<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Connect - Client-based ZTNA in Networking Demo</title>
    <link>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436835#M67</link>
    <description>&lt;P&gt;Lets say you go into the office and now finance.merakitraining.net is internally accessible.&lt;/P&gt;&lt;P&gt;How does it decide when to proxy it through Umbrella versus letting it route normally?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2024 10:06:57 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2024-08-21T10:06:57Z</dc:date>
    <item>
      <title>Cisco Secure Connect - Client-based ZTNA</title>
      <link>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436833#M65</link>
      <description>&lt;P&gt;In addition to the the existing Remote Access and Browser-based ZTNA deployments(scenarios covered in &lt;A href="https://dcloud2-sjc.cisco.com/content/instantdemo/cisco-secure-connect-instant-demo-v2?returnPathTitleKey=content-view" target="_blank" rel="noopener nofollow noreferrer"&gt;Cisco Secure Connect Instant Demo&lt;/A&gt;), we are introducing the &lt;STRONG&gt;Client-based ZTNA&lt;/STRONG&gt; to &lt;A href="https://cs.co/mlp" target="_blank" rel="noopener nofollow noreferrer"&gt;Meraki Launchpad&lt;SPAN class="lia-unicode-emoji" title=":rocket:"&gt;&lt;span class="lia-unicode-emoji" title=":rocket:"&gt;🚀&lt;/span&gt;&lt;/SPAN&gt;&lt;/A&gt; for &lt;U&gt;Cisco and partner sellers&lt;/U&gt; to demonstrate. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Feature Summary:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Zero Trust Network Access (ZTNA) is a turnkey-as-a-service solution that provides granular Zero Trust based access to network resources. Cisco Secure Client with the ZTA module or Cisco Zero Trust Access mobile apps (Apple iOS &amp;amp; Samsung Android 14+) enables endpoints for secure private access using Client-based ZTNA. More reading in &lt;A href="https://community.meraki.com/t5/Secure-Connect-Resource-Hub/Client-based-ZTNA/ta-p/243904" target="_blank"&gt;Community post: Client-based ZTNA&lt;/A&gt;. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Demo Story:&lt;/STRONG&gt;&lt;BR /&gt;Bill S. (bills@merakitraining.net) from the Finance department needs to access the internal private application with FQDN 'finance.merakitraing.net.' Instead of using a remote access VPN, Meraki Launchpad IT has decided to implement ZTNA, which offers more granular control over access to only the required network resources. The team opted for Client-based ZTNA, as it is well-suited for most modern, client-initiated applications. Bill's client device is not part of this demo, but as you can see below the device has been enrolled with Cisco Secure Client ZTA module and Bill's identity is associated.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ZTNA-enroll-0.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266129i28C0CAE5B6DFF392/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ZTNA-enroll.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266136i3B5F23AD37E0012D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Now, let's demonstrate how this Client-based ZTNA is implemented and managed.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Demo Flow (~15mins):&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;As Cisco employees or partners, access &lt;STRONG&gt;Meraki Launchpad&lt;SPAN class="lia-unicode-emoji" title=":rocket:"&gt;&lt;span class="lia-unicode-emoji" title=":rocket:"&gt;🚀&lt;/span&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; demo org via &lt;A href="https://cs.co/mlp" target="_blank" rel="noopener nofollow noreferrer"&gt;https://cs.co/mlp&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;Navigate to &lt;A href="https://n398.meraki.com/o/d029Cc/manage/organization/secure_connect/directory_users?from=secure_connect+users" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;Secure Connect &amp;gt; Users&lt;/STRONG&gt;&lt;/A&gt; page and verify Bill is part of the &lt;STRONG&gt;Finance Meraki Training&lt;/STRONG&gt; group.&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShawnHu_1-1724284033399.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266126iA10E17B0FEE3BC93/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Review the &lt;STRONG&gt;Finance Home&lt;/STRONG&gt; private application on &lt;A href="https://n398.meraki.com/o/d029Cc/manage/organization/secure_connect/applications/private_resources?from=secure_connect+resources_applications" target="_blank" rel="noopener nofollow noreferrer"&gt;Secure Connect &amp;gt; Resources and Applications&lt;/A&gt; page. Highlight that only &lt;STRONG&gt;Client-based&lt;/STRONG&gt; is enabled under &lt;STRONG&gt;Access methods&lt;/STRONG&gt; section for this application. &lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShawnHu_2-1724284247997.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266127iD6494259AA48B896/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShawnHu_4-1724284619759.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266131iBD412137686EE5BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Review the &lt;A href="https://n398.meraki.com/o/d029Cc/manage/organization/secure_connect/browser_access_policy?from=secure_connect+zero_trust_access" target="_self" rel="nofollow noopener noreferrer"&gt;Secure Connect &amp;gt; Zero Trust Access&lt;/A&gt; settings to confirm that the group &lt;STRONG&gt;Finance&lt;/STRONG&gt; has the allow permission to access the appropriate resources and applications. Defining access policies by user group is a scalable way to manage your network. However, you can also configure policies at the individual user level.&lt;DIV class=""&gt; &lt;/DIV&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ZTA-Policies.