Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage VAs in Secure Access

Want to summarize with AI?

Log in

Describes Manage VAs in Secure Access. Cisco Secure Access Virtual Appliances (VAs) are lightweight virtual machines that function as conditional DNS forwarders on your network.


Cisco Secure Access Virtual Appliances (VAs) are lightweight virtual machines that function as conditional DNS forwarders on your network. Secure Access VAs support DNS-layer security only.

In Secure Access, you can manage the configuration and deployment of the VAs for your organization.

First, download the images for the VAs and configure authentication for the VAs. Then deploy the VAs in your environment.

Manage the Secure Access Site.

Manage the settings and updates for the VAs.


Configure Authentication for Virtual Appliances

Cisco Secure Access communicates with the Secure Access Virtual Appliances (VAs) that are deployed in your organization. Secure Access makes software syncs and health checks to your VAs and requires that API requests from the VAs use authentication.

To manage the authentication of the communications from the VAs to Secure Access, we recommend that you configure API key credentials for your VA deployments.

Your API key credentials apply to all AD Connectors and Virtual Appliances deployed in your environment.

Note
The API key authentication is available for Secure Access Virtual Appliance version 3.7.0 and newer and the Cisco AD Connector version 1.14.4 or newer.

For more information about configuring authentication for AD Connectors and Virtual Appliances, see Configure Authentication for AD Connectors and VAs.


How to Set Up Your API Credentials

Procedure

  1. First, create the Secure Access Key Admin API key and secret.

  2. Then, use your Secure Access Key Admin API key credentials to generate your Secure Access client API key and secret.

What to do next

Your Secure Access client API key credentials are stored in the Virtual Appliances deployed in the organization.

Secure Access client API key credentials are valid for 90 days.

Virtual Appliances use your Secure Access client API key credentials to generate an OAuth 2.0 access token. The access token is included in every API request from the Virtual Appliance to Secure Access.

Authentication for VAs is available in Secure Access Virtual Appliance version 3.7.0 and newer.


Procedure for Configuring Authentication for Virtual Appliances

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.
  • Secure Access Virtual Appliance version 3.7.0 and newer.

Create a Secure Access Key Admin API key and secret. Use the Secure Access Key Admin API credentials to generate your Secure Access client API key credentials.

The Secure Access client API key and secret are stored in the VAs that you deploy in your environments. The generated API credentials (key and secret) apply to all VAs in the organization.


Step 1 – Create the Key Admin API Key Credentials

Procedure

Create a Secure Access Key Admin API key. For more information, see Add Key Admin API Keys. Select each type of permission for the key.

The Key Admin with All Permissions interface.
Note
Save your Key Admin API key and secret and use these credentials to configure the authentication for the VAs in the organization.

Step 2 – Add the Key Admin API Key Credentials

Add the Secure Access Key Admin API key and secret to the VA configuration in Users and Groups. Then, generate a Secure Access client API key and secret.

Procedure

  1. Navigate to Connect > Users and User Groups > Configuration Management.


    The Secure Access AD Configuration Mgmt interface.
  2. Click Advanced Settings.


    The Secure Access Advanced Settings interface.
  3. For Key Admin API Key, add the Key Admin API key, and for Key Admin Key Secret, add the Key Admin API key secret. For information about creating the Key Admin API key, see Step 1 – Create the Key Admin API Key Credentials.


    The Secure Access AD Connector Auth Add Keys interface.
  4. After you add the Key Admin API key and secret, click Generate Client API Key Pair.

  5. Save the Secure Access client API key and secret. Secure Access updates the client API key and secret automatically every 90 days.


    The Secure Access Authentication AD Generated interface.

Refresh Client API Key and Secret

Refresh your Secure Access client API key and secret.

Procedure

  1. Navigate to Connect > Users and User Groups > Configuration Management.


    The Secure Access AD Configuration Mgmt interface.
  2. Click Advanced Settings.

  3. Click Refresh.

    Secure Access refreshes the client API key and secret.


