Learn how to set up, manage, and secure cloud environments with Cisco Multicloud Defense.
About Multicloud Defense
Protect your AWS, Azure, GCP, and OCI environments with Cisco Multicloud Defense. Get centralized control, gateway security, and a streamlined multicloud protection mechanism. Create an organization, claim subscription code, and activate Multicloud Defense in Cisco Security Cloud Control. Use the Cloud Explorer graphical view to create workflows and protect your assets. Enable visibility, view cloud traffic, and secure your cloud account, with the 90-day free trial subscription.
Setup with the Multicloud Defense Wizard
Onboard your AWS, Azure, Google Cloud Platform (GCP) & Oracle Cloud (OCI) clouds with Multicloud Defense. Enable traffic visibility through collection of Virtual Network (VNet), VPC Flow, and DNS Logs. Secure your cloud accounts with a gateway deployed in centralized or distributed model.
AWS
Connect your AWS account, including EC2 instances, to Multicloud Defense (MCD) Controller using a CloudFormation template. Ensure secure access and communication by creating IAM roles and enabling traffic visibility. Streamline cloud security management with ease using MCD.
Azure
Simplify Azure security using Multicloud Defense. Onboard your subscription with IAM roles and ARM templates for streamlined deployment. Secure virtual networks and manage access effectively.
GCP
Connect Google Cloud Platform to Multicloud Defense Controller by creating service accounts and enabling APIs. Onboard GCP projects and folders through Terraform, manually, or script, and manage via gcloud CLI for resource orchestration and asset discovery.
OCI
Prepare your OCI account (including US West region) for Multicloud Defense. Connect to the Controller using automated scripts or manual setup of groups, policies, and OCIDs. Enable secure Multicloud Defense for your OCI tenant.
Remove a Cloud Service Provider From Multicloud Defense
Clean up the Multicloud Defense instance to remove cloud service providers, gateways, delete gateways, subnets, VNets, and remove permissions for GCP, AWS, Azure, and OCI accounts.
AI Defense
Integrate AI Defense with Multicloud Defense to secure your AI assets. Discover AI models, apply runtime protection, and validate safety. Connect your Multicloud Defense tenant to AI Defense for enhanced AI runtime monitoring and security.
Asset and Inventory Discovery
Discover cloud assets with Multicloud Defense for enhanced protection. Ensure inventory visibility across AWS, Azure, OCI, and GCP. View the security posture of your resources. Evaluate security groups and apply rules to mitigate risks.
Multicloud Defense Gateway and Service VPCs or VNets
Secure clouds with Multicloud Defense Gateways. Manage deployments, integrate with AWS CloudWAN, and auto-scale for performance. Protect apps, simplify networks, and support VPCs/VNets with Ingress, East-West/Egress gateways. Use advanced load balance configurations to create gateways on Multicloud Defense.
Site-to-Site VPN Tunnel Connection
Create secure site-to-site VPN tunnels using Multicloud Defense to connect networks across locations. Connect to AWS, Azure, GCP, ASA, or FTD devices. Configure and manage encrypted connections for optimal VPN protection.
Configure a Virtual Network Connection for Azure Virtual WAN
Learn how to connect a Cisco Multicloud Defense service VNet to an Azure Virtual WAN vHub and configure route association and propagation.
Rules and Rule Sets
Control cloud traffic and enhance security with Multicloud Defense policy rules and rule sets. Dynamically manage policies across multiple clouds and protect applications with advanced security profiles. Simplify rule configurations for comprehensive protection.
Objects
Manage security policies efficiently across hybrid clouds (AWS, GCP), using Multicloud Defense objects. Share static and dynamic objects with Security Cloud Control for consistent configurations. Import objects to adapt to real-time events and reduce maintenance.
Address Objects
Multicloud Defense Address Objects secure your cloud using static IPs/CIDRs/FQDNs and dynamic cloud resources like VPCs, Instance IDs, and tags. Efficiently define policy rules and automate security updates.
FQDN Objects
Use FQDN Match Objects to control network traffic in Multicloud Defense. Define rules with FQDNs and PCREs for precise matching of standalone and group objects, and block unwanted traffic for enhanced security.
Service Objects
Secure your multicloud traffic with service objects. Configure reverse/forward proxy & forwarding rules for deep packet inspection. Define L4 match criteria, set rate limits, and ensure robust protection against malicious activity.
Certificates and Keys
Secure Multicloud Defense with TLS certificates for ingress/egress. Import keys through AWS, GCP, Azure. Validate certificates in profiles/FQDNs.
Certificate and Keys Tech Notes
Generate self-signed root CAs, intermediate CAs, and application certificates for Multicloud Defense. Install the root CA as a trusted CA on various operating systems, ensuring secure communication and trust within your environment.
