Multicloud Fabric Onboarding

 
Updated September 30, 2026
PDF
Is this helpful? Feedback

Multicloud Fabric Onboarding

Introduction

Multicloud Fabric is Cisco’s fully managed networking service for connecting site-to-cloud and cloud-to-cloud networks. It supports networks in AWS, Azure, and Google Cloud, as well as Meraki sites.

In Multicloud Fabric, you:

  1. Authorize cloud access for the cloud providers you use.

  2. Onboard the networks you want to include in the fabric.

  3. Choose which resources should communicate.

Multicloud Fabric then provisions the routing, tunnels, and policies needed to realize those connections. It simplifies multicloud networking by giving you a way to:

  • Discover and manage network resources.

  • Define specific connectivity between the resources you choose.

  • Monitor connection health and events, including event history, to help you investigate connectivity issues.

Rather than automatically connecting every onboarded network, Multicloud Fabric’s Zero Trust Routing capability distributes only the routes authorized by your connection choices.

Cloud account integration requirement

Your AWS, Azure, or Google Cloud environment is administered outside Multicloud Fabric. As a result, Multicloud Fabric needs an explicit, customer-authorized cloud identity to call the selected provider’s control-plane APIs for the approved scope. This authorization lets Multicloud Fabric discover your network inventory, as well as create and manage the Multicloud Fabric-owned cloud connectivity resources needed for integration.

What cloud account integration enables

Refer to this table for a description of what cloud account integration enables for Multicloud Fabric.

Enabled capability What Multicloud Fabric is authorized to do When it takes effect

Cloud discovery

Read the data required to show eligible resources in Multicloud Fabric, such as the authorized account, subscription, CIDR, and related inventory.

Initial discovery starts after the integration validates.

Network onboarding

Create and manage the connectivity resources for a selected network, such as the supported cloud-side VPN, gateway, and tunnel.

Only after you select a discovered network and submit onboarding.

Connections and route exchange

Use onboarded cloud networks as connection endpoints, and apply the explicit route-exchange intent.

Only after the endpoints are onboarded and you create a connection.

Operations and lifecycle

Correlate status for items such as integration, discovery, attachment, and events. Support approved update and offboarding workflows

As resources and operations exist, and only when you initiate the applicable lifecycle action.

Before you start

You need access to create or modify the required identity and access resources. Based on your company policies, you may need your IT or cloud administration team to provision these rights.

Refer to this table for a description of what you configure for your cloud account.

Provider Your scope Identity you configure How Multicloud Fabric uses it

AWS

Your AWS account

A cross-account IAM role ARN with the Multicloud Fabric principal and external ID in its trust relationship.

Multicloud Fabric assumes the role through AWS STS and validates the requested access.

Azure

Your Azure subscription

A Microsoft Entra service principal: Tenant ID, client/application ID, client secret, and the intended subscription role assignment.

Multicloud Fabric authenticates the service principal and validates Azure Resource Manager access.

Google Cloud

Your Google Cloud project or a supported parent scope

A service-account identity or material with the required IAM roles and enabled APIs.

Multicloud Fabric authenticates the service account and validates access to the selected Google Cloud scope.

Integration workflow

Complete these tasks to access and set up Multicloud Fabric for use:

  1. Onboard to Cisco Cloud Control. Refer to Cisco Cloud Control Getting Started.

  2. Activate your Multicloud Fabric trial subscription.

  3. Integrate your cloud service provider (CSP) account by completing the relevant procedure:

Activate your Multicloud Fabric trial subscription

Before you begin

  • You must be a Meraki organization administrator and use a Meraki identity to activate Multicloud Fabric for use.

  • Before accessing Multicloud Fabric, you must enable the Early Access API in the Meraki Dashboard:

    1. Select Organization > Early Access.

      activate-trial.jpg
    2. In Meraki Early Access Program, scroll down to the Early API Access section.

    3. Select the opt-in toggle to enable the API.
      For additional information, refer to this page.

Follow these steps to activate your trial subscription for Multicloud Fabric:

  1. Open Cisco Cloud Control and sign in with your existing Meraki credentials.

  2. Select app-launcher.jpg.

  3. Under Apps, select Multicloud Fabric.

    activate-trial1.jpg
    • If Multicloud Fabric is already enabled for you, Multicloud Fabric’s overview page opens and you should not be prompted to sign in a second time. Skip ahead to Step 7.

    • If you are not yet authorized to access Multicloud Fabric, a splash page opens.

      activate-trial2.jpg

      Proceed to Step 4.