    The Secure Access Authentication AD Generated interface.
  4. For Refresh Client Keys, check the box to confirm the deletion of the client API key and secret.


    The Secure Access Refresh AD Keys interface.
  5. Click Refresh.


Reset Client API Key

Delete your Secure Access Key Admin API key and Secure Access client API key.

After you delete the Key Admin API key and client API key, existing VA deployments may continue to use the stored Secure Access client API key and secret for up to 90 days.

Procedure

  1. Navigate to Connect > Users and User Groups > Configuration Management.


    The Secure Access AD Configuration Mgmt interface.
  2. Click Advanced Settings.

  3. Click Reset Client API Key.


    The Secure Access Authentication AD Generated interface.
  4. For Reset Client API Keys, check the box to confirm the deletion of both the Key Admin API key and client API key for the VAs in the organization.


    The Secure Access AD Reset Key Dialog interface.
  5. Click Reset.


Manage DNS Forwarders

Once deployed in your environment, you can view your Cisco Secure Access Virtual Appliances (VAs) in Cisco Secure Access. Navigate to DNS Forwarders in Secure Access and manage the settings for the VAs. On each VA, you can manage the Secure Access Site for the VA, reset the VA's password, and upgrade and delete a VA.


Procedure for Managing DNS Forwarders


View the DNS Forwarders

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. On DNS Forwarders, view the deployed Virtual Appliances. The VAs have several properties:

    • Name—The descriptive name of the VA.

    • Internal IP—The internal IP address of the VA.

    • Site—The name of the Site associated with the VA.

    • Type—The type of the DNS Forwarder, for example: Virtual Appliance.

    • Status—The status of the VA.

    • Version—The version of the deployed software image on the VA.


    The Secure Access DNS Forwarders List interface.


Sync the Configuration Settings to Deployed VAs

Secure Access refreshes the latest configuration settings for the deployed Virtual Appliances.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. On DNS Forwarders, click Sync.


Edit a Site


Upgrade a Virtual Appliance

The update of a VA results in the loss of DNS service for the duration of the update. We highly recommend that you perform updates during non-business hours, or preferably, deploy a second VA for this site to automate the process of updates without introducing VA downtime.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Navigate to a Virtual Appliance and click the ellipsis (...), and then click Upgrade Virtual Appliance.


    The Secure Access Va on List interface.
  3. For Upgrade Virtual Appliance, click Upgrade.


Reset Password

Reset a Virtual Appliance's password. The Virtual Appliance username is vmadmin.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Locate a Virtual Appliance and click the ellipsis (...), and then seelect Reset Password.


    The Secure Access Va on List interface.

  3. For Reset Virtual Appliance Password, click. Reset, to generate a new password for the Virtual Appliance.


    The Secure Access Va Reset Password interface.

    Note
    It can take up to 15 minutes for the password to reset and sync with the deployed VAs.

Delete a Virtual Appliance

Remove the Virtual Appliance from the organization.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Locate a Virtual Appliance and click the ellipsis (...), and then select Delete.


    The Secure Access Va on List interface.
  3. Check the box to confirm the deletion of the VA, and then click Delete.


    The Secure Access Delete Va interface.

Manage Site for Virtual Appliance

A Cisco Secure Access Virtual Appliance (VA) is associated with a Secure Access Site. You can add a new Site, select and rename a Site, or delete the Site for the VA. If you do not select a Site for the VA, Secure Access uses the default Site.

For information about managing Sites and Internal Networks, see Manage Sites and Manage Internal Networks.


Procedure for Managing Site for Virtual Appliance


Add a Site

Add a Site for the VA.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Locate a Virtual Appliance, click the ellipsis (...), and then select Edit Site.


    The Va on List 01 interface.
  3. Click +Add, enter a descriptive name for the Site, and then click Save.

    After you add a Site, associate the Site with an Internal Network. For more information, see Manage Internal Networks.


    The Va Add Site interface.

Select a Site

Select a Site for the VA.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Locate a Virtual Appliance, click the ellipsis (...), and then select Edit Site.


