Cisco Secure Access
Unified access control has strengthened zero trust while integration and automation still need work
What is our primary use case?
We use Cisco SD-WAN in our own company for our own needs, and we are also selling this to our customers while performing operations for customer networks. My personal customer scope is the large enterprise customer. We have integrated Cisco Identity Intelligence with Cisco Secure Access using Cisco ISE.
How has it helped my organization?
This integration has influenced our identity management and security measures significantly, as we use Cisco ISE to harmonize the access control, leading us towards a zero-trust network environment.
What is most valuable?
The advantages I see in Cisco Catalyst SD-WAN compared to their competitors is the seamless service scope, where I can have from Cisco the LAN, Wi-Fi environment, the SD-WAN environment, and the security environment, and as now announced from Cisco, all the management is combined in one orchestrator, which is the most beneficial aspect for me, not looking for the best of breed but more looking for the best fit.
I have used the policy verification to help reduce policy misconfigurations.
The multi-organization management capability of Cisco Secure Access in terms of usability and efficiency is quite good, as there is an RBAC system, allowing me to granularly define the access roles. I would rate this an eight.
What needs improvement?
For SD-WAN, I do not see any room for improvement, but for Cisco Secure Access, I think there is a lot to do for Cisco to integrate that in the Telco enterprise environment for seamless operation.
I am not talking about the integration with third-party solutions; you need to control the SD-WAN security policies in the same hand with the cloud security, and currently, both are managed by two different management systems, so you need to integrate that seamlessly.
It could be better from Cisco. The API interfaces, for example, Terraform integration, could be quite useful because there are some customers looking for full automation, and therefore it would be good to have a Terraform integration.
Some other companies are better on the market currently when it comes to the AI Access feature of Cisco Secure Access for providing deep visibility and control over AI applications, tools, and LLMs. If you compare it with the AI capability of Juniper Mist, Cisco needs to do a little bit more.
IPsec is a very old protocol, and sometimes it is good to see if there are some alternatives for VPNs in Cisco Secure Access.
I would like to see flexible access to the cloud in the next release to make it better. Currently, you set up one IPsec tunnel and that is all, which I think is not sufficient. There could be a better way, and what is missing are some virtualization services and security services in Cisco Secure Access cloud environment, especially for dedicated customers, such as governance and so on.
For how long have I used the solution?
I have been dealing with Cisco SD-WAN for ten to fifteen years.
How are customer service and support?
Technical support is perfect, and I find it fine. I would rate their support an eight out of ten.
There is still room for improvement when it comes to response time, especially if you need some response from the US. If you need support from the US side, you can see the different countries, and sometimes it takes very long to get an approval from the US side, which is something that could be better.
How was the initial setup?
The initial setup of Cisco Secure Access was not straightforward. There were a lot of discussions, especially with our customer about what the benefits are, particularly regarding the cost and the cost-benefits ratio, with discussions being more governance-driven or management-driven rather than technical, which meant it took a lot of time.
What's my experience with pricing, setup cost, and licensing?
In my experience with the Experience Insights feature or Digital Experience Monitoring of Cisco Secure Access, ThousandEyes is a fine tool, but currently, my experience with our customer is that it is too expensive just to have it. It is nice to have, but it is not business-critical, and therefore it is too expensive.
The overall pricing of Cisco Secure Access has changed dramatically in the last half year, and I would say it is too high.
I think Cisco should consider their licensing model, as anything could be improved.
What other advice do I have?
Currently, AI Supply Chain Risk Management is not really an issue for us today. I would rate Cisco Secure Access a seven out of ten overall.
Unified cloud security has simplified zero trust access and protected hybrid users
What is our primary use case?
My main use case for Cisco Secure Access is for one client, where I deployed DNS security. Previously, Cisco DNS security was part of Umbrella; now, it has been moved to Cisco Secure Access. I implemented DNS security, which provided the client with cloud-based DNS security and intelligent proxy features, so they are protected from day-zero attacks with policy management in place. That was one use case for Cisco Secure Access, and for another client, I have recently deployed ZTNA using Cisco Duo MFA.
