Cloud-delivered Security Service Edge (SSE) platform with unified management console
Secure Access is delivered from Cisco's cloud rather than from appliances at each site, and combines the security functions of a Security Service Edge into one service. A single management console holds the configuration, policy, and reporting for web, private application, and firewall traffic, so an administrator does not switch consoles per function. Traffic from users and sites is forwarded to the cloud service, inspected there, and then sent on to its destination.
02
Secure Web Gateway (SWG) with full web proxy inspection of HTTP/HTTPS traffic
The service includes a secure web gateway that terminates and proxies user web traffic rather than only inspecting it in passing. Both HTTP and HTTPS requests are proxied, so the full URL, the request, and the response body are available for policy decisions and inspection. Because inspection is at the proxy, file content, application actions, and threat scanning all operate on the reconstructed session.
03
TLS/SSL decryption and inspection
Encrypted sessions are decrypted at the cloud proxy so their contents can be inspected, then re-encrypted before being forwarded to the destination. Decryption is controlled by policy, so administrators can exempt categories such as financial or health sites from inspection while decrypting the rest. Endpoints trust the service's certificate so the substitution does not break the client.
04
URL and web content filtering by category and reputation
Web requests are checked against a categorization of destinations and a reputation assessment of the site, and policy allows, blocks, or warns based on those attributes. Administrators select the content categories to block, such as adult or gambling content, and can add explicit destination lists that override the category decision. Blocked requests return a block page to the user and are recorded as events.
05
Granular web app controls (block uploads, downloads, posts within apps)
Beyond allowing or blocking an application outright, the service can control specific actions within it because the proxy sees the full transaction. Administrators can permit an application while blocking file uploads, file downloads, or the posting of content within it. This lets a service be used in read-only or restricted fashion instead of being blocked entirely.
Your plan caps how many capabilities are shown — upgrade to see the full list