  4. Select Start free trial.

  5. Complete these actions:

    1. Select the tenant you want to enable Multicloud Fabric for.
      If you have grouped tenants, select the single Meraki tenant in which you want to enable Multicloud Fabric.

    2. Review Multicloud Fabric’s terms and conditions.

    3. Check the check boxes.

    4. Type Subscribe, then select Confirm.

      activate-trial3.jpg

      After your access is enabled, the Welcome to Multicloud Fabric slider opens.

      activate-trial4.jpg
  6. Select Next to cycle through the slider’s screens, which describe Multicloud Fabric’s core features.

  7. In the last screen, select Onboard network to open Multicloud Fabric’s Overview.

Integrate an AWS account

Complete the AWS integration workflow to establish IAM access for Multicloud Fabric and provide the necessary role Amazon Resource Name (ARN).

  1. In Multicloud Fabric’s left navigation, select Cloud Access.

  2. Select Add cloud integration > AWS.
    Review access rights opens.

    connect-aws1.jpg
  3. Review the access rights that you are granting Multicloud Fabric, then select Next.
    Create IAM roles opens.

    connect-aws2.jpg
    note.svg

    For Beta, an IAM role is already configured, as well as the required permission and trust policies.


  4. In the trust policy, copy the role’s ARN (arn:aws:iam::xxxxxxxxxxxx:role/mcn-integrations-role) and then select Next.

    Amazon Resource Names (ARNs) opens.

    connect-aws3.jpg
  5. Paste the role’s ARN into Role ARN #1, then select Save.

Integrate an Azure account

The Azure integration workflow consists of these tasks:

note.svg

Azure VNets that are onboarded to Multicloud Fabric must not use or overlap the 10.254.0.0/16 address range. Multicloud Fabric’s Beta release reserves this range for internal IPsec tunnel addressing and BGP peering. If an Azure VNet’s address space overlaps this range, the VNet cannot be onboarded successfully. Choose a non-overlapping address range before onboarding.


Create an Azure gateway subnet

Before integrating Azure, create a gateway subnet in the Azure virtual network that Multicloud Fabric should attach to.

  1. In the Azure portal, search for and select virtual networks.

  2. In Virtual networks, select the virtual network you want to add a subnet to.

  3. In the left navigation, select Subnets.

  4. Select + Subnet.

  5. Enter this information for the subnet, then select Save:

    • Subnet purpose: enter Virtual Network Gateway

    • Name: enter GatewaySubnet

    • Include an IPv4 address space: select this option

    • IPv4 address range: enter the appropriate address range

    • Starting address: enter the range’s starting IP address

    • Size: enter a subnet size of /27 or larger

Multicloud Fabric relies on the GatewaySubnet name to select the correct attachment subnet. Multicloud Fabric does not automatically choose the subnet address range because that range must come from your Azure virtual network space.

Create a service principal

To create a service principal and grant access to subscriptions in Azure, complete these tasks:

Register a new application
  1. In the Azure portal, select Microsoft Entra ID.

  2. From the left navigation, select App registrations.

  3. Select New registration.

  4. Enter the application’s name.

  5. In Supported account types, select Accounts in this organization directory only (Default Directory only - Single tenant).

  6. Select Register.

Create a client secret
  1. In the Azure portal, select Manage > Certificates & secrets > Client secrets.

  2. Select New Client Secret.

  3. In Add a client secret:

    1. Enter a description for the secret.

    2. Set how long the secret will be valid.

    3. Select Add.
      Make sure to record the secret’s value.

Add a role assignment to a subscription
  1. From the left navigation, select Access control (IAM).

  2. Select Add > Add role assignment.

  3. In Job function roles, select Network Contributor, and then select Next.

  4. Select Members.

  5. In Assign access to, select User, group, or service principal.

  6. Choose Select members.

  7. Select the application you created previously, and then choose Save.

  8. Select Next.

  9. Select Review + assign, and then select Review + assign.

Connect an Azure subscription to Multicloud Fabric

Complete the Azure integration workflow to provide service principal credentials to Multicloud Fabric and grant Multicloud Fabric access to the Azure subscriptions that it should connect to.

  1. In Multicloud Fabric’s left navigation, select Cloud Access.

  2. Select Add cloud integration > Azure.
    Access rights opens.

    connect-azure1.jpg
  3. Review the access rights that you are granting Multicloud Fabric, then select Next.
    Configure access to Azure subscriptions opens.

    connect-azure2.jpg
  4. Enter this information, then select Next:

    • Your Azure tenant’s ID and client ID (in the Azure portal, select Overview to view these values)

    • Your application’s client secret (in the Azure portal, select Manage > Certificates & secrets > Client secrets).

