Cisco Secure Access Help

PDF

Cisco Secure Access Help

Integrate Catalyst SD-WAN with Secure Access

Want to summarize with AI?

Log in

Integration Catalyst SD-WAN with Secure Access to share network context and apply consistent security enforcement for users, devices, and workloads.


Cisco Catalyst SD-WAN integrates with Cisco Secure Access to share network context between the platforms for the purpose of applying consistent security enforcement for users, devices and workloads across the enterprise. Context-aware security policies become key for implementing and achieving a true zero-trust framework for the enterprise.

With this integration feature, administrators can automatically build tunnels with reliability to Secure Access from a Catalyst SD-WAN branch and share VPN ID/name and Security Group Tag (SGT) context learned from the enterprise. Cisco Catalyst SD-WAN can be deployed and connected using either virtual or physical secure routers at branch offices, data center networks, and regional hubs. This integration allows IT teams to:

  • Connect any user to any application, with integrated capabilities for multicloud, security, predictive operations, and enhanced network visibility on a Secure Access Service Edge (SASE)-enabled architecture.

  • Ensure a predictable user experience for applications.

  • Optimize Software-as-a-Service (SaaS), Infrastructure-as-a-Service (IaaS), and Platform-as-a-Service (PaaS) connections.

  • Offer integrated security, either on-premises or in the cloud.

This section describes how to enable inline context propagation, represented by VPN IDs and Security Group Tags (SGTs).


Solution Overview

Applying consistent security enforcement for users, devices, and workloads across the enterprise is top-of-mind for any CISO. Whether the security enforcement is within the campus, branch, cloud, or data centers; consistent context-aware security policies are needed to implement and achieve a true zero-trust framework for an enterprise.

Use cases for context-aware security enforcement can revolve around employees, guests, or IoT networks behind a Catalyst SD-WAN branch that need to securely access internet/SaaS applications, with Cisco Secure Access providing cloud-based security enforcement.

With this integration, Cisco Secure Access administrators can use the rich enterprise context shared from Catalyst SD-WAN to configure simpler but granular policy control towards internet/SaaS for branch users.


The Catalyst Sd Wan Scope interface.
Note

For information about context sharing with Cisco ISE, see Integrate Identity Services Engine (ISE) with Secure Access.


Components and Prerequisites

This topic describes the components and prerequisites required for integrating Catalyst SD-WAN with Secure Access.

Components Used

The information in this integration section is based on the following components:

  • Cisco Catalyst SD-WAN release 20.15/17.15

  • Cisco Secure Access

  • Cisco ISE 3.1 patch or higher

Prerequisites

  • A working knowledge of Cisco Catalyst SD-WAN configuration and features.

  • A working knowledge of Cisco Secure Access.

The information in this section is based on devices configured in a specific lab environment. All of the devices used started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any procedure or command.


Solution Workflow

The following is the workflow for context sharing between Catalyst SD-WAN and Secure Access for VPN ID:

  1. Catalyst SD-WAN Manager integrates with Cisco Secure Access using SSE cloud credentials.

  2. Cisco Secure Access learns VPN identities using APIs (out-of-band).

  3. In Catalyst SD-WAN Manager, the Secure Service Edge policy group is configured to share VPN context in IPsec tunnels.

  4. Once the tunnels are up, VPN ID context is shared in the IPsec metadata header inline.

  5. VPN identities are leveraged in Secure Access internet access rules.

  6. Packets with VPN ID context are then subject to Secure Access policy match as source objects.

VPN ID context sharing is optional. Be aware that if the same VPN ID (VPN 88 for example) is assigned across different branches, then traffic coming into Secure Access from these branches is subject to the same policy. A Secure Access policy rule cannot differentiate traffic between branches using the same VPN ID.



Configure Context Sharing Between Catalyst SD-WAN and Secure Access

This topic describes how to set up context sharing between Catalyst SD-WAN and Secure Access for VPN IDs.

Prerequisites

  • Make sure the DNS and IP domain-lookup command is configured on vpn0 for devices and Cisco SD-WAN Manager with both having internet access.

  • Enable NAT on the WAN of the SD-WAN edge internet interface.

  • Re-direct branch internet/SaaS-bound traffic from the branch LAN towards Cisco Secure Access, using the SSE default route in config-group or policy-group (data policy for specific application based redirect). See documentation for more details.

  • Use config-group/policy-group infra only on Catalyst SD-WAN Manager.


Generate API Key Pair for Context Sharing

To configure the API keys needed for Catalyst SD-WAN Manager and Cisco Secure Access to share information, you need to generate key pair from Cisco Secure Access.

