Software Secure Access
Activity Manage

Cisco Secure Access Help Limitations and Range Limits Other Components

Last updated: Aug 07, 2025

Other Components

Feature Limit Description
Destination Lists A destination list is not active until you set an access rule that includes the destination list. Destination lists may contain fully qualified domain names (FQDN), URLs, or IP addresses.
A destination list's comment string can contain at most 256 characters.
A destination list does not support regular expressions in URL paths.
A destination list may include at most 5,000 destinations.
Bypass Domains No more than 2000 bypass domains may be added to Secure Access. The number of bypass domains can be increased upon request.
Internal Networks No more than 5000 internal networks may be added to Secure Access.
WebSockets and HTTP PATCH For WebSockets or HTTP PATCH requests, the Secure Access Secure Web Gateway does not perform file inspection.
File Transfer The maximum file size that the Secure Web Gateway (SWG) can upload is 20 GB.
File Download The maximum file size that can be downloaded is 5 GB, which applies only for access rules with the Isolate action. If the access rule does not specify the Isolate action, Secure Access will permit downloads of files greater than 5 GB. Secure Access scans the downloaded files.
Block Page Bypass You cannot use the Block Page Bypass feature with a redirected block page. If configured, Secure Access uses the default appearance of the block page.
Customer CA Signed Root Certificate Six certificates per organization.
File Scanning (Antivirus, Threat Grid, and AMP)
  • A file must be less than 50 MB.
  • Compressed file scanning supports no more than 16 levels of recursion.
  • AMP: The system computes only the archive hash, not hashes for files inside archives.