Cisco Secure Access Help

PDF

Cisco Secure Access Help

Virtual private network requirements

Want to summarize with AI?

Log in

Network requirements to support virtual private networks (VPN) in Secure Access.


Your network must meet the following requirements for Cisco Secure Client deployments with the Virtual Private Network (VPN) module.


Secure Access VPN Services

Required by Cisco Secure Client deployments with the Virtual Private Network (VPN) module.

The Cisco Secure Client VPN module uses HTTPS to communicate with the Secure Access VPN client head end services. We recommend that you allow all traffic on ports 443 over TCP or UDP, and ports 500/4500 over IPsec (UDP) for the Secure Access VPN domains.

Note
The Cisco Secure Client VPN module automatically uses TLS 443/UDP when it senses that 443/UDP is open.

Remote access virtual private network (VPN) head end services.

Domain Port/Protocol
*.vpn.sse.cisco.com 443 TLS (TCP/UDP)
*.vpn.sse.cisco.com 500/4500 IPsec (UDP)

Secure Access VPN Client Certificate Revocation Services

Required by Cisco Secure Client deployments with the Virtual Private Network (VPN) module.

The Cisco Secure Client Zero VPN module uses HTTPS to communicate with the Secure Access VPN client certificate revocation services. We recommend that you allow all traffic on ports 80 over TCP for the Secure Access VPN domains.

Domains Port/Protocol Description
*.vpn.sse.cisco.com 80/TCP Validate VPN certificates