Software Secure Access
Activity Manage

Cisco Secure Access Help Traffic Steering for Zero Trust Access Client-Based Connections Best Practices

Last updated: Aug 07, 2025

Best Practices

In general, you should not add destinations directly to the Zero Trust traffic steering page. Instead, add a Private Resource. For more information, see Add a Private Resource.

  • The private resource address to edit must be configured as a wildcard fully-qualified domain name (FQDN).

  • You should not edit entries on the zero-trust traffic steering page, except for the following purpose:

    Edit entries on the Zero Trust traffic steering page if you have configured the access address for a Private Resource as a wildcard FQDN of the format *.example.com and you want to exclude specified subdomains from Client-based ZTA. For example, you might want to exclude your company's public URL, www.example.com, from Zero Trust Access.

    For instructions, see Using Wildcards to Configure Traffic Steering for Private Destinations.