Cisco Smart Switches Configuration Guide for DPU Security Mode, Release 10.6(x)
Cisco Smart Switches Configuration Guide for DPU Security Mode, Release 10.6(x)
This guide describes the DPU security mode, which enables Smart Switches to provide distributed, stateful Layer-4 segmentation and security enforcement using embedded Data Processing Units (DPUs). These switches integrate Hypershield technology to enforce security policies at line rate, embedding security functions directly into the network infrastructure without requiring additional hardware.
This table summarizes the new and changed features in this guide for Release 10.6(x) and provides links to the sections where they are documented.
| Feature | Description | Changed in Release | Where Documented |
|---|---|---|---|
|
DPU Security enablement – feature service acceleration |
Allows you to power up the DPUs on the N9300 Smart Switches by enabling feature service acceleration |
10.6(3s)F |
Onboarding and Security Enablement |
|
Network security operations |
An exclusive admin role for the DPU security mode on N9300 Smart Switches |
10.6(3s)F |
|
|
VRF redirection and VLAN redirection |
Supports VLAN-based bridged traffic redirection and VRF-based routed traffic redirection to the DPU providing Layer 3 and Layer 4 inspection. |
10.6(3s)F |
|
|
Traffic inspection and integration with VXLAN |
Integrates traffic inspection seamlessly with VXLAN overlays and traditional VLAN/VRF configurations, leveraging DPUs for hardware-accelerated security features within the switch. |
10.6(3s)F |
|
|
Inter-VRF Traffic Inspection |
Inspects traffic in the DPU between sources and destinations in different VRFs; supported by symmetric hashing mode only. |
10.6(3s)F |
|
|
Layer 2 isolation for micro-segmentation |
Allows routing of the same-subnet IPv4 traffic through security inspection using receive-only VLAN mapping, Layer 2 isolation on a service VLAN, and enhanced local Proxy ARP. |
10.6(3s)F |
|
|
High Availability |
Ensures that the services remain available for both bridged and routed traffic during switch or DPU failure or outage. |
10.6(3s)F |
Defines the N9300 Smart Switch architecture, in which the NPU handles routing and switching while DPUs provide Hypershield-managed traffic filtering and also describes how Service-Ethernet ports connect the NPU and DPUs to support traffic inspection and forwarding.
Defines the N9300 Smart Switch operating modes, user roles, and privileged commands for managing and troubleshooting DPUs and the Hypershield Agent.
Guides you through configuring the Hypershield Controller, enabling DPU service acceleration, onboarding Smart Switches, redirecting traffic, and activating firewall-based security inspection.
Describes how to configure and verify inter-VRF traffic inspection by leaking routes between VRFs and redirecting traffic to DPUs for firewall inspection, with symmetric hashing required.
Describes VXLAN EVPN traffic inspection on N9300 Smart Switches, including VTEP-based inspection and limitations when the default VRF is configured as a service VRF.
Provides concepts, topology, requirements, configuration tasks, and verification commands for directing same-subnet IPv4 traffic through firewall inspection by using local-proxy ARP and Layer 2 isolation.
Ensures service continuity for bridged and routed traffic by synchronizing firewall states between two identical, redundantly connected Smart Switches. If a failure or service outage occurs, the system automatically deflects traffic to the healthy peer to maintain stateful inspection and network operation.