Cisco Smart Switches Configuration Guide for DPU Security Mode, Release 10.6(x)

PDF

Cisco Smart Switches Configuration Guide for DPU Security Mode, Release 10.6(x)

About this content

This guide describes the DPU security mode, which enables Smart Switches to provide distributed, stateful Layer-4 segmentation and security enforcement using embedded Data Processing Units (DPUs). These switches integrate Hypershield technology to enforce security policies at line rate, embedding security functions directly into the network infrastructure without requiring additional hardware.


What's changed in this book

This table summarizes the new and changed features in this guide for Release 10.6(x) and provides links to the sections where they are documented.

Feature Description Changed in Release Where Documented

DPU Security enablement – feature service acceleration

Allows you to power up the DPUs on the N9300 Smart Switches by enabling feature service acceleration

10.6(3s)F

Onboarding and Security Enablement

Network security operations

An exclusive admin role for the DPU security mode on N9300 Smart Switches

10.6(3s)F

User Accounts and RBAC

VRF redirection and VLAN redirection

Supports VLAN-based bridged traffic redirection and VRF-based routed traffic redirection to the DPU providing Layer 3 and Layer 4 inspection.

10.6(3s)F

Configure Traffic redirection to firewall service

Traffic inspection and integration with VXLAN

Integrates traffic inspection seamlessly with VXLAN overlays and traditional VLAN/VRF configurations, leveraging DPUs for hardware-accelerated security features within the switch.

10.6(3s)F

Traffic inspection with Smart Switches in VXLAN EVPN fabric

Inter-VRF Traffic Inspection

Inspects traffic in the DPU between sources and destinations in different VRFs; supported by symmetric hashing mode only.

10.6(3s)F

Inter-VRF Traffic Inspection

Layer 2 isolation for micro-segmentation

Allows routing of the same-subnet IPv4 traffic through security inspection using receive-only VLAN mapping, Layer 2 isolation on a service VLAN, and enhanced local Proxy ARP.

10.6(3s)F

Layer 2 Isolation for Micro-segmentation

High Availability

Ensures that the services remain available for both bridged and routed traffic during switch or DPU failure or outage.

10.6(3s)F

High Availability and Redundancy

Smart Switches

Defines the N9300 Smart Switch architecture, in which the NPU handles routing and switching while DPUs provide Hypershield-managed traffic filtering and also describes how Service-Ethernet ports connect the NPU and DPUs to support traffic inspection and forwarding.

User Accounts and RBAC for Smart Switches

Defines the N9300 Smart Switch operating modes, user roles, and privileged commands for managing and troubleshooting DPUs and the Hypershield Agent.

Onboarding and Security Enablement

Guides you through configuring the Hypershield Controller, enabling DPU service acceleration, onboarding Smart Switches, redirecting traffic, and activating firewall-based security inspection.

Inter-VRF Traffic Inspection

Describes how to configure and verify inter-VRF traffic inspection by leaking routes between VRFs and redirecting traffic to DPUs for firewall inspection, with symmetric hashing required.

Traffic Inspection with Smart Switches in VXLAN EVPN Fabric

Describes VXLAN EVPN traffic inspection on N9300 Smart Switches, including VTEP-based inspection and limitations when the default VRF is configured as a service VRF.

Layer 2 isolation for micro-segmentation

Provides concepts, topology, requirements, configuration tasks, and verification commands for directing same-subnet IPv4 traffic through firewall inspection by using local-proxy ARP and Layer 2 isolation.

High Availability and Redundancy

Ensures service continuity for bridged and routed traffic by synchronizing firewall states between two identical, redundantly connected Smart Switches. If a failure or service outage occurs, the system automatically deflects traffic to the healthy peer to maintain stateful inspection and network operation.