Cisco Secure Access
Unified cloud security has simplified zero trust access and protected hybrid users
What is our primary use case?
My main use case for Cisco Secure Access is for one client, where I deployed DNS security. Previously, Cisco DNS security was part of Umbrella; now, it has been moved to Cisco Secure Access. I implemented DNS security, which provided the client with cloud-based DNS security and intelligent proxy features, so they are protected from day-zero attacks with policy management in place. That was one use case for Cisco Secure Access, and for another client, I have recently deployed ZTNA using Cisco Duo MFA.
For a specific example of how I used Cisco Secure Access for one of these clients, I will provide the example of one client where I deployed ZTNA through MFA. The client has around 1500 users working in a hybrid environment, so connecting every user on the VPN, whether hardware-hosted, VM-hosted, or anywhere else, causes unnecessary burden. SASE is the best use case of Cisco Secure Access in the hybrid environment, where if users want to access any of their private applications, they connect to Cisco Secure Cloud. From the cloud, the traffic is tunneled, providing zero-trust access and requiring MFA to access any internal application. This way, since it is cloud-based security, the routing and everything is taken care of in the cloud, avoiding dependency on hardware infrastructure or overusing the link in the data center itself.
What is most valuable?
The best feature that Cisco Secure Access offers is a single platform where DNS security, ZTNA, and everything are in one place, all managed through a single cloud dashboard.
Having everything in a single platform and dashboard has made things easier for me and my clients because everything is available for checking or troubleshooting.
Cisco Secure Access has positively impacted my organization because we are Cisco preferred partners. We deploy everything for our clients, so it is not just about deploying it in our organization. Since we are a preferred partner, many clients requiring Cisco Secure Access are routed to us from Cisco.
After deploying Cisco Secure Access, I received specific positive outcomes and feedback from my clients. For the use case concerning DNS security over the last three months, their AD integration with Cisco Secure Access allows them to create user-based policies for DNS security based on identity and username. They also receive a dashboard to monitor reports on threats and everything online in the cloud. The customer is very happy that they are able to overview their organization, seeing the number of users utilizing maximum applications, the top talkers, and everything.
Cisco Secure Access has greatly impacted protecting my organization and clients from threats such as phishing and ransomware. Because it has ZTNA and is cloud-based with VMs deployed inside the network, it creates best practice tunnels required for accessing applications from day one. Thus, we can deploy with peace of mind without juggling best practices or opening only specific ports.
What needs improvement?
Cisco Secure Access can be improved by providing information about the location of the PoPs where users are connected. The guidelines in KSA say it is mandatory for the PoPs to be regional, similar to how Fortinet SASE discloses its PoP locations.
In terms of needed improvements around documentation and support, the documentation has been good for me. Since I deployed for the first time, I went through Cisco documents, which helped me a lot, and their program on the T-Cloud labs also provided great support. Completing the lab gave me the confidence to deploy for the customer. The documentation and the labs provided by Cisco are very good.
For how long have I used the solution?
I have been using Cisco Secure Access for the last six months.
What other advice do I have?
For others looking into using Cisco Secure Access, my advice is that it is a good solution and they should experience it.
I chose eight out of ten primarily due to only the PoP presence. I would rate the ease of managing Cisco Secure Access through its single cloud-managed console an eight.
In my experience, it is easy to navigate and manage everything from the console, but compared to the FortiGate SASE platform, FortiGate has a unified platform for all their products, while Cisco has each platform operating differently.
I use the Zero Trust Network Access (ZTNA) feature of Cisco Secure Access, and it is a great feature. We do not need to worry about the security of accessing applications from outside the environment. With ZTNA, each application access requires authentication, which is a truly great feature.
This ZTNA approach has positively changed my client's security posture, and there are no significant challenges or surprises. I rate this product eight out of ten.
Modern SSE-Based Secure Access That Speeds Up Work
User-Friendly with Strong Security but Session Timeout Frustrates
Dependable Security with Cost-Effective Flexibility
Ensures Compliance, Easy Setup, Needs Front-End Improvement
Consistent Secure Access Beyond VPN with Cisco Secure Access
The administration could also be more intuitive in some areas, and troubleshooting certain access issues can require digging through different settings and logs. For users, the experience is generally good, but there can occasionally be some confusion when access policies or security controls affect how they connect to specific resources. These are not major issues, but simplifying the management experience and making troubleshooting more straightforward would make the product even better.