Redefining Universal Zero Trust Network Access
In this session, Cisco covers Zero Trust Access accelerates zero trust access for all users, wherever they work and no matter where resources reside – powered by highly performant network access, modern identity security, and resilient architecture for “Five 9s” availability. One of the only SSE vendors to provide cross-platform identity context, Cisco enables IT teams to achieve zero trust maturity faster and with more resilient architecture.
Presented by Nitin Kumar, Manager, Technical Marketing Engineer. Recorded live at Tech Field Day Extra at Cisco Live EMEA 2025 in Amsterdam, Netherlands on February 12, 2025. Watch the entire presentation at https://techfieldday.com/appearance/cisco-presents-day-2-at-tech-field-day-extra-at-cisco-live-emea-2025/ or visit https://techfieldday.com/event/clemea25/ or https://Cisco.com/ for more information.
Transcript
Hey, folks. Uh, my name's Nin Kumar. I'm part of the cloud security, uh, group at Cisco, and we focus on a lot of different topics and technologies.
Specifically today, I wanted to talk about Universal Zero Trust access and, and how we're sort of approaching redefining it from a perspective of improving our own technology, but also how we're stitching together some of the solutions that we already own. Uh, so the, the, these can work more cohesively and to kind of set the stage on what we're doing and why we're doing it. We know that zero trust is required everywhere.
You know, you can't open an email or go to a, any web application without getting, uh, pinged with two F-A-M-F-A requirements, but it's obviously goes beyond that, right? We, we know this happens at the user level. Uh, there's ZTNA that's now implemented at the different locations that you're working out of, whether that's at home or in the office.
Uh, and then also this applies generally to apps, and that's what most people think of when we talk about Zero Trust. So, as customers have been adopting this over the last few years, we have this concept of legacy ZTNA, what we're calling universal ZTNA, because we're trying to apply this everywhere, uh, to really have that borderless network that, you know, a lot of companies have been promising. Um, but what we realized is that this only covers part of the picture, right?
Only some of the users are protected. Uh, they, we have to account for users that are now RTO coming back to the office. They're hybrid users.
How do we account for these users that are moving around in different places, right? We don't just have users that are in one static location anymore, uh, which is sort of what this middle box is talking about. And then there's this third thing around legacy applications.
So what do we do for these types of applications that are not ZTNA aware or simply that the customer's not ready to adopt? I just got out of a customer meeting just now where they said, look, we, we wanna do ZTNA, we're using VPN, but we're just not ready to migrate everything over. Uh, and we have to do this slowly, and we don't even know if some of our applications are ZTNA ready, like they have developers that have a lot of ZTNA, uh, or applications that they've developed themselves, but they don't know how to get around that.
So what we're doing is offering this in multiple layers. So one of the things, uh, our product does is provide VPN as a service to kind of provide a stop gap for that, where we're actually terminating VPN on behalf of the customer, and then they can slowly migrate over. And what that gives them is the user knows how to use VPN, right?
They may not necessarily know how to enable ZTNA, but they know how to use VPN and connect in, and then slowly that customer can then, uh, you know, migrate those applications over once they're aware. So that's what this sort of third bullet is about, you know, legacy applications and what to do. And we know that Universals ETNA can't meet the moment where it is, is right now.
We have to continue to develop ZTNA in general. What that means is we have to account for compounding challenges, like privacy mandates, user experience. As we're doing this, we don't want to inhibit the user from just doing their normal job, right?
If they open an email or they're starting to use generative AI to, to start prompting it for whatever, right? Getting writing documents and checking things. We don't want to hinder that activity.
But then we also need to provide business resilience as well. Like, how do we provide our end customers that are supporting their users? Some level of resiliency around this.
And some of it comes to making sure that policies are synced, making sure that there's not overlapping policies. Because when we talk about ZTNA, we're now stitching together all, all these different kind of solutions together. And it's sort of no surprise on how we got here, right?
If we look at the, the space that we're in right now, especially in security, it's fairly fragmented with all these different pieces. We have MFA to account for now, we're introducing ZTNA. VPN is sort of this legacy, legacy service that's been at the, you know, underpinning of application access.