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266133iA0219D393764C84E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, you might be interested in how Meraki Launchpad IT team gains the visibility into Bill's access? First, navigate to &lt;STRONG&gt;Secure Connect &amp;gt; Security Activity &lt;/STRONG&gt;to access the Umbrella dashboard. Once there, continue by selecting &lt;STRONG&gt;Reporting &amp;gt; Core Reports &amp;gt; Activity Search&lt;/STRONG&gt; on the Umbrella side.&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShawnHu_5-1724285355020.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266130i38E1944791B125C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Select &lt;STRONG&gt;Client-based ZTA&lt;/STRONG&gt; to filter the activity logs, and you will find Bill accesses the application every few hours.&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShawnHu_6-1724285452230.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/266135iDFD48FB978EF2573/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;To conclude, with Cisco Secure Connect Client-based ZTNA, now Bill who is part of Finance group can efficiently access the internal finance application anytime from anywhere with their ZTNA trusted devices. Also, Meraki Launchpad IT team minimizes the attack surface by reducing unnecessary network access. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resources&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learning.meraki.net/#/online-courses/90fdc9ab-061d-43bd-8deb-608646ac1734" target="_blank" rel="noopener nofollow noreferrer"&gt;Meraki Learning: Introducing Cisco Secure Connect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/CiscoPlusSecureConnect/Cisco_Secure_Connect_-_ZTNA_Architecture_Start" target="_blank" rel="noopener nofollow noreferrer"&gt;Meraki doc: Cisco Secure Connect - ZTNA Architecture Start&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/CiscoPlusSecureConnect/Cisco_Secure_Connect_-_ZTNA_Architecture_Start/Cisco_Secure_Connect_-_Client-based_ZTNA" target="_blank" rel="noopener nofollow noreferrer"&gt;Meraki doc: Cisco Secure Connect - Client-based ZTNA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/CiscoPlusSecureConnect/Cisco_Secure_Connect_-_ZTNA_Architecture_Start/Cisco_Secure_Connect_-_Zero_Trust_Access_Policies" target="_blank" rel="noopener nofollow noreferrer"&gt;Meraki doc: Cisco Secure Connect - Zero Trust Access Policies&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 04:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436833#M65</guid>
      <dc:creator>xiaoyhu</dc:creator>
      <dc:date>2024-08-21T04:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Connect - Client-based ZTNA</title>
      <link>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436834#M66</link>
      <description>&lt;P&gt;Various users and clients are involved in different Secure Connect use cases, and we have automation in place to continuously generate these access activities. Here is a quick list. &lt;/P&gt;&lt;TABLE border="1" width="64.94276677100144%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="22px"&gt;Users&lt;/TD&gt;&lt;TD width="25%" height="22px"&gt;Group&lt;/TD&gt;&lt;TD width="12.5%" height="22px"&gt;Use Cases&lt;/TD&gt;&lt;TD width="12.5%"&gt;UMB Reporting&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="42px"&gt;&lt;SPAN&gt;upayup@merakitraining.net&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="42px"&gt;Doctors&lt;/TD&gt;&lt;TD width="12.5%" height="42px"&gt;Browser-based ZTA&lt;/TD&gt;&lt;TD width="12.5%"&gt;Activity Search&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="42px"&gt;&lt;SPAN&gt;bills@merakitraining.net&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="42px"&gt;Finance&lt;/TD&gt;&lt;TD width="12.5%" height="42px"&gt;Client-based ZTA&lt;/TD&gt;&lt;TD width="12.5%"&gt;Activity Search&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="62px"&gt;&lt;SPAN&gt;iheal@merakitraining.net&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="62px"&gt;Doctors&lt;/TD&gt;&lt;TD width="12.5%" height="62px"&gt;Remote Access/VPN &lt;/TD&gt;&lt;TD width="12.5%"&gt;Remote Access Logs&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;iheal@merakitraining.net&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;Doctors&lt;/TD&gt;&lt;TD&gt;Data Loss Prevention&lt;/TD&gt;&lt;TD&gt;Data Loss Prevention&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 21 Aug 2024 04:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436834#M66</guid>
      <dc:creator>xiaoyhu</dc:creator>
      <dc:date>2024-08-21T04:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Connect - Client-based ZTNA</title>
      <link>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436835#M67</link>
      <description>&lt;P&gt;Lets say you go into the office and now finance.merakitraining.net is internally accessible.&lt;/P&gt;&lt;P&gt;How does it decide when to proxy it through Umbrella versus letting it route normally?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 10:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436835#M67</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-08-21T10:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Connect - Client-based ZTNA</title>
      <link>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436836#M68</link>
      <description>&lt;P&gt;Currently the client-based ZTNA will always intercept traffic for destinations identified as client-based ZTNA traffic. There is no concept of Trusted Network in client-ZTNA yet. &lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 13:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/networking-demo/cisco-secure-connect-client-based-ztna/m-p/5436836#M68</guid>
      <dc:creator>ggeihsle</dc:creator>
      <dc:date>2024-08-21T13:34:15Z</dc:date>
    </item>
  </channel>
</rss>