    The Va on List 01 interface.
  3. Locate and select a Site for the VA, and then click Save.


    The Va Edit Site Select Site interface.

Rename a Site

Edit the name of a Site.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Locate a Virtual Appliance, click the ellipsis (...), and then select Edit Site


    The Va on List 01 interface.
  3. Locate the name of a Site, and then for Action click the ellipsis (...).


    The Site Va Rename Delete interface.
  4. Click Rename, enter a descriptive name in the text area, and then click Save.


    The Va Site Rename Site interface.

Delete a Site

Delete a Site.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Locate a Virtual Appliance, click the ellipsis (...), and then select Edit Site.


    The Va on List 01 interface.
  3. Locate the name of a Site, and then for Action click the ellipsis (...).

  4. Click Delete, check I understand and wish to proceed, and then click Delete to remove the Site.


    The Va Manage Site Delete Site 02 interface.

Configure Updates for Virtual Appliances

Cisco Secure Access Virtual Appliances (VAs) can receive automatic software updates. New software versions for the Virtual Appliances become available and are usually applied without any intervention required.


How Secure Access Updates Your Virtual Appliance

You can configure updates for the VAs in your organization. Secure Access makes API requests from each VA and pushes out software updates. If you wish to update a specific VA first, do this manually. For more information, see Manually Configure Update of a Virtual Appliance.

Logic is built-in to our API to prevent two VAs at a single site from updating at once or updating when one of the VAs is in an error state. The following checks are performed:

Procedure

  1. The API checks if there is only a single VA for the site. If there is only one VA, the API does not offer a command to auto-update.

  2. If there is a secondary VA for the site but it is in an error state, then the first VA will not auto-update.

  3. The API checks to see if a second VA for that site is already updating and if it is in a mid-update state it will not auto-update during that window of time. If we have ordered a VA to update and have not heard back that it has completed, this qualifies as a mid-update state.

  4. If all the prerequisite checks have been met, the VA is updated.


Procedure for Configuring Updates for Virtual Appliances


Configure Automatic Updates of Virtual Appliances

Set up automatic updates to your deployed Virtual Appliances.

Procedure

  1. Navigate to Connect > DNS Forwarders > Settings.


    The Secure Access DNS Settings interface.
  2. For Virtual Appliance Automatic Upgrade Schedule, choose the Day and Time range for the automatic software updates.


    The Secure Access Configure Upgrade Schedule interface.
    1. For Day, select Any day or a day of the week.


      The Secure Access Va Choose Day interface.
    2. For Time range, select one of the available times.


      The Secure Access Va Time Range interface.
  3. Click Save.


Manually Configure Update of a Virtual Appliance

The update of a VA results in the loss of DNS service for the duration of the update. We highly recommend that you perform updates during non-business hours, or preferably, deploy a second VA for this site to automate the process of updates without introducing VA downtime.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Navigate to a Virtual Appliance and click the ellipsis (...), and then click Upgrade Virtual Appliance.


    The Secure Access Va on List interface.
  3. For Upgrade Virtual Appliance, click Upgrade.


    The Secure Access Upgrade Va interface.

Postpone Updates to Virtual Appliances

You can postpone the upgrade of the software on the Secure Access Virtual Appliances in your environment. Configure the delay of the upgrade for 90 days since the latest software update was made available.

After 90 days, Secure Access upgrades the software on your Virtual Appliances according to the schedule that you configured.

Note
The software update delay applies to major releases only, and not for patch releases.

Procedure

  1. Navigate to Connect > DNS Forwarders > Settings.

  2. For Postpone Virtual Appliance Automatic Upgrade for 90 Days, select Enabled.


    The Secure Access Va Postpone Upgrade interface.

Configure Failover to Third-Party Resolvers

Configuring failover in Cisco Secure Access Virtual Appliance (VA) version 3.8.4 and later, allows administrators to specify public IPv4 DNS resolver IP addresses as fallback options. When this feature is enabled, the VA routes DNS queries according to a defined order during failover: initially to the configured Cisco resolvers, then to the Cisco global resolver, and, if those are unreachable, to the administrator-specified third-party public IPv4 resolvers.

