting existing workflows or functionality.

For example, on Android:

  • Cisco Secure Client for Android Release 5.1.9.114 or earlier will continue to use the legacy User ID and fingerprint for registration purposes, regardless of whether a deployment key is present.

  • Cisco Secure Client for Android Release 5.1.9.115 or later will use the deployment key for registration, regardless of whether the User ID and fingerprint are present. If the deployment key is unavailable, the legacy User ID and fingerprint will be used for registration instead.


Cisco Meraki MDM

For Meraki administrators, once you have deployed the Cisco Security Connector (CSC), use the Meraki dashboard to deploy the app to devices. When your endpoints have registered with Secure Access, they will appear in the dashboard. For information about how to configure and enroll an Android device, see Meraki documentation.


Add App to Cisco Meraki

This process needs to be done only once.

Procedure

  1. In Meraki, navigate to System Manager > Apps > Add Apps > Add New Android App.


    This process needs to be done only once. In Meraki, navigate to System Manager Apps Add Apps Add New Android App.
  2. Search for Cisco Secure Client - AnyConnect or for the bundle id com.cisco.anyconnect.vpn.android.avf.


    In Meraki, navigate to System Manager Apps Add Apps Add New Android App. Search for Cisco Secure Client - AnyConnect or for the bundle id com.cisco.anyconnect.vpn.android.avf.
  3. Select the app and approve the permissions, then click Approve. If the app has been previously approved, simply re-approve it.


    The bundle id com.cisco.anyconnect.vpn.android.avf. Select the app and approve the permissions, then click Approve. If the app has been previously approved, simply re-approve it.

Add Configuration for App

Procedure

  1. Navigate to System Manager > Settings and click Add Profile.

  2. Select Device Profile (default) from the pop-up, then click Continue.


    To System Manager Settings and click Add Profile. Navigate to System Manager Settings and click Add Profile. Select Device Profile (default) from the pop-up, then click Continue.
  3. Name the profile.


    Settings and click Add Profile. Navigate to System Manager Settings and click Add Profile. Select Device Profile (default) from the pop-up, then click Continue. Name the profile.
  4. Click Add Settings.

  5. Select the Android device type, then search for Managed App Config.


    Select Device Profile (default) from the pop-up, then click Continue. Name the profile. Click Add Settings. Select the Android device type, then search for Managed App Config.
  6. Choose Android from the Platform menu, then choose Cisco Secure Client - AnyConnect from the App menu.

  7. Click +.



  8. Choose umbrella_org_id from the menu, and enter your org ID value. (Refer to the orgId property in the mobileconfigAndroid.json file.)

  9. Click +. Choose umbrella_reg_token from the menu and enter the value. (Refer to the regToken property in the mobileconfigAndroid.json file.)

  10. Click +. Choose umbrella_va_fqdns from the menu and enter the value. For example, va1.yourdomain.com.



  11. Click Add Settings, then search for Certificate. Click to select the result.

  12. Name the certificate, then click Choose File.


    And enter the value. For example, va1.yourdomain.com. Click Add Settings, then search for Certificate. Click to select the result. Name the certificate, then click Choose File.
  13. In the popup window, select the Secure Access root CA file you downloaded from the Secure Access dashboard. For example, https://dashboard.sse.cisco.com/o/YOUR-ORG-ID/#/deployments/configuration/rootcertificate.

  14. Click Save.

  15. Upload the CA certificate, then click Save.

  16. Navigate to Profile Configuration and deploy the configuration to one or more Android devices.

  17. Click Save.


Push the App to Devices

Multiple Device Push

Procedure

  1. Open Systems Manager > Apps.

  2. Select Cisco Secure Client- AnyConnect > Push, then push the app to the desired devices.

  3. Click Save.


    Multiple Device Push Open Systems Manager Apps. Select Cisco Secure Client- AnyConnect Push, then push the app to the desired devices. Click Save.

What to do next

Single Device Push

  1. Open Systems Manager > Apps.

  2. Select Cisco Secure Client - AnyConnect, then scroll to the device list.

  3. Select a specific device, then click Push.

  4. Click Save.


    Click Save.