Uh, we have our NAC SD WAN devices sitting at the edge, and then we have some things around, uh, you know, general security, I-P-S-C-A-S-B, and proxy and things like that. So I talked about some of the products that we're integrating and implementing as part of this universal ZTA story. Um, and that's really what we're doing to redefine it.
And what that means is we're taking different pieces of the Cisco technology stack, mainly Cisco Secure Access, which is our secure service Edge duo, and Cisco thousand Eyes, obviously our observability platform. And we're trying to stitch these products together in a cohesive way to kind of bring the, the customer along into adopting ZTNA, uh, but also not just cobbling things together, like doing real integration between all these three different products. So I'm gonna talk a little bit about, from a technology perspective, some of the things we're doing to meet all those challenges that I just talked about.
And, you know, obviously what we think is our advantage in general is sort of bringing all these use cases together. And at the bottom is some of the newer things we're introducing to help that customer adopt these services, like flexible enforcement, which I'll talk about. We've just done an integration with enterprise browser.
So Chrome has an enterprise browser where you can extend, uh, cap security capabilities. And this really, uh, goes well into our ZTNA sort of framework and story. And then there's been a rise of gen AI adoption, or just generally customers are not sure how to adopt it properly.
Like when I talk to customers about Gen Generat generative ai, usually the answer is, well, I'm just blocking everything, or I just don't have a, a great security posture and I don't know what to do with Gen ai. So we're introducing some guardrails for these customers to start safely adopting gen generative AI in very specific ways. And it goes beyond just doing, you know, DLP, like, don't put in credit card numbers into chat GPT.
And then we provide some things around policy assurance as well, like I mentioned, to make sure that policies are optimized. So the way we're doing this is in three main pillars. Uh, the first one is modernizing application access.
So Cisco Secure Access, and a lot of our different services are built on this modern PARP architecture and the underlying technology that's underneath that in terms of the transit from our client. So this is our Cisco Secure client into our data centers for processing, is masking quick protocols. So Quick was developed by Google some time ago.
Mask is a newer protocol that was introduced mainly for efficiency, and we're using, uh, vector Pro packet processing, which basically batches, uh, uh, packets together, um, for more efficient traffic flow, essentially, instead of doing sort of just relying on standard TCP for that. And Mask is also used by vendors like Apple. So if you open up your, you know, your Apple iPhone, you see that private relay option that's using mask technology to make sure that if you have that enabled for privacy reasons, you're not slowed down in general, right?
As you're browsing the internet, doing whatever. And then all of that is, is obviously funneled through and hits our cloud data centers. So all of our services are hosted in the cloud, but it's going through this entire optimized backbone.
And that's really what we're hanging our hat on in terms of making sure that we're providing super low latency and efficiently carrying that traffic all the way through the network for that customer. This o obviously applies to both internet and ZTNA based traffic as well. So I, I wanted to give a, a preview of something that we're doing to kind of help these customers on their journey and helped them adopt.
So I talked a little bit about VPN as a service is something that we offer, but we're also working on something for on-premises ZTNA enforcement, and I'll explain what that means. So this is a standard flow for us where you have your roaming users and we have resources that they can connect to. There's obviously a lot that goes into some, you know, these, these simple lines.
But essentially what we're doing is we're carrying that, that request for a private resource could be an AWS or Azure or like a private data center and user makes a request. We send it to our pop architecture that I showed earlier to our data centers, and then there's A-Z-T-A-Z-T-N-A proxy that's responsible for making the decisions and also making sure that the user's authorized, we authenticate that user, uh, to make sure they can access the resource, pretty standard flow that we have to deal with here. And then we have our standard flow around on-premises, right?
A user's inside of the network, they may not necessarily have the client enabled, that's fine. Uh, and they're able to access their resources, uh, just fine because they're, they're local to the network and there's less checks that we might have to do there. What we've introduced is this secondary ZTNA proxy that today lives inside of Cisco Secure Firewall and FTD.
And what we're doing is we're policy syncing what we've configured for ZTNA access in the cloud to the firewall. So what that actually provides the end user or customers is this second flow here. And a lot of our customers came to us and said, for privacy reasons, or for, for efficiency, we may in everything back to the Cisco Cloud.