Types of Traffic
Protect your cloud environment! Multicloud Defense helps enable traffic logs, so you can detect threats across AWS, Azure, and GCP. Monitor DNS & VPC flows for better security.
Security Profiles
Enhance your network security with Multicloud Defense security profiles. Configure profiles like Firewall Rules, IPS, Antivirus, DLP, and WAF to protect against threats and control applications, ensuring comprehensive security across your multicloud environment.
Gateway Profiles
Enhance network security and management with Gateway Profiles. Configure routing, NAT, VPN, QoS, and access control for efficient and secure communication. Monitor traffic, forward logs, and optimize gateway performance using various profile types.
Profile Actions
Manage profiles in Multicloud Defense by viewing details, editing standalone and group profiles, adding or removing gateway associations, and deleting profiles. Streamline security configurations and maintain network control through effective profile management.
FQDN and URL Filtering Categories
Protect your cloud environment with Multicloud Defense FQDN/URL filtering, powered by Cisco Talos. Categorize and control web traffic across 84 categories, blocking malicious sites and ensuring policy enforcement for enhanced security and visibility.
Flow Analytics
Use Multicloud Defense Flow Analytics to gain visibility into network events and logs. Improve your security posture by using filtering options to analyze traffic summary, firewall events, web attacks and more.
Network Analytics
Analyze network performance with Multicloud Defense using bandwidth, connection, and request rates. Monitor CPU and memory usage of gateway instances to optimize performance and assess traffic trends. Gain visibility into your network's health and resource utilization.
Audit and System Logs
Monitor user actions and system events within Multicloud Defense using audit and system logs. Use advanced search, and filter logs by various fields such as Action Type, User, Gateway, or severity level, and display them in UTC or local time formats to identify and address potential issues.
Threat Research
Strengthen your network using Threat Research. Spot intrusions, web threats & malicious sources with Common Vulnerability Scoring System (CVSS) scores & Common Vulnerabilities and Exposures (CVE) in Multicloud Defense. Refine policies and search effectively.
Cloud Visibility Reports
Discover valuable network insights with Multicloud Defense's cloud visibility reports. Generate discovery and threat analytics reports to examine network traffic patterns, detect threats, and assess gateway performance, ensuring robust cloud security and informed decision-making.
Alerting Overview
Integrate Multicloud Defense with widely deployed alerting services like Microsoft Sentinel, PagerDuty, ServiceNow, and Slack. Forward critical system-level alerts and enable cloud operations teams to respond effectively to user-defined system events and severity levels.
Alert Destinations / SIEMs
Configure Multicloud Defense to send alerts to platforms such as Datadog, Microsoft Sentinel, PagerDuty, ServiceNow, Microsoft Teams, Webex, Splunk, and Slack. Integrate with SIEMs and set up automated notifications for critical events. Ensure timely responses to security incidents.
Log Forwarding Overview
Configure Multicloud Defense log forwarding profiles to send security events, traffic logs, and gateway metrics to SIEM systems such as AWS S3, Datadog, GCP Logging, Microsoft Sentinel, Splunk, Sumo Logic, Syslog, and Webhooks. Create standalone or group profiles for event, traffic, or metrics logs and associate them with gateways or cloud accounts for comprehensive security monitoring and analysis.
Log Forwarding Destinations / SIEMs
Forward Multicloud Defense logs to AWS S3, Datadog, GCP Logging, Microsoft Sentinel, Splunk, Sumo Logic, Syslog, and Webhooks. Enable processing, access, and correlation of security events. Improve security monitoring and analysis across platforms.
Management
Manage your Multicloud Defense account by creating and deleting API keys, application tags, and custom tags. Configure alert services and rules to send alerts to third-party endpoints, optimizing alert opportunities within the dashboard.
Manage Your Multicloud Defense Account
Secure access to the Security Cloud Control API by configuring API keys. Generate unique keys for each tenant to authenticate and authorize access. Revoke compromised keys immediately to maintain the security of your resources.
Cloud Accounts
Manage cloud service provider accounts in Multicloud Defense by adding, editing, exporting, or deleting them. Monitor assets, modify monitored regions, and update log profiles for enhanced security.
Compliance Certificates and Awards
Learn about Multicloud Defense compliance certificates and awards that demonstrate alignment with recognized security and regulatory standards. Find certification details and access supporting documents through the Cisco Trust Portal.
Troubleshoot Connecting Your Account
Troubleshoot and connect your cloud accounts to Multicloud Defense by manually onboarding GCP projects and folders or Azure subscriptions. Create service accounts, enable APIs, configure VPCs, and register applications for seamless integration and robust security.