Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

About this content

Learn how to set up, manage, and secure cloud environments with Cisco Multicloud Defense.


About Multicloud Defense

Learn about Multicloud Defense and the cloud security capabilities it provides for connected cloud environments.

Setup with the Multicloud Defense Wizard

Learn how to use the Multicloud Defense Wizard to set up cloud security for your environment.

AWS

Learn how to connect and manage AWS accounts in Multicloud Defense to protect AWS cloud environments.

Azure

Explains the range of services provided by Azure and key attributes that differentiate them.

GCP

Explains key attributes and offerings of Google Cloud Platform as a cloud service.

OCI

Learn how to connect and manage OCI accounts in Multicloud Defense to protect Oracle Cloud Infrastructure environments.

Remove a Cloud Service Provider From Multicloud Defense

Clean up the Multicloud Defense instance to remove cloud service providers, gateways, delete gateways, subnets, VNets, and remove permissions for GCP, AWS, Azure, and OCI accounts.

AI Defense

Integrate AI Defense with Multicloud Defense to secure your AI assets. Discover AI models, apply runtime protection, and validate safety. Connect your Multicloud Defense tenant to AI Defense for enhanced AI runtime monitoring and security.

Asset and Inventory Discovery

Discover cloud assets with Multicloud Defense for enhanced protection. Ensure inventory visibility across AWS, Azure, OCI, and GCP. View the security posture of your resources. Evaluate security groups and apply rules to mitigate risks.

Multicloud Defense Gateway and Service VPCs or VNets

Learn about Multicloud Defense gateways and service VPCs or VNets for securing cloud network traffic.

Site-to-Site VPN Tunnel Connection

Create secure site-to-site VPN tunnels using Multicloud Defense to connect networks across locations. Connect to AWS, Azure, GCP, ASA, or FTD devices. Configure and manage encrypted connections for optimal VPN protection.

Configure a Virtual Network Connection for Azure Virtual WAN

Learn how to connect a Cisco Multicloud Defense service VNet to an Azure Virtual WAN vHub and configure route association and propagation.

Rules and Rule Sets

Control cloud traffic and enhance security with Multicloud Defense policy rules and rule sets. Dynamically manage policies across multiple clouds and protect applications with advanced security profiles. Simplify rule configurations for comprehensive protection.

Objects

Manage security policies efficiently across hybrid clouds (AWS, GCP), using Multicloud Defense objects. Share static and dynamic objects with Security Cloud Control for consistent configurations. Import objects to adapt to real-time events and reduce maintenance.

Address Objects

Multicloud Defense Address Objects secure your cloud using static IPs/CIDRs/FQDNs and dynamic cloud resources like VPCs, Instance IDs, and tags. Efficiently define policy rules and automate security updates.

FQDN Objects

Use FQDN Match Objects to control network traffic in Multicloud Defense. Define rules with FQDNs and PCREs for precise matching of standalone and group objects, and block unwanted traffic for enhanced security.

Service Objects

Secure your multicloud traffic with service objects. Configure reverse/forward proxy & forwarding rules for deep packet inspection. Define L4 match criteria, set rate limits, and ensure robust protection against malicious activity.

Certificates and Keys

Secure Multicloud Defense with TLS certificates for ingress/egress. Import keys through AWS, GCP, Azure. Validate certificates in profiles/FQDNs.

Certificate and Keys Tech Notes

Generate self-signed root CAs, intermediate CAs, and application certificates for Multicloud Defense. Install the root CA as a trusted CA on various operating systems, ensuring secure communication and trust within your environment.

Types of Traffic

Protect your cloud environment! Multicloud Defense helps enable traffic logs, so you can detect threats across AWS, Azure, and GCP. Monitor DNS & VPC flows for better security.

Security Profiles

Learn how security profiles define protection settings for cloud traffic in Multicloud Defense.

Gateway Profiles

Enhance network security and management with Gateway Profiles. Configure routing, NAT, VPN, QoS, and access control for efficient and secure communication. Monitor traffic, forward logs, and optimize gateway performance using various profile types.

Profile Actions

Manage profiles in Multicloud Defense by viewing details, editing standalone and group profiles, adding or removing gateway associations, and deleting profiles. Streamline security configurations and maintain network control through effective profile management.

FQDN and URL Filtering Categories

Learn about FQDN and URL filtering categories for defining web traffic controls in Multicloud Defense security policies.

Flow Analytics

Learn how to use Flow Analytics in Multicloud Defense to understand network traffic across cloud environments.

Network Analytics

Learn how to use Network Analytics in Multicloud Defense to investigate cloud network traffic and activity.

Audit and System Logs

Provides a unified view and advanced features to manage logs efficiently.

Threat Research

Strengthen your network using Threat Research. Spot intrusions, web threats & malicious sources with Common Vulnerability Scoring System (CVSS) scores & Common Vulnerabilities and Exposures (CVE) in Multicloud Defense. Refine policies and search effectively.

Cloud Visibility Reports

Discover valuable network insights with Multicloud Defense's cloud visibility reports. Generate discovery and threat analytics reports to examine network traffic patterns, detect threats, and assess gateway performance, ensuring robust cloud security and informed decision-making.

Alerting Overview

Explains the purpose and key attributes of system alerts.

Alert Destinations / SIEMs

Explains how service rules with alert destinations are used to notify web services or applications.

Log Forwarding Overview

Explains how logs are forwarded to various systems for analysis, monitoring, and storage.

Log Forwarding Destinations / SIEMs

Explains how log destinations interface with SIEMs to manage and analyze security events effectively.

Management

Manage your Multicloud Defense account by creating and deleting API keys, application tags, and custom tags. Configure alert services and rules to send alerts to third-party endpoints, optimizing alert opportunities within the dashboard.

Manage Your Multicloud Defense Account

Manage your Cisco account settings to keep them up-to-date and secure.

Cloud Accounts

Manage cloud service provider accounts in Multicloud Defense by adding, editing, exporting, or deleting them. Monitor assets, modify monitored regions, and update log profiles for enhanced security.

Compliance Certificates and Awards

Learn about Multicloud Defense compliance certificates and awards that demonstrate alignment with recognized security and regulatory standards. Find certification details and access supporting documents through the Cisco Trust Portal.

Troubleshoot Connecting Your Account

Troubleshoot and connect your cloud accounts to Multicloud Defense by manually onboarding GCP projects and folders or Azure subscriptions. Create service accounts, enable APIs, configure VPCs, and register applications for seamless integration and robust security.