So we're following this flow here, they have to go back to the cloud to get to this resource. We may have some resources that we need immediate access to without traversing to the internet and back down all the way around. So now we're going to define a flow inside of our dashboard where you can define private resource needs to go to my on-premises firewall directly, and then we can hit our resource and they'll get the same ZTNA experience as well where they're gonna be prompted, authorized, authenticated, and then we'll, we'll also provide posture at that time as well, regardless of what flow they're doing.
So check the operating system, is their disc encryption enabled? Is that user coming from a device that has, you know, the, the right level of browser? Are they using a preferred browser?
Do we want them to use Edge or Chrome or do we want them to use Firefox? So all of these things can be defined in the posture setting, and we can synchronize those as well. So, you know, super efficient way of being able to kind of bypass some of our own services if they really need to get to resources.
And that's one thing we're doing to kind of help these customers, uh, you know, efficiently connect to resources. And that's sort of what we're, what we're talking about. Yep.
You might have already mentioned it, but, uh, the roaming users, these are unmanaged devices, not like a consultant. They generally, these are going to be managed devices with Cisco Secure client. We do have an option in the Cisco secure access solution for unmanaged.
And I'll talk a little bit about that when we get to the Chrome section because it sort of extends our capabilities, but we have another option called clientless, ZTNA, which basically means if it's an unmanaged device and if it's a known user. So the user has to be a directory user for us to be able to authenticate that user and know that they can access an application. One sort of use case we're after for this is contractors or, uh, new user onboarding, right?
Like if Cisco acquired a new company, we're onboarding users quickly and we need to get them access to certain things in the, in the network, right? So what clientless TA provides our customers is the ability to, uh, publicly or publish A URL for that resource. We'll do this in the dashboard, and as soon as that user hits that URL, we'll go through our normal ZTNA flow at that point without needing the client.
So we address it in that way where we have some use cases for clientless or unmanaged access. And then when we talk about integrations with Chrome browser, as I mentioned, that even extends that further. And what we call that is unmanaged device managed browser where we can push out a, a browser profile to them to use, and then they're basically able to access through the same sort of flow for like different applications.
And then we can even apply security controls in the browser as well. Like you can't take screenshots or you can't print. There's some DLP specific settings that we can apply as well.
So we have some options through integrations and also in our native product as well for that. Interesting. Did that answer your question?
Yeah. Yeah. Cool.
So, you know, we're on this topic about trying to simplify application access. Cisco also released, uh, something called Cisco Security Cloud, which you can think of as an overall manager for accessing different types of Cisco security products. So if a customer's invested already in firewall and duo and thousand Eyes and maybe secure access, they'll have the ability to be able to access everything from a single dashboard over time.
We're also going to simplify policy administration. That's one thing we realize, especially when we're talking about syncing ZTNA policy and all those types of things, is we want them to do it in, in a single place and not have to jump around. I have a Question.
Yeah. How would this, uh, look like with CDO similar central? Yeah, so it's, you can think of it as, as sort of an evolution of what we're doing with CDO right now, right?
I think we, that's the direction we want to go is is CDO was sort of our defense orchestrator for security, and now we wanna sort of evolve this into Cisco Security Cloud as well, because this also ties into identity. And that's another piece that unfortunately we don't have time for today, but that's another piece that's in as a, as part of this as well. And digital sovereignty is going to be considered for those environments that are not allowed to do anything cloud, uh, say That in for what?
Digital Sovereignty. Um, So clouds It, it could be a consideration. I, I don't, I don't have an answer for that today, but I'm, I'm sure that might be something considered, especially when we're talking about regional access and you know, then we get in the conversation about RAC as well, who has access to control what systems and things like that.
Yep. So I know we're, you know, we've spent some time talking about ZTNA and how to give access to resources, but there's some extended challenges that we're seeing as customers are generally adopting, you know, security service edge products that include ZTNA, uh, which is around AI and how to manipulate and use ai. So I mentioned at the top that one of the things that we're working on, um, that's gonna be available very soon, is the ability to have better visibility and better control of sh what we call shadow AI inside of generative AI tools.
