Network requirements to support virtual private networks (VPN) in Secure Access.
Your network must meet the following requirements for Cisco Secure Client deployments with the Virtual Private Network (VPN) module.
Cisco Secure Access Help
Is this content helpful?
Thank you for your feedback. Your response has been recorded.
AI responses are currently only available to logged in users. Log in
Only ask questions about this document. To ask questions about this product as a whole, go to Technical Documentation .
Suggestions
Sorry, we couldn't generate a response for this query.
Cisco Secure Access Help
Updated: August 24, 2026
Want to summarize with AI?
Log inNetwork requirements to support virtual private networks (VPN) in Secure Access.
Your network must meet the following requirements for Cisco Secure Client deployments with the Virtual Private Network (VPN) module.
Required by Cisco Secure Client deployments with the Virtual Private Network (VPN) module.
The Cisco Secure Client VPN module uses HTTPS to communicate with the Secure Access VPN client head end services. We recommend that you allow all traffic on ports 443 over TCP or UDP, and ports 500/4500 over IPsec (UDP) for the Secure Access VPN domains.
NoteThe Cisco Secure Client VPN module automatically uses TLS 443/UDP when it senses that 443/UDP is open.
Remote access virtual private network (VPN) head end services.
| Domain | Port/Protocol |
|---|---|
| *.vpn.sse.cisco.com | 443 TLS (TCP/UDP) |
| *.vpn.sse.cisco.com | 500/4500 IPsec (UDP) |
Required by Cisco Secure Client deployments with the Virtual Private Network (VPN) module.
The Cisco Secure Client Zero VPN module uses HTTPS to communicate with the Secure Access VPN client certificate revocation services. We recommend that you allow all traffic on ports 80 over TCP for the Secure Access VPN domains.
| Domains | Port/Protocol | Description |
|---|---|---|
| *.vpn.sse.cisco.com | 80/TCP | Validate VPN certificates |
Need help?
(Requires a Cisco Service Contract)
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.