cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
692
Views
2
Helpful
5
Replies

Secure Access, Secure Client ZTNA users internet destination

hadi123
Level 1
Level 1

Hi needing for assistance on how to use zero trust access for internet destinations. I am testing for users who connected to secure client zta to allow or block internet destinations. I created internet destinations and access policy for internet access, but when I try to access through the internet with zta user connected, it is not routed to the access policy that I made. I also enabled the DNS and Web Security under connect > end user connectivity.

1 Accepted Solution

Accepted Solutions

Yes - so normally internet access would not go via ZTNA, this is for private apps. However, if you want to send public internet traffic via ZTNA to egress from your resource connector, it is conceptually a private app. As such you define it as a private app, and it is subjected to a private app rule, which is by default a BLOCK unless specifically allowed in keeping with zero trust principles  

 

 

View solution in original post

5 Replies 5

howe
Level 1
Level 1

Using zero trust for internet destination actually utilises a private access rule, think of it as a private app with a non rfc 1918 address.

https://docs.sse.cisco.com/sse-user-guide/docs/zero-trust-access-to-internet-destinations

 

Thanks for the link. Question, when making access policy it should be private access? Not Internet Access?

Yes correct, private access rule  

Noted, thanks! So for clarification, Secure client zta users accessing internet destination and applying granular policy to it, that should be private access rule?

Yes - so normally internet access would not go via ZTNA, this is for private apps. However, if you want to send public internet traffic via ZTNA to egress from your resource connector, it is conceptually a private app. As such you define it as a private app, and it is subjected to a private app rule, which is by default a BLOCK unless specifically allowed in keeping with zero trust principles