Cisco Secure Access Help

PDF

Cisco Secure Access Help

SAML identity provider requirements

Want to summarize with AI?

Log in

Network requirements to support Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules, and Secure Access integrations with SAML identity providers (IdPs).


If you intend to configure Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules, and Secure Access integrations with SAML IdPs, ensure that your network meets the requirements for your deployment.


Secure Access SAML Gateway Services

Required by Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules and Secure Access integrations with SAML identity providers (IdPs).

You must deploy either a Network Tunnel or PAC file in your organization to connect user devices to the Secure Access Secure Web Gateway (SWG).

We recommend that you allow all traffic on port 443 over TCP for the Secure Access SAML Gateway services domains.

Unless noted, send id.sse.cisco.com requests to the SWG, not directly to the internet.

Domain Port/Protocol Description
saml.fg.id.sse.cisco.com 443 TCP Secure Access SAML Gateway
*.fg.id.sse.cisco.com 443 TCP Secure Access SAML Gateway (multiple entity IDs)

Active Directory Federation Service SAML Identity Provider

  • If your organization integrates with SAML Active Directory Federation Service (AD FS) identity provider (IdP), we recommend that you bypass web traffic to *.id.sse.cisco.com on the Secure Access secure web gateway (SWG).

Secure Access SAML Identity Provider Domains

Required by Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules, and Secure Access integrations with SAML identity providers (IdPs).

To enable connections to your SAML identity providers (IdPs), allow the following domains in your firewalls on ports 80 and 443 over TCP. Ensure that traffic to your SAML IdP is bypassed on the SWG to avoid an authentication loop. For more information, see Manage Domains.

Domain Ports/Protocols
ocsp.int-x3.letsencrypt.org 80/443 TCP
isrg.trustid.ocsp.identrust.com 80/443 TCP
*.cisco.com 80/443 TCP
*.opendns.com 80/443 TCP
*.umbrella.com 80/443 TCP
*.sse.cisco.com 80/443 TCP
*.okta.com 80/443 TCP
*.pingidentity.com 80/443 TCP
secure.aadcdn.microsoftonline-p.com 80/443 TCP

Azure AD SAML Identity Provider

To exclude Azure AD SAML Identity Provider domains from Secure Access SSL Decryption, add the following domain names to your list of bypassed domains.

Domain Port/Protocol
login.live.com 80/443 TCP
login.microsoftonline.com 80/443 TCP
msauth.net 80/443 TCP
msftauth.net 80/443 TCP

Secure Access SAML Gateway Client Certificate Revocation Services

Required by Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules, and Secure Access integrations with SAML identity providers (IdPs).

We recommend that you allow all traffic on ports 80 over TCP for the Secure Access SAML Gateway Client Certificate Revocation services domains.

Domains Port/Protocol Description
validation.identrust.com 80/TCP Validate SAML certificates