This capability allows organizations to:

  • Maintain uninterrupted DNS resolution for users and applications during Cisco resolver outages.

  • Customize DNS failover behavior by selecting up to five public IPv4 DNS resolvers that best meet organizational requirements.

Configuration and management of this feature are performed through the Secure Access dashboard. Only IPv4 addresses are supported for custom fallback resolvers. The failover sequence and health monitoring are handled automatically by the VA, ensuring seamless DNS service continuity and simplified administration.

Recovery and Switchback

The Virtual Appliance periodically checks the connectivity status of the configured Cisco resolvers. When connectivity is restored, the VA automatically switches DNS queries back to the Cisco resolvers. The recovery process typically takes two to three minutes and requires no manual intervention.

Key Considerations

  • IPv4 Support Only: Only IPv4 addresses are supported for custom public DNS resolvers.

  • Configuration Requirement: Failover functions only when the VA is configured with at least one Cisco IPv4 resolver.

  • Failover Latency: The transition from a Cisco resolver to a third-party resolver takes approximately three minutes. DNS resolution will be temporarily unavailable during this period.

  • Failover Sequence: The VA resolves DNS queries in the following order:

    1. Configured Cisco resolver

    2. Cisco global IPv4 resolver

    3. First available custom IP address (third-party resolver)


Enable Third-Party Resolver Failover

Enabling third-party resolver failover allows administrators to specify public IPv4 DNS resolver addresses as fallback options in the Secure Access dashboard. When enabled, the VA automatically routes DNS queries to these configured resolvers if Cisco DNS services become unavailable, helping to maintain continuous DNS resolution for connected clients.

Before you begin

  • Ensure you are running VA version 3.8.4 or later.

  • At least one Cisco IPv4 resolver must be configured.

  • Administrator privileges are required to modify DNS Forwarder settings.

Procedure

  1. Navigate to Connect > DNS Forwarders.

  2. Click Settings.

    DNS Forwarder page displaying the Settings option.

    The DNS Forwarders Settings page is displayed.

  3. In the Fallback Resolver IPs for Virtual Appliances area, check the Enable Custom fallback resolver IPs checkbox.

    Fallback Resolver IPs for Virtual Appliances section with fields for entering up to five public IPv4 addresses as fallback DNS resolvers.
  4. Enter the IPv4 address of the non-Cisco public fallback DNS resolver in the field.

    Click Add fallback resolver IP to add additional IPV4 addresses. You can add up to five custom public IPv4 resolver addresses as fallback options.
    Note
    Only IPv4 addresses are supported for custom fallback DNS resolvers.
  5. Click Save.


Verify the Current Resolver on the Virtual Appliance

To determine which resolver is currently handling DNS queries:

  1. Access the VA through the VMware console or SSH.

  2. Run the config va status command. Alternately, run the config va show command.

  3. Review the Current Resolver section in the command output to identify the active nameserver.

    You identify whether the Cisco Umbrella DNS resolver or a third-party fallback resolver is currently active.

    Sample command output for Umbrella DNS resolver

    The following screenshots show the output of the config va status and config va show commands, demonstrating how the Virtual Appliance displays the active resolver when an Umbrella DNS resolver is being used.


    Output of the config va status command showing the Virtual Appliance is currently using a Cisco Umbrella DNS resolver as the active resolver.

    Output of the config va show command showing the Virtual Appliance is currently using a Cisco Umbrella DNS resolver as the active resolver.

    Sample command output for third-party resolver

    The following screenshots show the output of the config va status and config va show commands, demonstrating how the Virtual Appliance displays the active resolver when a third-party fallback DNS resolver is in use.


    Output of the config va status command showing the Virtual Appliance is currently using a third-party fallback DNS resolver as the active resolver.

    Output of the config va show command showing the Virtual Appliance is currently using a third-party fallback DNS resolver as the active resolver.