      Confirm subscriptions opens.

      connect-azure3.jpg
  5. Confirm that the subscriptions configured for your Azure account are displayed. Then select Save.

Integrate a Google Cloud account

To onboard a Google Cloud account, complete these tasks:

Create a service account

  1. In your Google Cloud project, ensure these APIs are enabled:

    • Compute Engine API

    • Cloud Resource Manager API

    • Logs API

  2. Sign in to the Google Cloud console and select Identity & Access > Service Accounts.

  3. Select Create project.

  4. Enter a service account name and description, then select Create and continue.
    The Google Cloud console generates a service account ID based on the name you enter. If you need to, change the ID. You will not be able to do so later.

  5. Set these permissions:

    • Logs Viewer

    • Network Administrator

    • Viewer

  6. Select Continue, then select Done.

Generate a JSON key

  1. In Identity & Access > Service Accounts, select gcp-options.jpg > Manage keys.

  2. Select Add key > Create new key.

  3. Ensure JSON is set as the key type, then select Create.

  4. Download a copy of the JSON file.

Connect a Google Cloud account to Multicloud Fabric

  1. In Multicloud Fabric’s left navigation, select Cloud Access.

  2. Select Add cloud integration > Google Cloud.
    Review access rights opens.

    connect-google1.jpg
  3. Review the access rights that you are granting Multicloud Fabric, then select Next.
    Configure access to Google projects opens.

    connect-google2.jpg
  4. Complete these tasks, then select Next.

    1. Set Single Project Discovery as the discovery scope.

    2. In Create a service account, drag the JSON key you created previously.
      Confirm projects opens.

      connect-google4.jpg
  5. Confirm that the projects configured for your Google Cloud account are displayed. Then select Save.

Verify cloud access in your provider console

If an integration does not validate, or if you want to confirm the configured scope, compare the values shown in your provider console against those in Cloud Access.

AWS

  1. In AWS, select AWS Console > IAM > Roles.

  2. Select the same role that is shown in Cloud Access.

  3. In Trust relationships, confirm that the Multicloud Fabric principal and external ID match the values presented by Multicloud Fabric.

  4. In Permissions, confirm that the attached or inline policy corresponds to the access rights you selected.

Azure

  1. In the Azure portal, select Subscriptions.

  2. Select the target subscription.

  3. Select Access control (IAM) > Role assignments or Check access.

  4. Select the Multicloud Fabric service principal.

  5. Compare the subscription, tenant, client/application ID, role, and assignment scope values with those provided in Cloud Access.

  6. Select Microsoft Entra ID > App registrations to confirm application identity and secret expiry.

Google Cloud

  1. In the Google Cloud console, select the target project.

  2. View these pages:

    • Select IAM & Admin > IAM to confirm the service-account principal and roles.

    • Select IAM & Admin > Service Accounts to confirm the service-account email and key status.

    • Select APIs & Services > Enabled APIs & services to confirm that the required APIs are enabled.

  3. Compare the project ID and service-account identity with the values displayed in Cloud Access.

Access provider console information

Refer to these pages for more information about verifying cloud access in your provider’s console:

Manage cloud account integrations

View cloud account details

From the details page for a cloud account that has been integrated with Multicloud Fabric, you can:

To open a cloud account’s details page, select its link in Cloud Access. You can also select ellipsis.jpg > See details.

cloud-account-details.jpg

Update cloud account access credentials

Follow these steps to update the access credentials for either an Azure or Google Cloud account.

  1. Select Cloud Access.

  2. Select the account whose access credentials you want to update to open its details page.

  3. Select Edit > Rotate credentials.

  4. Update the account’s credentials:

    • For an Azure account, enter the new client secret.

    • For a Google Cloud account, upload the new service account key (.json).

  5. Select Save.

Disconnect a cloud account

Follow these steps if you need to disconnect a cloud account that has been integrated with Multicloud Fabric.

  1. Select Cloud Access.

  2. Select the account you want to disconnect to open its details page.

  3. Select Disconnect.

    disconnect-cloud-account.jpg
  4. In Disconnect integration:

    1. Select Remove for every VPC or VNet that was onboarded with this account.
      You will not be able to disconnect the account without doing this first.

    2. Select Disconnect.

Three components comprise Multicloud Fabric’s UI:

Overview

Overview serves as the starting point for your Multicloud Fabric session:

  • Scan the tiles at the top of this page to quickly determine the status of the connections, Multicloud Fabric regions, sites, and VPCs that are managed by Multicloud Fabric.

