Software Secure Access
Activity Manage

Cisco Secure Access Help Network Tunnel Configuration Establish a Tunnel Client Reachable Prefixes

Last updated: Aug 07, 2025

Client Reachable Prefixes

Secure Access expects a private RFC 1918 address as the source IP for outbound packets. If you use non-RFC 1918 addresses, you can add them under Client Reachable Prefixes when configuring your tunnel. This overrides the default behavior, which allows all traffic destined for RFC 1918 addresses to return through the tunnel. For information about address allocation and private networks, see RFC 1918.

Secure Access supports the following options for client-reachable prefixes:

  • Static IP addresses, which must be globally unique in the customer org; i.e. no other network tunnel group can be configured with the same address.
  • BGP-based dynamic routing. BGP dynamic routing enables advertisement of self-service (private) network prefixes to physical network devices that support BGP such as routers, and removes the dependency on static routes.

Note: After updating client reachable prefixes for an established tunnel, wait at least five minutes, disconnect and shut down the tunnel for at least 10 seconds, and then reconnect the tunnel.