Procedure

  1. Log into Cisco Secure Access and navigate to Admin > Management > API Keys.

  2. In the upper right, click the Add button.

  3. Expand the Key Scope section and select the options Identities, Network Tunnel Group, and Tunnels.

  4. Assign Read/Write permissions to the selected scopes.

  5. Set Regions to Read Only.
    The API Key Scope interface.

  6. When all scopes are defined, click CREATE KEY. Copy and save the resulting key and secret.


Create Cisco Secure Access Credentials

Procedure

  1. In another browser tab, log into Catalyst SD-WAN Manager, and navigate to Administration > Settings > Cloud Credentials

  2. Enable Cisco SSE.

  3. Paste your Secure Access Organization Id, Api key, and Secret.

  4. Enable Context Sharing.

  5. Click Add.


    The Catalyst Cloud Credentials interface.

Add a Secure Service Edge (SSE) Policy Group

Procedure

  1. Navigate to Configuration > Policy Groups > Secure Internet Gateway/Secure Service Edge.

  2. Click Add Secure Service Edge (SSE) to configure the SSE connectivity policy.


    The Catalyst Enable Context Sharing interface.

Enable Context Sharing

Procedure

  1. Under SSE Provider, select Cisco Secure Access.

  2. Under Context Sharing, enable VPN and/or SGT for context sharing for your SSE policy.

  3. Click Save.


    The Catalyst Context Sharing VPN ID interface.

Verify and Monitor Context Sharing

This topic describes how verify context sharing between Catalyst SD-WAN and Secure Access for VPN IDs.


Verify Context Sharing in Secure Access

Service VPN IDs from Catalyst SD-WAN are automatically added to Secure Access as source resources when enabled from the SD-WAN Manager. Once added, these VPN IDs can be used when configuring access rules.

Procedure

  1. Navigate to Resources > Sources and Destinations > SD-WAN Service VPN IDs to verify that the VPN IDs are shared as resources.


    The Secure Access Resources interface.
  2. Navigate to Secure > Policy > Access Policy.

  3. Click the Add Rule drop down and choose Internet Access to verify that the VPN IDs are shared as source objects for internet access rules.


    The Secure Access Internet Rule interface.
  4. From the Select sources drop down, choose Catalyst SD-WAN Service VPN IDs as a rule source.

    From there, you can select Any Catalyst SD-WAN Service VPN ID, which will include all existing and future VPN IDs in the rule. Alternately, you can select any (or all) existing VPN IDs for more granular internet access rules.


Monitor Context Sharing in SD-WAN Manager

You can view information about the Cisco Secure Access tunnels that you have configured from a Cisco Catalyst SD-WAN device.

Procedure

Under SD-WAN Manager Tunnel monitoring Dashboard.

The Catalyst Monitor interface.

Monitor Secure Access Tunnels using the CLI

To view information about the Cisco Secure Access tunnels that you have configured from a Cisco Catalyst SD-WAN device, use the show sse all command.

Device# show sse all

***************************************
   SSE  Instance Cisco-Secure-Access
***************************************
Tunnel name : Tunnel15000001
Site id: 2678135102
Tunnel id: 617865691
SSE tunnel name: C8K-63a9b72b-f1fa-4973-a323-c36861cf59ee
HA role: Active
Local state: Up
Tracker state: Up
Destination Data Center: 52.42.220.205
Tunnel type: IPSEC
Provider name: Cisco Secure Access
Context sharing: CONTEXT_SHARING_SRC_VPN

Tunnel name : Tunnel15000002
Site id: 2678135102
Tunnel id: 617865691
SSE tunnel name: C8K-63a9b72b-f1fa-4973-a323-c36861cf59ee
HA role: Backup
Local state: Up
Tracker state: Up
Destination Data Center: 44.241.136.173
Tunnel type: IPSEC
Provider name: Cisco Secure Access
Context sharing: CONTEXT_SHARING_SRC_VPN

Activity Search in Secure Access

To search for activity from the sources in your environment over a selected time period, use the Activity Search report. The report lists all security (and non-security) activity for the sources reporting to Secure Access for the selected time period.

Procedure

  1. Navigate to Monitor > Reports > Activity Search. This takes you to the default view of the Activity Search report, which lists all of your identities and the internet requests or traffic events for your organization, tracked over time.


    You to the default view of the Activity Search report, which lists all of your identities and the internet requests or traffic events for your organization, tracked over time.
  2. Hover over individual column values to apply it as a search filter or to exclude it from the search.