{"id":12572,"date":"2024-05-24T03:03:54","date_gmt":"2024-05-24T03:03:54","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/demystifying-multicloud-networking-with-cisco-multicloud-defense\/"},"modified":"2024-05-24T03:03:54","modified_gmt":"2024-05-24T03:03:54","slug":"demystifying-multicloud-networking-with-cisco-multicloud-defense","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/demystifying-multicloud-networking-with-cisco-multicloud-defense\/","title":{"rendered":"Demystifying Multicloud Networking with Cisco Multicloud Defense"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p>In today\u2019s modern IT environment, most organizations leverage both the public cloud and private data center to house critical business applications. In many cases, these applications require communication with other applications to execute a particular need for the business. A common challenge among the customers I have spoken with is that they have applications in one environment that need to talk to applications in another environment, but they don\u2019t want to send that data directly over the internet.<\/p>\n<p>I don\u2019t blame them\u2014 enterprises want to minimize their internet exposure as much as possible, hiding internal apps away from the internet.<\/p>\n<p>Traditionally, organizations have leaned on dedicated connection (or cloud-native) services like AWS Direct Connect or Azure ExpressRoute to connect applications in the public cloud to the private data center. While these methods are high-speed options that facilitate connections between the public cloud and private data center, these connections are costly at scale, are not encrypted using IPsec, do not facilitate cloud-to-cloud connectivity, and require different configuration depending on the cloud environment.<\/p>\n<p>To solve these challenges, Cisco has released new multicloud networking capabilities enabling scalable, secure <strong>site-to-cloud<\/strong>\u00a0and <strong>cloud-to-cloud<\/strong> connectivity. These features use Cisco VPN code on the Multicloud Defense Egress Gateway and BGP routing for better connectivity across your cloud environment.<\/p>\n<figure id=\"attachment_457347\" aria-describedby=\"caption-attachment-457347\" style=\"width: 936px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-457347 size-full\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/ctfyvguybtycrtxer.png\" alt=\"\" width=\"936\" height=\"482\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/ctfyvguybtycrtxer.png 936w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/ctfyvguybtycrtxer-300x154.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/ctfyvguybtycrtxer-768x395.png 768w\" sizes=\"auto, (max-width: 936px) 100vw, 936px\"\/><figcaption id=\"caption-attachment-457347\" class=\"wp-caption-text\">Figure 1: Applications are deployed everywhere<\/figcaption><\/figure>\n<h2><strong><span style=\"color: #6abf4b;\">Why Multicloud Networking?<\/span><\/strong><\/h2>\n<p>Customers can leverage multicloud networking from Cisco to build highly secure connections between applications and environments using a simplified architecture and workflow. This means organizations can easily connect applications from one environment to another at scale while also keeping operations in house to reduce cost. Our multicloud networking capabilities use widely adopted route-based VPN and BGP routing for secure connections and automated network advertisements. These multicloud networking capabilities can be described as:<\/p>\n<ul>\n<li><strong>Site-to-cloud networking:<\/strong> Secure connectivity between the data center and the cloud<\/li>\n<li><strong>Cloud-to-cloud networking:<\/strong> Secure connectivity between clouds<\/li>\n<\/ul>\n<h2><strong><span style=\"color: #6abf4b;\">A Closer Look<\/span><\/strong><\/h2>\n<p>To build site-to-cloud and cloud-to-cloud connections, customers would leverage Cisco Defense Orchestrator for establishing fully orchestrated and automated IPsec tunnels between environments. The platform uses BGP for optimized, resilient routing, allowing for the secure connection between the data center and the cloud (site-to-cloud) and between clouds (cloud-to-cloud).<\/p>\n<p>When building a site-to-cloud connection, customers would use Cisco Secure Firewall (either physical or virtual appliance) at the data center edge and a Multicloud Defense Gateway at the cloud edge for the beginning and the end of the connection. For multicloud deployments that require cloud-to-cloud connectivity, multiple Multicloud Defense Gateways would be used. Site-to-cloud and cloud-to-cloud networking capabilities can be supported in both <strong>centralized<\/strong> and <strong>distributed<\/strong> security models.<\/p>\n<p>The Multicloud Defense Gateway is based on a single-pass architecture and includes VPN code embedded in the data path pipeline. This enables direct termination of route-based IPsec VPN on the egress gateway. Route-based VPN is used with BGP routing for an automated CIDR advertisement. As soon as the IPsec tunnel is terminated on the egress gateway it advertises and learns all the networks using BGP, enabling automated traffic steering.<\/p>\n<figure id=\"attachment_457348\" aria-describedby=\"caption-attachment-457348\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-457348 size-large\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/fcghgvhjbxrte-1024x394.png\" alt=\"\" width=\"640\" height=\"246\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/fcghgvhjbxrte-1024x394.png 1024w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/fcghgvhjbxrte-300x115.