And what this provides us is the ability to view, uh, and understand generative AI prompts at a deeper level. So what this thing in the middle here around safety and compliance, for example, if someone is using CHATT PT for, and they're typing in things that may be related to self harm, or they're asking chatt PT or, or another generative AI tool, you know, how do I make a explosive device? Or something like that, right?
That won't necessarily be caught by standard DLP 'cause DLP, you're looking at PII credit card numbers, you know, am I-G-D-P-R compliant? Are there things that, you know, I need to do to ensure that my data's not being exfiltrated outside of my organization? This is more about, um, monitoring specific types of prompts and then doing enforcement.
And we call this AI guardrails. And this is a native integration, meaning you don't have to buy a separate product with, uh, Cisco AI defense, which is just newly launched. They have a whole AI hub, um, for that.
But that's essentially what we're doing there, is we have a deeper visibility, and then obviously we do apply DLP as well. So those examples that I just gave around, uh, P-I-I-P-C-I data. So if someone's, you know, trying to input something into, into a generative AI tool, uh, we can detect that.
We also detect things like source code. 'cause that's a big use case that's come up where we have developers putting source code into, you know, whatever chat GBT or Claude to try to verify their work. And then now that's part of your LLM, right?
And who knows who owns that data at that point. And now we have deep seek, which is a whole nother can of worms in terms of, you know, data privacy and things like that. So Just to distinguish a bit, your capabilities here, so you are doing not only that, you ident identified the AI sites based on the destination, URL mm-hmm.
Also can identify, then there is a text, uh, post field Yes. Where people can put into the DLP engine can control what people are putting into that. Then you can maybe also report on what has been exposed to ai, let's say, uh, text fields.
Yeah. Yeah. So we would monitor the, the prompts that the users are actually putting in versus just the response that we're getting back from the, the AI tool as well.
So we're doing it at two levels, basically. Yeah. From, from the technical perspective is just analyzing, uh, what the, the user is uploading, uh, attached that to a Gmail account, like, uh, Python, an AI prompt.
Yeah. We we can do that as well. Yeah.
We have the ability to do it on upload and download and not just for generative AIing. Yeah, for like any web destination that takes an upload like a Gmail or Webmail. And if that upload contains anything that violates a DLP policy, we can stop that in two ways.
We can do it in, in real time, or we can do it based on our API controls that we have. Are you able to distinguish if the user is, uh, using corporate AI versus the freeware, let me say consumer ai, for example, a corporate Yeah. Pilot.
So, um, I, I'm not exactly, I don't have an answer on whether we can do that with our AI defense capabilities today. We do have something to address that separately. It's called tenant controls, where, um, and unfortunately we don't have a regenerative AI today.
Um, it's probably something we're working on, but for platforms like Google Drive or Microsoft 365, we have the ability to apply a tenant control option where you can define the domains for your specific corporate tenants. Okay. And if someone is trying to use their own personal tenant, uh, we'll block them from doing that.
They're only allowed to to use the corporate tenant, and we're gonna f funnel them every single time into that tenant. Um, this comes up, especially when we're talking about things like data exfiltration, where if you're trying to copy stuff out of your corporate tenant into your personal Gmail or G drive, Google Drive, um, this is something that can prevent that from even happening. And if you don't have those guardrails, then you can do, we'll do DLP and prevent it at that layer as well.
So we have multiple layers, we can do protection. And last question to that, do you have already a predefined reporting or dashboard? So yes, our compliance people always want to know who has accessed what and so on.
So this is already in inside your Yeah. Your dashboard. Yeah.
Yeah. So we, we do have a full sort of data loss prevention dashboard. Um, I believe we're working on a compliance specific dashboard as well.
That's a, I know that's a big gas Company, just AI specific. Yeah, so the, the AI defense product does have compliance data that it reports back. I believe we, we are gonna implement that into the secure access implementation as well.
Um, but in general, I know getting visibility and auditing for compliance reasons and having possibly a separate view for that, definitely something we're thinking about, um, in general. And, um, if you said it's built into, um, secure access, so what kind of does it require, like just the general secure access or does it require advantage or like licensing one? So for DLP, uh, secure Access Advantage is the, is what it would require.