Push the Cisco Root Certificate


MobileIron MDM

By downloading an XML file from Secure Access, optionally updating it, and then pasting its contents into your MobileIron system, MobileIron is able to push configuration information to both the Cisco Security Connector (CSC) and Secure Access so that your Android device is registered with Secure Access. The result is that your Android device is protected by Secure Access.

Note

MobileIron Details

For more information about using the Cisco Secure Access module with the MobileIron Mobile Device Manager, refer to MobileIron documentation, which is available online at MobileIron's website.


Configure the App

Procedure

  1. In your MobileIron admin dashboard, add a label.

  2. In your MobileIron dashboard, navigate to Apps > App Catalog.


    Cisco Secure Access. In your MobileIron admin dashboard, add a label. In your MobileIron admin dashboard, add a label. In your MobileIron dashboard, navigate to Apps App Catalog.
  3. Search for the app by name: Cisco Secure Client - AnyConnect or by bundle id: com.cisco.anyconnect.vpn.android.avf

  4. Click Cisco Secure Client- AnyConnect and open its Description page.





  5. Click Edit and expand Default Configuration for AnyConnect.

  6. Scroll to Umbrella Organization Id, Umbrella Registration Token, and Umbrella VA FQDN.


    And open its Description page. Click Edit and expand Default Configuration for AnyConnect. Scroll to Umbrella Organization Id, Umbrella Registration Token, and Umbrella VA FQDN.
  7. Open the file you saved in the section Android Configuration Download. Copy and paste the organizationid and regToken values from the file into Umbrella Organization Id and Umbrella Registration Token.

  8. Add the Secure Access VA FQDN IPs if there is a VA in the network.

  9. Click Save.

  10. Apply the label you created to the Android app. This label enables the administrator to push the app to managed Android devices.

  11. Upload the VA certificate to the MDM and push it to all users.

  12. Apply the label you created to the Android app.


    The administrator to push the app to managed Android devices. Upload the VA certificate to the MDM and push it to all users. Apply the label you created to the Android app.

    The label enables you to push the app to specific users.


Push the App

Procedure

  1. In your MobileIron dashboard, navigate to Devices & Users > Devices.

  2. Select a registered device from the Devices List.

  3. Apply the label to the device.

  4. Select Force Device Check-In from the Actions menu to push the app to the selected device.


Push User Identities

When user identities are pushed to Secure Access, you can identify and search users and devices. For more information, see Manage Identities.


Push the Cisco Root Certificate


VMware Workspace ONE

This section explains how to deploy the Umbrella module on Android devices using zero-touch deployment. This method ensures seamless protection by enabling Always On VPN through the Mobile Device Manager (MDM) Workspace One, without manual intervention.

The Umbrella module in Cisco Secure Client provides robust protection against threats by securing both applications and internet-based traffic at the DNS layer on Android devices.

Note

Workspace ONE Details

For more information about using the Cisco Umbrella Anyconnect module with the Workspace ONE MDM, refer to the Workspace ONE documentation available online on VMWare's documentation website.

Install the Cisco Secure Client only after you have published and installed the Always On VPN profile in Workspace One Intelligent Hub.

Prerequisites for Deployment

  • Complete the Android EMM (Enterprise Mobility Management) registration, device enrollment, and a work profile creation.

  • Ensure that the MDM app Hub is visible within the work profile.


Create Always On VPN Profile

Before you begin

Before you create an Always On profile, we strongly recommend ensuring both your Windows operating system is up to date with sustem-provided updates and your Windows Defender account is not out of date. Insufficient versioning and noncompliance causes policy failure.

Procedure

  1. In the Workspace ONE UEM console, navigate to Resources > Profiles & Baselines > Profiles.

  2. Click Add and choose Add Profile from the drop-down list.



  3. Select Android as the platform.



  4. Choose CUSTOM DPC or ANDROID MANAGEMENT API as the Management Type and click Next.


    Dd and choose Add Profile from the drop-down list. Select Android as the platform. Choose CUSTOM DPC or ANDROID MANAGEMENT API as the Management Type and click Next.
  5. Enter a name for your profile. For example, Always On VPN.


    The Name Your Profile interface.
  6. Navigate to the VPN section and click Add.