For a specific example of how I used Cisco Secure Access for one of these clients, I will provide the example of one client where I deployed ZTNA through MFA. The client has around 1500 users working in a hybrid environment, so connecting every user on the VPN, whether hardware-hosted, VM-hosted, or anywhere else, causes unnecessary burden. SASE is the best use case of Cisco Secure Access in the hybrid environment, where if users want to access any of their private applications, they connect to Cisco Secure Cloud. From the cloud, the traffic is tunneled, providing zero-trust access and requiring MFA to access any internal application. This way, since it is cloud-based security, the routing and everything is taken care of in the cloud, avoiding dependency on hardware infrastructure or overusing the link in the data center itself.
What is most valuable?
The best feature that Cisco Secure Access offers is a single platform where DNS security, ZTNA, and everything are in one place, all managed through a single cloud dashboard.
Having everything in a single platform and dashboard has made things easier for me and my clients because everything is available for checking or troubleshooting.
Cisco Secure Access has positively impacted my organization because we are Cisco preferred partners. We deploy everything for our clients, so it is not just about deploying it in our organization. Since we are a preferred partner, many clients requiring Cisco Secure Access are routed to us from Cisco.
After deploying Cisco Secure Access, I received specific positive outcomes and feedback from my clients. For the use case concerning DNS security over the last three months, their AD integration with Cisco Secure Access allows them to create user-based policies for DNS security based on identity and username. They also receive a dashboard to monitor reports on threats and everything online in the cloud. The customer is very happy that they are able to overview their organization, seeing the number of users utilizing maximum applications, the top talkers, and everything.
Cisco Secure Access has greatly impacted protecting my organization and clients from threats such as phishing and ransomware. Because it has ZTNA and is cloud-based with VMs deployed inside the network, it creates best practice tunnels required for accessing applications from day one. Thus, we can deploy with peace of mind without juggling best practices or opening only specific ports.
What needs improvement?
Cisco Secure Access can be improved by providing information about the location of the PoPs where users are connected. The guidelines in KSA say it is mandatory for the PoPs to be regional, similar to how Fortinet SASE discloses its PoP locations.
In terms of needed improvements around documentation and support, the documentation has been good for me. Since I deployed for the first time, I went through Cisco documents, which helped me a lot, and their program on the T-Cloud labs also provided great support. Completing the lab gave me the confidence to deploy for the customer. The documentation and the labs provided by Cisco are very good.
For how long have I used the solution?
I have been using Cisco Secure Access for the last six months.
What other advice do I have?
For others looking into using Cisco Secure Access, my advice is that it is a good solution and they should experience it.
I chose eight out of ten primarily due to only the PoP presence. I would rate the ease of managing Cisco Secure Access through its single cloud-managed console an eight.
In my experience, it is easy to navigate and manage everything from the console, but compared to the FortiGate SASE platform, FortiGate has a unified platform for all their products, while Cisco has each platform operating differently.
I use the Zero Trust Network Access (ZTNA) feature of Cisco Secure Access, and it is a great feature. We do not need to worry about the security of accessing applications from outside the environment. With ZTNA, each application access requires authentication, which is a truly great feature.
This ZTNA approach has positively changed my client's security posture, and there are no significant challenges or surprises. I rate this product eight out of ten.
Modern SSE-Based Secure Access That Speeds Up Work
User-Friendly with Strong Security but Session Timeout Frustrates
Dependable Security with Cost-Effective Flexibility
Ensures Compliance, Easy Setup, Needs Front-End Improvement
Consistent Secure Access Beyond VPN with Cisco Secure Access
The administration could also be more intuitive in some areas, and troubleshooting certain access issues can require digging through different settings and logs. For users, the experience is generally good, but there can occasionally be some confusion when access policies or security controls affect how they connect to specific resources. These are not major issues, but simplifying the management experience and making troubleshooting more straightforward would make the product even better.