Secure Access SAML Identity Provider Domains
Required by Cisco Secure Client deployments with the Umbrella Roaming Security or Zero Trust modules, and Secure Access integrations with SAML identity providers (IdPs).
To enable connections to your SAML identity providers (IdPs), allow the following domains in your firewalls on ports 80 and 443 over TCP. Ensure that traffic to your SAML IdP is bypassed on the SWG to avoid an authentication loop. For more information, see Manage Domains.
Domain | Ports/Protocols |
---|---|
ocsp.int-x3.letsencrypt.org | 80/443 TCP |
isrg.trustid.ocsp.identrust.com | 80/443 TCP |
*.cisco.com | 80/443 TCP |
*.opendns.com | 80/443 TCP |
*.umbrella.com | 80/443 TCP |
*.sse.com | 80/443 TCP |
*.okta.com | 80/443 TCP |
*.pingidentity.com | 80/443 TCP |
secure.aadcdn.microsoftonline-p.com | 80/443 TCP |