Private resources are applications, networks, or subnets that are not publicly accessible from outside your network.
Private resources are applications, networks, or subnets that your organization controls. These resources are not publicly accessible from outside your network. Examples of private resources are:
-
Applications and services that run on-premises in your data center
-
Resources running on private clouds hosted from your data center
You can configure private network entities and add private resources in your Secure Access organization. Follow these steps to add a private resource and set up network connectivity to the resource, Then, set up profiles and certificates, add the private resources on the policy rules, and set up the Cisco Secure Client and distribute a URL to the private resource.
If you attach an empty private resource group to a policy, the entire rule containing the empty private resource is dropped.
Step 1: Set Up Private Resources
Configure end user connections to a private resource, and then add a private resource to a private resource group.
-
Understand your connection options.
Specify connection requirements for private resources where you want to allow access.
For more information, see Comparison of Zero Trust Access and VPN and Manage Branch Connections.
-
Add Private Resources.
Work with resource owners to gather the information needed to configure each resource. For more information, see Add Private Resources.
-
Add new Private Resources to Resource Connector Groups.
If your traffic connects through Resource Connectors rather than Network Tunnels, and you add a private resource after you add the resource connector group, you must add the new resource to a connector group. For more information, see Assign Private Resources to a Connector Group.
-
(Optional) Block zero-trust access to specified subdomains.
If you configure a Private Resource with an IP address having a leading wildcard (for example: *.example.com), you can block zero-trust connections to subdomains that you specify.
User devices must have the Cisco Secure Client deployed. For more information, see Using Wildcards to Configure Traffic Steering for Private Destinations.
If you have deployed the zero trust client on iOS devices, see unique matching information in the "Guidelines and Limitations" section of Set up the Zero Trust Access App for iOS Devices.
-
(Optional) Add Private Resource Groups.
To speed creation and management of access rules, and ensure consistent handling of related private resources, create groups of private resources that you want to manage as a unit. For more information, see Add Private Resource Groups.
Step 2: Set Up Network Connections, VPN Profiles, and Certificates
To support decryption of traffic to private resources, you must enable global decryption. For more information, see Decryption.
-
Configure network connectivity for zero-trust connections.
Add Network Tunnel Groups or Resource Connectors to allow Secure Access to communicate with and direct traffic to your private resources. For more information, see Manage Network Connections.
-
Add VPN profiles.
To allow VPN connections to private resources, add VPN profiles to your organization. VPN configurations such as VPN traffic steering rules must exist for the applicable network address spaces. For more information, see Manage Virtual Private Networks.
-
Add and manage certificates for private resources.
Secure Access requires certificates in order to connect user traffic with your private resources and decrypt that traffic for inspection by the Intrusion Prevention System (IPS). You can upload the certificate for a resource when you configure the resource, or manage certificates from the certificate list. For more information, see Certificates for Private Resource Decryption.
Step 3: Add Private Resources in Policy Rules
If an Access policy rule applies to traffic selected with the "Any" private destinations component, Secure Access does not evaluate the traffic using the DLP policy. Secure Access forwards the private traffic to the DLP engine only if an Access policy rule matches the traffic for the selected private resources or private resource groups.
Add private access rules to the Access policy or Real Time rules to the Data Loss Prevention (DLP) policy. After you add private resources to your organization, these resources are available for you to use as destinations in your policy rules. You can use private resources in your Access policy or DLP policy.
-
Add private access rules to the Access policy.
Private access rules define which users and devices can access the private resource in the organization. For more information, see Add a Private Access Rule.
-
Add Real Time rules to the Data Loss Prevention (DLP) policy.
Real-time DLP rules define the resources that the system scans for violations in HTTP/HTTPS and non-HTTP/non-HTTPS (such as SMB and FTP) traffic in both upload and download directions for all supported file types not including forms data. For more information, see Supported File and Form Types and Add a Real Time Rule to the Data Loss Prevention Policy.
Step 4: Set Up the Cisco Secure Client and Distribute URLs
-
Ensure that user devices are set up for client-based Zero Trust Access.
To configure resources for client-based zero-trust access, ensure that user devices meet the requirements for Zero Trust. You must have the Cisco Secure Client Zero Trust Access module deployed on the devices in your organization. For more information, see Zero Trust Access Requirements and Limitations.
-
Distribute URLs for browser-based Zero Trust Access.
Establish a system for making users aware of the special URLs needed for browser-based Zero Trust Access.