Cisco Secure Workload Compatibility Matrix
Cisco Secure Workload

Compatibility Matrix

Verify supported operating systems, external systems, and connectors for Secure Workload agents.

This lookup table provides details about the supported operating systems associated with each Cisco Secure Workload agent version. Please refer to the Secure Workload Software Agent Support Policy for detail on agent support lifecycle.


Secure Workload can integrate with a number of external systems to query workload and/or endpoint context, ingest traffic telemetry data, and enforce policies other than software agents. This table provides the information about supported versions and the capabilities that can be enabled through the integration.

External system Supported version Context (Labels) Enforcement Telemetry ingest
Cisco AnyConnect 4.8 and higher
Cisco ISE 2.4 and higher
Cisco Secure Firewall 7.0.1 and higher
Infoblox REST API enpoint supporting WAPI
version 2.6, 2.6.1, 2.7, 2.7.1
Kubernetes 1.16 to 1.27
Red Hat OpenShift 3.11, 4.2 to 4.13
ServiceNow New York and higher
VMware vCenter 6.5 and higher

Secure Workload uses connectors installed on external virtual appliances to support multiple use cases, including flow ingestion, inventory enrichment, and alert notifications. Edge connectors connect to external systems for ingest of context information for inventory enrichment or provide alert notification. Ingest connectors receive and process flow or packet data using standard protocols such as ERSPAN, IPFIX, and NetFlow v9. Secure connectors provide a local, on-premises proxy for orchestrator integration when using the Secure Workload SaaS platform.

This table provides the minimum virtual appliance resource requirements.

Appliance type Number of vCPUs Memory Storage Number of
Number of
connectors on
one appliance
Operating system
Edge virtual appliance 8 8 GB 250 GB 1 Up to 8
Ingest virtual appliance 8 8 GB 250 GB 3 Up to 3
SaaS secure connector 2 4 GB 1 RHEL and CentOS 7.x (x86_64)