Network requirements to support zero trust access.
If you intend to configure zero trust access, ensure that your network meets the requirements for your deployment.
Cisco Secure Access Help
Is this content helpful?
Thank you for your feedback. Your response has been recorded.
AI responses are currently only available to logged in users. Log in
Only ask questions about this document. To ask questions about this product as a whole, go to Technical Documentation .
Suggestions
Sorry, we couldn't generate a response for this query.
Cisco Secure Access Help
Updated: August 24, 2026
Want to summarize with AI?
Log in
On this page
Network requirements to support zero trust access.
If you intend to configure zero trust access, ensure that your network meets the requirements for your deployment.
Required by Cisco Secure Client deployments with the Zero Trust module.
The Cisco Secure Client Zero Trust module uses HTTPS to communicate with the Secure Access Zero Trust device enrollment services. We recommend that you allow all traffic on port 443 over TCP for the Secure Access Zero Trust domains.
| Domain | Ports/Protocol |
|---|---|
| ztna.sse.cisco.com | 443 TCP |
| acme.sse.cisco.com | 443 TCP |
| devices.api.umbrella.com | 443 TCP |
| sseposture-routing-commercial.k8s.5c10.org | 443 TCP |
| sseposture-routing-commercial.posture.duosecurity.com | 443 TCP |
Required by Cisco Secure Client deployments with the Zero Trust module.
The Cisco Secure Client Zero Trust module uses HTTPS to communicate with the client-based Secure Access Zero Trust proxy services. We recommend that you allow all traffic on ports 443 for the defined protocols on the Secure Access Zero Trust domains.
| Domain | Ports/Protocol |
|---|---|
| *.ztna.sse.cisco.com | 443/TCP |
| *.zpc.sse.cisco.com | 443/TCP and UDP |
| *.tia.sse.cisco.com | 443/TCP and UDP |
Cisco Secure Access Zero Trust supports any TCP or UDP client applications that do not rely on ICMP or DNS SRV discovery, with the following restrictions:
Required by Cisco Secure Client deployments with the Zero Trust module.
The Cisco Secure Client Zero Trust module uses HTTPS to communicate with the client-based Secure Access Zero Trust client certificate revocation services. We recommend that you allow all traffic on ports 80 and 443 over TCP for the Secure Access Zero Trust Client Certificate Revocation services domains.
| Domains | Port/Protocol |
|---|---|
| *.ztna.sse.cisco.com | 443 TCP |
Required by devices that are on an organization's network, connect to Secure Access with Zero Trust, and do not have the Cisco Secure Client deployed.
Unmanaged devices with Secure Access Zero Trust enabled use HTTPS to communicate with the Secure Access Zero Trust proxy services for unmanaged devices. We recommend that you allow all traffic on ports 80 and 443 over TCP for the Secure Access Zero Trust proxy services domains.
| Domains | Port/Protocol |
|---|---|
| *.ztna.sse.cisco.com | 443 TCP |
Required by the Secure Access Zero Trust and Connector Groups deployments in an organization.
The following IP addresses are reserved for use by Secure Access services for Resource Connectors and must not be used elsewhere on your network.
| IP Range |
|---|
| 100.64.0.0/10 |
Need help?
(Requires a Cisco Service Contract)
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.