Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
As told and showed to Cisco TAC this not only happens when publishing config from SMA to SWA with admin user but also with normal ISE authenticated user account. Beside from not recognizing FTP and SOCKS Proxy mode correct, it also wrongly recognizes...
Hello,maybe someone can help me with this issue. From time to time it happens that user requests that should hit the user access policy are instead matching the default policy and are dropped. If the user refreshed the page, the correct policy is hi...
Hi everyone,I´m currently doing a POC with Umbrella SIG. Traffic is forwared from the DC´s Internet Uplink (~1gbit) using SAML to authenticate users. Custom PAC file is used with Umbrella Anycast IP 146.112.255.50as destination.When comparing Umbrell...
This is not a global Cloudflare issue. Its the service that choose to enable Geo-blocking or some other sort of IP based security. We also see this from time to time and have to bypass the site from being sent through SSE.@sangchul I do agree but Ci...
@Way1 Maybe thats true at some degree depending on how many users behind a single IP. I can hide NAT 7k Users behind one single public IP from our company public IP space and it works fine.
@zetao Hello We are affected by the issue and we do not block advetisment content category. Login into an YT account fixes the issue but I can not ask thousands of users to create youtube/google accounts.We need to be able to block youtube for speci...
I run into the same issue, similar setup. Windows 11 clients, latest Cisco Secure Client(5.1.17) and ZTA modul. Only solution so far I found is to Unenroll the client. After the unenrollment I could not enroll again because of an issue with Duo Deskt...
Thanks a lot to both of you,There is only one Identification Profile the user can match and thats the default one. Using explicit proxy. All other profiles above are noAuth Rules with IP + URL matching conditions. The user hits the correct "Global Gr...