    M DPC or ANDROID MANAGEMENT API as the Management Type and click Next. Enter a name for your profile. For example, Always On VPN. Navigate to the VPN section and click Add.
  7. In the VPN setting configuration section, complete the fields, including the following:

    • From the Connection Type drop-down list, choose Cisco AnyConnect.

    • In the Server field, enter cisco://local.

    • In the Connection Name, enter the name.

    • Enable the Always on VPN button.

    • Enable the Set Active button.

    • Enable the Per-App VPN Rules button.

  8. Click Next.


    Enable the Per-App VPN Rules button. Click Next.
  9. Search or navigate to the Credentials section, and click Add.


    The Credential Section interface.
  10. In the Credential section, do the following:

    • From the Credential Source drop-down list, choose Upload.

    • Click Choose File to browse and select the Cisco_Umbrella_Root_CA Certificate downloaded from Umbrella.

    Note

    In Umbrella, navigate to Deployments > Configuration > Root Certificate, expand Cisco Root Certificate Authority, and download the Cisco Umbrella root certificate, see Push the Umbrella Certificate to Managed Devices

    • Click ATTACH CERTIFICATE.


      Click ATTACH CERTIFICATE.
  11. After successful upload of the certificate, the Credential Name would be added automatically and then click Next.


    Click ATTACH CERTIFICATE. After successful upload of the certificate, the Credential Name would be added automatically and then click Next.
  12. In the Assignment and Deployment profile settings screen, complete the fields, including the following:

    • In the Smart Group field, choose the group of devices to which the Always On VPN profile is to be assigned.

    • Select the appropriate deployment values. Choose Auto from the Assignment Type drop-down list, to deploy the profile to all device automatically.

  13. Click Save & Publish.




Add and Publish the Cisco Secure Client Application

Procedure

  1. In the Workspace ONE UEM console, navigate to Resources > Native > Public.


    The Apps Public 1 interface.
  2. Click Add Application.


    The Add Applctn interface.
    1. To add the Cisco Secure Client application, add the following details:

      1. Enter Managed By field, choose the Organization Group that you set up to manage applications.

      2. From the Platform drop-down list, choose Android.

      3. In the Source field, select SEARCH APP STORE to search for the application in the app store.

      4. In the Name field, enter Cisco Secure Client and click Next. Google Play launches within the console.


        The Managed Android Add Application interface.
  3. In the Google Play store, click the Cisco Secure Client AnyConnect application.


    The Name field, enter Cisco Secure Client and click Next. Google Play launches within the console. In the Google Play store, click the Cisco Secure Client AnyConnect application.
  4. Click Approve to accept the permission for all versions of the application.


    The Approve Request interface.
  5. Click Done to handle the new app permission requests.


    The App Permission Request interface.
  6. Now, click Save & Assign.


    The Edit Application interface.

    The Cisco Secure Client-AnyConnect Assignment Wizard appears:

  7. On the Distribution page, enter the necessary details to define how the application will be distributed. Click Restrictions.



  8. On the Restrictions page, enable the Managed Access button to allow only EMM managed devices to install the application. Click Tunnel.


    Will be distributed. Click Restrictions. On the Restrictions page, enable the Managed Access button to allow only EMM managed devices to install the application. Click Tunnel.
  9. On the Tunnel page, from the Android (Custom DPC) drop-down list, choose the Always On VPN profile created in the Create Always On VPN Profile section. This enables the Always On VPN profile for the managed devices. Click Application Configuration.


    The Always On VPN profile created in the Create Always On VPN Profile section. This enables the Always On VPN profile for the managed devices. Click Application Configuration.

    The Application Configuration page appears.


    The App Configuration interface.
  10. On the Application Configuration page, complete the fields, including the following:

    • Leave the Host field empty, as the server details are taken from the profile.

    • From the Accept SEULA For Users drop-down list, choose Enable to prevent users from manually accepting the SEULA banner.

    • From the Enable Always On VPN Mode for Secure Access Protection Only drop-down list, choose Enable to allow the Cisco Secure Client application to automatically manage protection and seamlessly accept VPN connection requests when Secure Access protection is activated.

    • From the Block users from creating new VPN connections drop-down list, choose Enable.

