Cisco Secure Access Help

PDF

Cisco Secure Access Help

Zero trust access requirements

Want to summarize with AI?

Log in

Network requirements to support zero trust access.


If you intend to configure zero trust access, ensure that your network meets the requirements for your deployment.


Secure Access Zero Trust Client-Based Enrollment Services

Required by Cisco Secure Client deployments with the Zero Trust module.

The Cisco Secure Client Zero Trust module uses HTTPS to communicate with the Secure Access Zero Trust device enrollment services. We recommend that you allow all traffic on port 443 over TCP for the Secure Access Zero Trust domains.

Domain Ports/Protocol
ztna.sse.cisco.com 443 TCP
acme.sse.cisco.com 443 TCP
devices.api.umbrella.com 443 TCP
sseposture-routing-commercial.k8s.5c10.org 443 TCP
sseposture-routing-commercial.posture.duosecurity.com 443 TCP

Secure Access Zero Trust Client-Based Proxy Services

Required by Cisco Secure Client deployments with the Zero Trust module.

The Cisco Secure Client Zero Trust module uses HTTPS to communicate with the client-based Secure Access Zero Trust proxy services. We recommend that you allow all traffic on ports 443 for the defined protocols on the Secure Access Zero Trust domains.

Domain Ports/Protocol
*.ztna.sse.cisco.com 443/TCP
*.zpc.sse.cisco.com 443/TCP and UDP
*.tia.sse.cisco.com 443/TCP and UDP

Known Network Restrictions for Zero Trust Clients

Cisco Secure Access Zero Trust supports any TCP or UDP client applications that do not rely on ICMP or DNS SRV discovery, with the following restrictions:

  • The client application must initiate all TCP connections or UDP flows.
  • Any protocol requiring a unique client IP address at the server, for example SMBv1, is not supported.

Secure Access Zero Trust Client-Based Proxy – Client Certificate Revocation Services

Required by Cisco Secure Client deployments with the Zero Trust module.

The Cisco Secure Client Zero Trust module uses HTTPS to communicate with the client-based Secure Access Zero Trust client certificate revocation services. We recommend that you allow all traffic on ports 80 and 443 over TCP for the Secure Access Zero Trust Client Certificate Revocation services domains.

Domains Port/Protocol
*.ztna.sse.cisco.com 443 TCP

Secure Access Zero Trust Proxy Services – Unmanaged Devices

Required by devices that are on an organization's network, connect to Secure Access with Zero Trust, and do not have the Cisco Secure Client deployed.

Unmanaged devices with Secure Access Zero Trust enabled use HTTPS to communicate with the Secure Access Zero Trust proxy services for unmanaged devices. We recommend that you allow all traffic on ports 80 and 443 over TCP for the Secure Access Zero Trust proxy services domains.

Domains Port/Protocol
*.ztna.sse.cisco.com 443 TCP

Secure Access Zero Trust Services and Connector Groups

Required by the Secure Access Zero Trust and Connector Groups deployments in an organization.

The following IP addresses are reserved for use by Secure Access services for Resource Connectors and must not be used elsewhere on your network.

IP Range
100.64.0.0/10