  • Select Onboard network to initiate the onboarding workflow for new VPCs/VNets and Meraki networks.

  • Select Connect resources to connect cloud resources and sites.

  • Select Connections, Sites, or VPCs to view the items that have been configured for these categories and manage them.

networking-overview.jpg

Cloud Access

In Cloud Access, you can view the cloud accounts that have been onboarded with Multicloud Fabric. From here, you can:

cloud-access.jpg

Event Log

The Event Log lists all the events that have taken place in your Multicloud Fabric environment over the time period you specify. From here, you can:

  • View the chart to quickly identify times where there has been more activity than usual.

  • Select an event to view its details.

event-log.jpg

Access Multicloud Fabric pages

The navigation paths for Multicloud Fabric pages vary slightly, depending on whether you are a North American customer accessing Multicloud Fabric through Cisco Cloud Control or a European customer accessing Multicloud Fabric through the Meraki Dashboard. The available functionality is identical in both.

Cisco Cloud Control (North American customers)

  1. In the Cisco Cloud Control top navigation bar, select app-launcher.jpg.

  2. Under Apps, select Multicloud Fabric.

  3. From the left navigation, select Overview, Cloud Access, or Event Log to open the corresponding page.

Meraki Dashboard (European customers)

  1. From the left navigation, select WAN & Cloud.

  2. Select Overview, Cloud Access, or Event Log to open the corresponding page.

Subscription and usage management

Multicloud Fabric pricing

Multicloud Fabric uses a consumption-based pricing model that is tracked through drawdown PIDs. This model mirrors cloud-native billing, so your costs align precisely with your infrastructure usage.

Subscription models

Two subscription models are available:

  • MCF-UNCOMMITTED: A pay-as-you-go option suited for variable usage, or for cases where an upfront commitment is not feasible.

  • MCF-COMMITTED: A subscription suited for cases where usage can be estimated in advance and higher discounts are desirable. This option requires an upfront commitment of at least $10,000, which is drawn down as usage is reported.

note.svg

You do not need to manage individual drawdown PIDs. The platform tracks usage automatically.


Usage calculation

Usage is calculated from the following meters:

  • Attachments: Billed per hour for each attached site, VPC, and Multicloud Fabric region.

  • Data transfer: Billed per GB. Refer to Data Transfer Charges for more information.

  • Premium services: Billed per service used, such as NAT and security service chaining.

Data transfer charges

Data transfer is priced according to a rate table that varies by cloud provider and by the direction of egress. Charges apply to traffic sent:

  • Across availability zones

  • Across regions

  • Across clouds or to the internet (internet-out)

Ingress to a cloud is never billed, so you pay only for outbound traffic and service usage. This transparent, consumption-driven structure lets you align networking spend with your organization’s multicloud traffic patterns.

Usage guidelines and limitations

  • Non-production policy: The public Beta is strictly for non-production evaluation. You must not use production data or production workloads.

  • Spend cap: The trial includes up to $5,000 in usage, calculated using undiscounted list prices. Usage includes data transfer costs, attachment costs, and Multicloud Fabric-region activation costs. Access is disabled when this limit is reached. All connections are disabled, and Multicloud Fabric-routed traffic is stopped. However, your configuration settings are preserved.

  • Usage warnings:

    • Threshold notifications: A notification appears when usage reaches 50% ($2,500) and again at 90% ($4,500) of the usage limit. The 90% notification reappears after each login until you dismiss it.

    • Usage visibility: Notifications are the only indicator of consumption. The dashboard displays a warning banner when a usage threshold is crossed, but it does not display your actual dollar amount of usage.

    • End-of-program warnings: Warnings begin two weeks before the public Beta ends and include a daily countdown until the program concludes.

General Availability transition

  • Retirement: The public Beta program will end when Multicloud Fabric achieves General Availability (GA) in November 2026.

  • Commercial conversion: At GA, free trial access is disabled. You can transition to commercial access by purchasing a license through Cisco Commerce Workspace (CCW) or a supported CSP marketplace.

  • License claiming: To claim your Multicloud Fabric license:

    1. With Multicloud Fabric open, select Subscription in the left navigation.

    2. Select Claim license key.

    3. Enter the key for your organization or tenant.
      A valid claim replaces free trial access with commercial access.

  • Retention window: After GA, Beta environments and connection settings are retained for 30 days. A valid claim within this window restores your previous Multicloud Fabric connection configuration. If no claim is made by the 30-day deadline, all retained Beta environments and settings are deleted.

    note.svg

    To move Beta network configurations to a commercial subscription, you must complete the standard license claim process.