Cisco Secure Access Help

PDF

Cisco Secure Access Help

Meraki Registration

Want to summarize with AI?

Log in

Describes Meraki Registration in Cisco Secure Access. For Meraki administrators, once you have deployed the Cisco Security Connector (CSC), use the Meraki dashboard to deploy the app to devices using the instructions in the Meraki document Apple Volume Purchase Program (VPP).


For Meraki administrators, once you have deployed the Cisco Security Connector (CSC), use the Meraki dashboard to deploy the app to devices using the instructions in the Meraki document Apple Volume Purchase Program (VPP). When your endpoints have registered with Secure Access, they will appear in the dashboard. For support, contact Meraki support.


Anonymization

Secure Access provides you with the option of anonymizing mobile devices for reporting and administration purposes. When you anonymize a mobile device, its label is hidden and replaced by your device's serial number. The label name is anonymized both in the Secure Access dashboard and in the CSC app UI. For information about how to anonymize your device, see Anonymize Devices.


Register with Meraki

Note

Meraki's Hide App Feature Incompatibility

The Cisco Security Connector is not compatible with Meraki's hide app feature.

Before you begin

  • You must log in to your Secure Access dashboard as an administrator.

  • Review and ensure that you meet the Cisco Security Connector requirements.

  • Have a Meraki API key. For more information about acquiring a Meraki API key, see Cisco Meraki Dashboard API.

  • Install the Cisco Security Connector app on your iOS device (typically through MDM).

  • Configure Meraki as required so that it can push configuration information to both CSC and Secure Access. For information about configuring Meraki, see the Meraki documentation.

  • If deploying to a supervised device, ensure that the names in Secure Access match the Meraki portal name, enable device name updates under Restrictions > iOS Restrictions (Supervised) > Allow Modification of Device Name (Enable) > Keep Device Name Up-to-Date with Dashboard (Enable).

Procedure

  1. Navigate to Connect > End User Connectivity and click Internet Security. Click the iOS tab.


    The Ios Configuration Download interface.
  2. Under the MDM Managed Devices section, click Download.

  3. In the Configure Managed iOS Clients window, click Link MDM.


    The Meraki Link MDM interface.
  4. Add your Meraki MDM API Key, optionally add an Administrator Email, and click Link.

    This email address is where diagnostic reports are sent when a user clicks the I icon from within the iOS device. Once set, this email address is automatically added when managing an MDM.

    Note

    You acquire a Meraki MDM API key from the Meraki dashboard. For more information, see Cisco Meraki Dashboard API.


    The Link Meraki MDM interface.
  5. In the Provision through Meraki MDM modal, select your MDM Profiles.

    Note

    While you can deploy more than one profile to an iOS device, if you try to deploy more than one profile with Secure Access applied, an error will occur and the second profile will not be applied. You can safely deploy a second profile with only Secure Access applied to a device that has an existing profile that only has Clarity applied.


    The Provision Through Meraki interface.
  6. Check Provision Cisco Secure Access Root Certificate.

    The root certificate is required to perform SSL decryption for the intelligent proxy and also helps avoid error messages when visiting blocked pages.

  7. Click Save.

    If successful, your mobile device registers with Secure Access and is listed at Resources > Roaming Devices > Mobile Operating Systems. CSC on your mobile device updates to connect to Secure Access so that your iOS device is protected by Secure Access.


    The Registered Device List interface.

Verify Push of Profile Config

Once you have provisioned Secure Access, verify the push of the Secure Access Profile Config on your Meraki dashboard.

Procedure

In Meraki, navigate to Systems Manager > Settings.

You'll see an Secure Access DNS Proxy profile with configuration settings populated from Secure Access.

What to do next


The Meraki Settings interface.

Anonymize Your Device

Secure Access provides you with the option of anonymizing mobile devices for reporting and administration purposes. When you anonymize a mobile device, its label is hidden and replaced by your device's serial number.

Procedure

  1. In Meraki, navigate to Systems Manager > Settings and then select your profile.


    The Select Profile interface.
  2. Under Value for anonymizationLevel, type 1.

    Note
    If anonymizationLevel is not listed, click Add Setting and add a Key with the value anonymizationLevel and Number with the value of 1. A value of 0 turns anonymization off.

    If anonymizationLevel is not listed, click Add Setting and add a Key with the value anonymizationLevel and Number with the value of 1. A value of 0 turns anonymization off.
  3. Click Save.

    Meraki pushes settings to Secure Access, and Secure Access hides the device's true label name by replacing it with the device's serial number. Existing active devices anonymize with 24 hours. New devices anonymize immediately.


    The Mobile Os Anonymized Device List 01 interface.

Verify Secure Access on Your Device

On your iOS device, verify that Secure Access is operational.

Procedure

  1. In the CSC app, click the Status icon and confirm that it shows Protected by Secure Access.

  2. For protection details, tap Protected by Secure Access.


    The Verify Secure Access interface.

Verify Secure Access with Meraki

You can verify the configuration and operation of Secure Access on your Meraki-administrated device.

Prerequisites


Procedure

In the Meraki SM, your profile now has a new setting: “Umbrella DNS Proxy”.

This setting was pushed from the Secure Access dashboard.


The Meraki Settings 01 interface.

Verify Local Operation on the iOS Device

Check the Meraki Profile.

Procedure

  1. On your phone, tap Settings > General.

    The MDM profile is listed under Device Management.

    The Settings General interface.
  2. Tap Meraki Management.

    Verify that Web Content Filter is now listed. This is your confirmation that the updated profile has been pushed to the iOS device.


    Verify that Web Content Filter is now listed. This is your confirmation that the updated profile has been pushed to the iOS device.
  3. Tap More Details.

    The More Details interface.
  4. Tap Cisco Umbrella DNS Proxy.

    Notice the App: com.cisco.ciscosecurity

    The Provider Bundle: com.cisco.ciscosecurity.CiscoUmbrella

    These indicate that the profile is working correctly.


    The DNS Proxy interface.

    The Provider Bundle interface.
  5. Navigate back to Meraki Management and tap Restrictions.

    The Restrictions interface.
  6. Tap Web Content Filter.

    The Web Content Filter interface.
  7. Review the Plugin Bundle ID com.cisco.ciscosecurity. This indicates that the profile is working correctly.

    The Bundle ID interface.

Verify Secure Access

Procedure

  1. In the Cisco Security Connector (CSC) app, tap Status.


    The Protected by Secure Access interface.
  2. Tap Protected by Secure Access.

    CSC lists connection details.

    Note
    IPv6 is listed as Unprotected because this device does not have an IPv6 address.

    The Protect by CSA interface.

Verify Clarity

Cisco Security App

Procedure

  1. In the Cisco Security app, tap Status.


    The Protected by Secure Access interface.
  2. Tap Protected by Clarity.

    The CSC list connection details.

    Note
    If CSC is enabled and registered, but not connected, generate some new web traffic and try again.
    The Clarity Protect interface.

Upgrade the Cisco Security Connector

When an updated version of the Cisco Security Connector is available, it will be pushed to the App Store and updated from there.


Uninstall the Cisco Security Connector

For information about removing apps from managed devices, see Meraki SM's documentation.


Meraki Documentation