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/fcghgvhjbxrte-768x295.png 768w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/fcghgvhjbxrte.png 1430w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><figcaption id=\"caption-attachment-457348\" class=\"wp-caption-text\">Figure 2: Multicloud Networking<\/figcaption><\/figure>\n<h2><strong><span style=\"color: #6abf4b;\">Site-to-cloud Networking<\/span><\/strong><\/h2>\n<p>Cisco Multicloud Defense and Cisco Defense Orchestrator provide an automated way to build highly secure, full-automated VPN tunnels between data centers and cloud environments.<\/p>\n<figure id=\"attachment_457349\" aria-describedby=\"caption-attachment-457349\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-large wp-image-457349\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfyvgubhivucyrtx-1024x446.png\" alt=\"\" width=\"640\" height=\"279\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfyvgubhivucyrtx-1024x446.png 1024w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfyvgubhivucyrtx-300x131.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfyvgubhivucyrtx-768x335.png 768w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfyvgubhivucyrtx.png 1430w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><figcaption id=\"caption-attachment-457349\" class=\"wp-caption-text\">Figure 3: Site-to-cloud networking (centralized security model)<\/figcaption><\/figure>\n<p><em>Figure 3<\/em> shows that on-premises Secure Firewall appliances (physical or virtual) are managed by Cisco Defense Orchestrator and the Multicloud Defense egress gateways are managed by the Multicloud Defense Controller.<\/p>\n<p>Cisco Defense Orchestrator orchestrates VPN configuration on the on-premises firewalls as well as talks to the Cisco Multicloud Defense Controller using APIs. This API communication between Cisco Defense Orchestrator and the Multicloud Defense Controller enables the orchestration of VPN configuration on the Multicloud Defense egress gateway(s). This approach provides customers with fully orchestrated secure IPsec connections, enabling secure connectivity between the data center and the cloud.<\/p>\n<figure id=\"attachment_457350\" aria-describedby=\"caption-attachment-457350\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-large wp-image-457350\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dfhgvjbhvgcfxd-1024x291.png\" alt=\"\" width=\"640\" height=\"182\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dfhgvjbhvgcfxd-1024x291.png 1024w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dfhgvjbhvgcfxd-300x85.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dfhgvjbhvgcfxd-768x218.png 768w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dfhgvjbhvgcfxd.png 1430w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><figcaption id=\"caption-attachment-457350\" class=\"wp-caption-text\">Figure 4: Site-to-cloud networking (distributed security model)<\/figcaption><\/figure>\n<p><em>Figure 4<\/em> shows how Cisco also supports site-to-cloud networking in a distributed security model using Cisco Defense Orchestrator, Secure Firewall, the Multicloud Defense Controller, and the Multicloud Defense egress gateway.<\/p>\n<h2><strong><span style=\"color: #6abf4b;\">Cloud-to-cloud Networking<\/span><\/strong><\/h2>\n<p>Cisco Multicloud Defense provides an automated way to build highly secure, full-automated VPN tunnels between cloud environments. IPsec tunnels are terminated on the Multicloud Defense egress gateways.<\/p>\n<figure id=\"attachment_457351\" aria-describedby=\"caption-attachment-457351\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-large wp-image-457351\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dxcgfhgvjfd-1024x428.png\" alt=\"\" width=\"640\" height=\"268\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dxcgfhgvjfd-1024x428.png 1024w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dxcgfhgvjfd-300x125.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dxcgfhgvjfd-768x321.png 768w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dxcgfhgvjfd.png 1430w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><figcaption id=\"caption-attachment-457351\" class=\"wp-caption-text\">Figure 5: Cloud-to-cloud networking (centralized security model)<\/figcaption><\/figure>\n<p><em>Figure 5 <\/em>shows the application VPC in AWS and the application VNet in Azure are protected using an egress gateway in the centralized deployment model. The Cisco Multicloud Defense Controller orchestrates IPsec VPN between egress gateways in Azure and AWS.<\/p>\n<figure id=\"attachment_457352\" aria-describedby=\"caption-attachment-457352\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-large wp-image-457352\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfvgbhvcyrxt-1024x236.png\" alt=\"\" width=\"640\" height=\"148\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfvgbhvcyrxt-1024x236.png 1024w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfvgbhvcyrxt-300x69.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfvgbhvcyrxt-768x177.png 768w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/cfvgbhvcyrxt.png 1430w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><figcaption id=\"caption-attachment-457352\" class=\"wp-caption-text\">Figure 6: Cloud-to-cloud networking (distributed security model)<\/figcaption><\/figure>\n<p><em>Figure 6<\/em> shows how Cisco also supports cloud-to-cloud networking in a distributed security model using Cisco Defense Orchestrator, the Multicloud Defense Controller, and multiple Multicloud Defense egress gateways.