    • Enter the application configuration details, such as, Secure Access Organization Id and Registration Token, by referring the Android Config File downloaded from the dashboard. For more information on how to download Android Config File, see Android Configuration Download.


    The App Configuration interface.
  11. Click Components Profile Configuration.

  12. Click Create.


    The Component Configuration interface.

    The Cisco Secure Client-AnyConnect app assignment is created.

  13. Click Save.


    The Cisco Secure Client-AnyConnect app assignment is created. Click Save.
  14. Click Publish to publish the Cisco Secure Client Application.


    The Cisco Secure Client-AnyConnect app assignment is created. Click Save. Click Publish to publish the Cisco Secure Client Application.

What to do next

As the app delivery method is set to auto on the Distribution page the application gets installed automatically on the device and is displayed in both the console and your device.


Microsoft Intune MDM

By downloading an XML file from Secure Access and then uploading it to your Intune system, Intune is able to push configuration information to both the Cisco Security Connector (CSC) and Secure Access so that your Android device is registered with Secure Access. The result is that your Android device is protected by Secure Access.

For information about configuring Intune, see Intune's documentation.

Note

Microsoft InTune Details

For more information about using the Cisco Secure Access module with the InTune Mobile Device Manager, see InTune documentation, available online at Microsoft's documentation website.


Publish the Cisco Secure Client - AnyConnect App to Managed Android Devices

Procedure

  1. In your InTune dashboard, navigate to Apps > All Apps > Add Application.

  2. From the App Type pull-down, choose Managed Google Play.


    Dashboard, navigate to Apps All Apps Add Application. In your InTune dashboard, navigate to Apps All Apps Add Application. From the App Type pull-down, choose Managed Google Play.
  3. In the Play store, search for Cisco Secure Client - AnyConnect (or the bundle id: com.cisco.anyconnect.vpn.android.avf).



  4. Approve the app and then click Select.

  5. Click Sync. The app appears in the App List after syncing.




Configure Secure Access

Procedure

  1. In your InTune dashboard, navigate to Apps > Configuration Policy.

  2. Create a new policy, including name and description. Select the "Managed Device" enrollment type and set the platform to “Android”.



  3. Click Associated App, search for Cisco Secure Client - AnyConnect, and then click OK.

  4. Click Configuration Settings, select Use Configuration Designer and then click Add.


    Click Associated App, search for Cisco Secure Client - AnyConnect, and then click OK. Click Configuration Settings, select Use Configuration Designer and then click Add.
  5. Search for Secure Access and add the values for Umbrella Organization ID and Umbrella Registration Token from the file you downloaded in the section Android Configuration Download.

  6. Click Add.


    Access and add the values for Umbrella Organization ID and Umbrella Registration Token from the file you downloaded in the section Android Configuration Download. Click Add.

    Access and add the values for Umbrella Organization ID and Umbrella Registration Token from the file you downloaded in the section Android Configuration Download. Click Add.

    Access and add the values for Umbrella Organization ID and Umbrella Registration Token from the file you downloaded in the section Android Configuration Download. Click Add.
  7. Click the newly created policy and assign it to the group to which you need to push the configuration.


    You downloaded in the section Android Configuration Download. Click Add. Click the newly created policy and assign it to the group to which you need to push the configuration.
  8. Navigate to All Apps, select Cisco Secure Client - AnyConnect, and then go to Assignments.


    The Managed Android Microsoft Endpoint Manager interface.
  9. Click Add Group.

  10. Set the Assignment Type to “Required”, select the groups to which the AnyConnect app is to be pushed and click OK.



  11. To check the installation status for a user or device, navigate to All Apps, select Cisco Secure Client - AnyConnect, and then check Device Install Status and User Install Status.


    To check the installation status for a user or device, navigate to All Apps, select Cisco Secure Client - AnyConnect, and then check Device Install Status and User Install Status.

Push User Identities

When user identities are pushed to Secure Access, you can identify and search users and devices. For more information, see Manage Identities.


Push the Cisco Root Certificate


Samsung Knox MDM

By downloading an XML file from Secure Access and then uploading it to your Knox system, Knox is able to push configuration information to both the Cisco Security Connector (CSC) and Secure Access so that your Android device is registered with Secure Access. The result is that your Android device is protected by Secure Access.