Okay. Yep. And then, um, I think you already mentioned it, but when it's for the guardrails, when, when it's, um, monitoring what people are putting in the problems mm-hmm.
Is it, um, blocking it or is it just, would it just notify if somebody's done something? So you'll see, uh, basically a response back as soon as it's blocked in real time. Okay.
Um, what we're working on right now is to notify the user if they have the Cisco Security client endpoint. Um, so it doesn't look as jarring, right? Because if you're blocked from a gen of AI tool, it's hard, you know, you're not gonna get a nice rendered block page.
What we do do today is we can send the user an end user notification for like DLP violations, for example. So if they see something like that, then at least the end user knows that they got an email for a DLP violation, right? Um, and then again, we're working on ways to do that, the endpoint.
So right away they get an alert that says, Hey, you've violated something, or you've, you know, you've done something at the AI level that is not appropriate. And then my other question is awareness material wise. Um, I would, I was in a presentation yesterday where they were talking about, uh, identity intelligence, and they were sharing how they could share, um, some, uh, awareness videos of how, why you, why you were blocked from something, what action behavior we're doing.
Um, is this something that for that maybe coming, if they're blocked, we could then send them awareness materials? Yeah. So we are working on an integration with, uh, the, uh, identity intelligence team, uh, into secure access.
So I think as we evolve and sort of keep developing and stitch that together as part of this mm-hmm. That's something that, that may be available, but I know we're working on that as well. Yeah.
Cool. Thanks for the questions. Um, I talked about some of the extended integrations we're doing in general.
Uh, so I, you know, I talked a little bit about Chrome Enterprise browser. Uh, again, this extends our capabilities. Our question around, you know, what do we do for unmanaged devices?
This is one way we can extend our overall security posture by leveraging Chrome Enterprise browser integration directly into secure access. And then I also mentioned, because we use mask protocol, uh, this is something that Native OS already has, so we can leverage some of the, the underlying technology that Apple and Cisco have in common, um, to be able to support, you know, these things. And, and Samsung also is, is leveraging these protocols, um, uh, as well Works also on chromium based, uh, yes.
Yes. Okay. So, Yep.
Uh, this is just slideshow now, I'll skip that because we kind of already talked through this. And this is more or less sort of a flow on, uh, what I explained earlier around different enforcement points. So if we have customers that have our managing Chrome browser, which is fairly common, um, they can go through this sort of managed device flow.
Again, Cisco Secret client would be installed because it's a managed device, the browser is managed. Now we get all of these extended capabilities that Chrome Enterprise browser gives us, like a print control, screenshot, capture controls, uh, maybe some local DLP policy that you can apply at the browser level, and then also apply all of the capabilities that we provide, uh, at the Cisco secure access level that I talked about. DLP, you know, we do have a proxy service as well where you can do sort of more sophisticated filtering, uh, and then the unmanaged use case, you can leverage the Cisco secure access clientless, ZTNA, and then also extend your security footprint using Chrome Enterprise browser.
And we're gonna continue to do deeper integrations. Uh, some of the work we're doing is we're obviously are not locked, going to be locked in with Chrome. We wanna expand that out to other enterprise browsers that are in, in the market right now as well, and make a, a little bit more agnostic so we can support whatever the customer has, right?
Whether that's Edge for enterprise, you know, in the future, if they bring browsers like Island that are very specific to enterprise use cases, uh, things like that. So kind of the model is I'm a managed client, I have access to everything my user's entitled to, so it could be multiple apps or the unmanaged one. I have kind of the burden that I need to expose in URL for each app so that the unmanaged, uh, accesses, uh, can happen via that URL.
Yeah. For now, yes, because we, they have to know what published URL to go to. Now if we're, if we're using the unmanaged browser, but managed profile use case where we would, you know, try to, to have them use a specific profile, like if they're a contractor, we can present things in the form of tiles or, or make a little bit more user friendly, uh, for that contractor or end user that's unmanaged, so they know exactly where to click into, uh, and get to the resource.
So we'll try to, you know, we can make a little bit more seamless that way, but for now, they, you know, there would have to be exposed to, to some URL to access to get to the application. And they're exposing in the DNS, the platform is taking care of that, or the user will have to have an external DNS where they can Yeah, It, it, it's gonna work generally like any request over the internet. Okay.
