Get Started With Private Access Rules

Private access rules control and secure access to internal resources and applications that are private and should not be accessed by the general public.

Traffic to private destinations is blocked by default. You must create rules to allow traffic to private destinations.

  1. Plan your private access rule
    Plan your rule so that you get the results you expect. For example, factors such as rule order impact traffic handling.
  2. Create rule components.
    You will assemble rules largely from components, including but not limited to source, destination, endpoint posture, and security control components.
    See Components for Private Access Rules
  3. Specify rule defaults.
    New rules will use the default security controls and other settings that you specify on the Rule Defaults page.
    See Default Settings for Private Access Rules
  4. Add private access rules
    Generally, you will create rules to allow access to private resources.
    See Add a Private Access Rule
  5. Configure logging for the default private access rule
    Traffic to private destinations that does not match any other private access rule in the policy will be handled by the default private access rule. Traffic that matches this rule is blocked.
    See Edit the Default Access Rules
  6. Edit the global settings
    See Global Settings for Private Access Rules
  7. Review the rule order
    Make sure the order of the rules on the Policy page will have the results you expect.
    See Edit the Order of the Rules on the Policy Page
  8. Distribute dummy access URLs to end users
    For rules allowing access to private resources using browser-based connections, distribute the remotely accessible dummy URL to the users who will use it to connect to the resource. You configure a URL for each resource when configuring the resource.
    See Add a Private Resource.

📘

Users who are not allowed access may see a Block page

Users that attempt to access a configured private resource will see a Block page if all of the following are true:

  • The user's access is blocked by a Block rule, including by the default private access rule.
  • The user's device has the Cisco Secure Client installed.
  • Decryption is enabled on the private resource configuration page.
  • VPN connections are not enabled on the private resource configuration page.
  • Zero Trust connections are enabled for the resource.

You cannot customize this block page, and this block page is NOT the same block page that users see when they attempt to access a blocked internet destination.


Troubleshoot Internet Access Rules< Get Started With Private Access Rules > Components for Private Access Rules