For information about configuring Knox, see Knox's documentation.

Note

Samsung Knox Details

For more information about using the Cisco Secure Access module with the Samsung Knox Mobile Device Manager, see Knox documentation, which is available online at the Samsung Knox support website.

Register with the Enterprise Mobile Manager (EMM)


The Samsung Knox Mobile Device Manager, see Knox documentation, which is available online at the Samsung Knox support website. Register with the Enterprise Mobile Manager (EMM).

Enroll Android Devices

Procedure

  1. In the Knox dashboard, navigate to Users.

  2. Add necessary informatil,on and click Save and Request Enrollment.


    Sequence of actions and relevant settings presented in the procedure. In the Knox dashboard, navigate to Users. Add necessary informatil,on and click Save and Request Enrollment.
  3. Install Samsung Knox Manage from the Google Playstore and enroll the device if it is not already enrolled.

  4. When the device is enrolled, follow the prompts to create the work profile mode.

  5. Verify that the device appears in the Knox Manage Device list.


    If it is not already enrolled. When the device is enrolled, follow the prompts to create the work profile mode. Verify that the device appears in the Knox Manage Device list.

Push the App

Procedure

  1. In the Knox dashboard, navigate to Application > Add > Select Application Type.


    In Cisco Secure Access. In the Knox dashboard, navigate to Application Add Select Application Type. In the Knox dashboard, navigate to Application Add Select Application Type.
  2. Select Public, search for Cisco Secure Client - AnyConnect in the Playstore and approve it.


    Type. In the Knox dashboard, navigate to Application Add Select Application Type. Select Public, search for Cisco Secure Client - AnyConnect in the Playstore and approve it.
  3. Click Assign. This assigns the application to the device.


    Add Select Application Type. Select Public, search for Cisco Secure Client - AnyConnect in the Playstore and approve it. Click Assign. This assigns the application to the device.

Set Managed Configuration

Procedure

  1. Set Managed Configuration.


    The Set Managed Configuration workflow in Cisco Secure Access. It explains the sequence of actions and relevant settings presented in the procedure. Set Managed Configuration.
  2. Add the Secure Access organization and registration token.


    Access. It explains the sequence of actions and relevant settings presented in the procedure. Set Managed Configuration. Add the Secure Access organization and registration token.
  3. Select the target group or organization and click Assign.


    Presented in the procedure. Set Managed Configuration. Add the Secure Access organization and registration token. Select the target group or organization and click Assign.

Create Profile in Knox Manage

Procedure

  1. Navigate to Profile and apply application control settings.


    Profile in Knox Manage workflow in Cisco Secure Access. Navigate to Profile and apply application control settings. Navigate to Profile and apply application control settings.
  2. Verify that the applications pushed to the device appear.


    Navigate to Profile and apply application control settings. Navigate to Profile and apply application control settings. Verify that the applications pushed to the device appear.

Push User Identities

When user identities are pushed to Secure Access, you can identify and search users and devices. For more information, see Manage Identities.


Push the Cisco Root Certificate


Push the Cisco Root Certificate to Devices

To support the display of block pages for HTTPS sites, HTTPS decryption if the Intelligent Proxy is used, and Trusted Network Detection if a VA is present you must push the Secure Access certificate to each of your managed devices.


Procedure

Before you begin

Procedure

  1. Navigate to Secure > Settings > Certificate.


    Full admin access to the Secure Access dashboard. See Manage Accounts. Navigate to Secure Settings Certificate.
  2. Expand Secure Access root certificate and download the Cisco Secure Access root certificate.

    For more information about installing the root certificate, see Install the Cisco Secure Access Root Certificate.


    The Secure Access Root Certificate interface.
  3. Push the root certificate to all your devices from the MDM admin panel so that block pages can be displayed.

    This allows block pages for HTTPS sites to appear correctly, enables HTTPS decryption if the Intelligent Proxy is used, and enables Trusted Network Detection if a VA is present.

What to do next

Note
If there is an Secure Access VA in your network and you want to use Trusted Network Detection, configure the VA as detailed in Umbrella Virtual Appliance: Receiving user-IP mappings over a secure channel.