Yeah. At the end of the day, it's, it's traversing, it's egressing from their device out to whatever edge they have out to the internet, then to our cloud, then our cloud knows what to do because we see a request, uh, and we kick off a whole, uh, reverse CTNA process where we're authenticating the user and making sure they can access the application. Um, but it will, they don't have to do anything additional on their machine for that.
Which type of growth protocols are supported through the Chrome Enterprise plugin For Chrome? I, I I, beyond TCP? I'm not sure if what other protocols they support.
Um, obviously quick is the other one that I know about. Um, no, No, I mean, which type of application, uh, which type of protocol I can reach the application only, uh, web-based. Oh, So yeah, for secure access, we, so originally it was, uh, you know, web-based TCP based applications.
We're now supporting SSH and RDP as well. Okay. In terms of other services that we support.
So even at the CLIENTLESS level, if you're trying to access something through SSH or RDP, that's something we'll support as well. Yep. Cool.
So, um, you know, the, another pillar that we have, and we've sort of had some of this in our conversation around identity as well, which is obviously very important to this whole journey of Universal Zero Trust. We have to know who that user is, and we have to, it has to come from a trusted source, but it doesn't stop there. We know that there are other things in your network besides users that we need to provide some level of, uh, segmentation for and access for.
So one example of this is an integration we're doing with Cisco ice, where ICE will give us essentially what we call security group tags. And so think of these as tags for users and devices like a set of HVAC or cameras, printers, any IT or OT devices. All of these can be tagged sent through to secure access, and we can use those security group tags inside of our policy.
And what that gives us is very granular, fine-grain policy policy and, and all, you know, accomplishing some level of segmentation as well. It's like, one example I use is, you know, if we have a factory that is responsible for, you know, making car parts and they have a security group tag for robotic arms and they have a contractor, third party contractor that's responsible for maintaining those robotic arms, then through this we can tag those devices and then we can create a policy and secure access to say my contractor users are only allowed to access through these specific security group tags, uh, the iot specific applications only. So if they're, if they're access to my intranet, they can only access the IOT specific apps and nothing else, they're sort of segmented off in the rest of the network, right?
So we're providing some layer of security and, uh, segmentation there. And this is just sort of talking about some of the things we're doing in the future. Uh, and I, I tease this a little bit in terms of what we're doing with sharing context and sharing some of the, the synchronization between our different products.
So just know that we'll be able to support this across multiple domains where we can share context between SD WAN if the customer has it, our SSC firewall, et cetera, and then use that same level location that what I just described, you know, across all destinations essentially. And I know we're towards the end here, um, I'll sort of leave this, but essentially we do have the ability to kind of extend resiliency from a deployment perspective. So we obviously do have an integration today with our SD-WAN solution, and that's essentially what we're bringing together to create SSE, it's our SD-WAN networking components with all of the SSE components that I talked about and the sort of close out, you know, when we talk about building resiliency, we're also talking about how does a customer maintain, uh, resiliency in monitoring the efficiency of their users.
And this is something we've built into the solution using Cisco thousand eyes. So this is like that last product that I included in that first bullet where we're providing end-to-end visibility from the client all the way to the destination. And we can provide remediation and visibility if there are issues anywhere in this path, right?
If we see a spike in the CPU, if we see that the user's having issues accessing a SaaS app, we have what we call synthetic tests that we've built to do that for private resources as well. Not just accessing Salesforce, but if there's a custom application they're having issues accessing, we can do an end-to-end test in real time and say, look, the problem is at the network, the problem is at the user, or somewhere in between, right? So it gives that customer really deep visibility, uh, into that.
And this, the capability is called digital experience monitoring that's built into our secure access product. Um, that was really it. We have some great announcements at Cisco Live EMEA that we're, we've been talking about.
You know, I talked about enterprise browser, some of the flexible enforcement that we're using. We went to a little bit of the guardrails as well. And then some of the, the ways we're leveraging our own ai, not just the generative ai, but our own AI models for policy assurance, verifying policy overlap, things like that.
Okay.