<\/p>\n<p>The new multicloud networking capabilities add fully orchestrated VPN tunnels where IPsec tunnels are formed between networks advertised in the BGP domain. In addition to secure connectivity, customers need a way to enable threat-centric policies between source and destination subnets. To solve this challenge, Cisco is enabling common security objects across on-premises Cisco firewalls and Multicloud Defense Gateways with the new <strong>Hybrid Segmentation<\/strong> feature.<\/p>\n<h2><strong><span style=\"color: #6abf4b;\">Hybrid Segmentation<\/span><\/strong><\/h2>\n<p>For the site-to-cloud connectivity use case, sharing network objects between Secure Firewall, Multicloud Defense, and Cisco Defense Orchestrator simplifies the hybrid segmentation policy creation process for administrators by pooling objects across into one centralized location. This reduces complexity, minimizes human error when creating new objects, and removes duplicative processes.<\/p>\n<h2><strong><span style=\"color: #6abf4b;\">Static object sharing<\/span><\/strong><\/h2>\n<p>Now static network objects can be shared between Cisco Multicloud Defense and the Cisco Defense Orchestrator.<\/p>\n<figure id=\"attachment_457354\" aria-describedby=\"caption-attachment-457354\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-large wp-image-457354\" src=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dcfgvjhbgvfxdz-1024x518.png\" alt=\"\" width=\"640\" height=\"324\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dcfgvjhbgvfxdz-1024x518.png 1024w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dcfgvjhbgvfxdz-300x152.png 300w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dcfgvjhbgvfxdz-768x389.png 768w, https:\/\/storage.googleapis.com\/blogs-images\/ciscoblogs\/1\/2024\/05\/dcfgvjhbgvfxdz.png 1430w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><figcaption id=\"caption-attachment-457354\" class=\"wp-caption-text\">Figure 7: Hybrid Segmentation (Static Object sharing)<\/figcaption><\/figure>\n<p>Figure 7 shows objects being shared between CDO and Multicloud Defense controller. Object <strong>\u201cdb\u201d <\/strong>is imported from the CDO and objects \u201capp1-aws\u201d &amp; \u201capp2-aws\u201d are automatically synchronized from the Cisco Multicloud Cloud Defense Controller.<\/p>\n<p>Now administrator can configure the following policies in CDO and the Multicloud Defense Controller:<\/p>\n<ul>\n<li>Policy on CDO and Multicloud Defense Controller: Allow app1-aws, app2-aws access to db<\/li>\n<\/ul>\n<p>In addition, to secure VPN connectivity features advanced threat security features can also be enabled on Multicloud Defense Egress Gateway.<\/p>\n<h2><strong><span style=\"color: #6abf4b;\">Conclusion<\/span><\/strong><\/h2>\n<p>Modern enterprises are becoming an increasingly complex spiderweb of connections between on-premises datacenters, branch locations, cloud VPCs, cloud regions, and cloud accounts. The traditional approach of doing direct connections between all the networks, or manually managing IPsec connectivity adds a lot of complexity. Cisco has brought together Cisco Defense Orchestrator, Secure Firewall, and Multicloud Defense to manage creating the connectivity across all the environments\u2014ensuring applications can reach the destinations they require. Through these capabilities, customers achieve greater control while reducing cost by bringing operations in-house. In addition to building secure connections, these solutions together also simplify policy creation for customers by way of network object sharing between environments\u2014reducing risk of human error when building policy and minimizing complexity across environments.<\/p>\n<p>If you would like to learn more about how Cisco is driving further innovation across Cisco Defense Orchestrator, Secure Firewall, and Multicloud Defense, be sure to stop by the Innovation Zone at Cisco Live US 2024 or reach out to your Cisco sales representative!<\/p>\n<h2><strong><span style=\"color: #6abf4b;\">Additional resources:<\/span><\/strong><\/h2>\n<p>Cisco Blog on Multicloud Defense Architecture<\/p>\n<p>Cisco Multicloud Webinar<\/p>\n<p>Cisco Multicloud Defense Whitepaper<\/p>\n<p>Cisco Multicloud Defense Website<\/p>\n<p>See how Cisco is leveraging Cisco Defense Orchestrator, Multicloud Defense, and Secure Firewall to securely connect apps from site to cloud and between clouds.<\/p>\n<hr\/>\n<p style=\"text-align: center;\"><em>We\u2019d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!<\/em><\/p>\n<p style=\"text-align: center;\"><strong>Cisco Security Social Channels<\/strong><\/p>\n<p style=\"text-align: center;\"><strong>Instagram<\/strong><br \/><strong>Facebook<\/strong><br \/><strong><a href=\"https:\/\/twitter.com\/CiscoSecure\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a><\/strong><br \/><strong>LinkedIn<\/strong><\/p>\n<p>Share:<\/p>\n<p>\n  \t<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async defer src=\"https:\/\/platform.instagram.com\/en_US\/embeds.js\"><\/script><br \/>\n<br \/><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In today\u2019s modern IT environment, most organizations leverage both the public cloud and private data center to house critical business applications. In many cases, these [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-12572","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/12572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=12572"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/12572\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/12573"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=12572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=12572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=12572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}