Software Secure Access
Activity Manage

Cisco Secure Access Help Network Requirements for Secure Access Secure Access SAML Identity Provider Domains

Last updated: Aug 07, 2025

Secure Access SAML Identity Provider Domains

Required by Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules, and Secure Access integrations with SAML identity providers (IdPs).

To enable connections to your SAML identity providers (IdPs), allow the following domains in your firewalls on ports 80 and 443 over TCP. Ensure that traffic to your SAML IdP is bypassed on the SWG to avoid an authentication loop. For more information, see Manage Domains.

Domain Ports/Protocols
ocsp.int-x3.letsencrypt.org 80/443 TCP
isrg.trustid.ocsp.identrust.com 80/443 TCP
*.cisco.com 80/443 TCP
*.opendns.com 80/443 TCP
*.umbrella.com 80/443 TCP
*.sse.com 80/443 TCP
*.okta.com 80/443 TCP
*.pingidentity.com 80/443 TCP
secure.aadcdn.microsoftonline-p.com 80/443 TCP