Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Configure Your Gateway

Want to summarize with AI?

Log in

Learn how to find, filter, and review Cisco Multicloud Defense gateways, cloud providers, instance counts, and configuration details.


View your Multicloud Defense Gateways and statistic in Infrastructure > Gateways > Gateways. From this page you can search and filter your gateways, view the cloud service providers assocaited with each gateway, current instance count and type, and more.

For more information on the supported use cases for specific gateway environments, see Supported Gateway Use Cases.


Before You Begin

You can also orchestrate a Transit Gateway through the Multicloud Defense Gateway or attach an existing Transit Gateway.

Multicloud Defense Gateway Prerequisites and Limitations

Prerequisites

The supported cloud service providers (AWS, Azure, GCP, OCI) are separate entities that use their own vocabulary and gateway environment. Not every option available in the Multicloud Defense Controller is compatible with your cloud service provider. For example, AWS uses its own Transit Gateway and you can add VPCs to it while Azure utilizes a load- balancer to manage web traffic and applications and you can add VNets to it. Keep this in mind when proceeding.

Note

For AWS environments, when securing spoke VPCs in centralized mode, Multicloud Defense attaches VPCs to the Transit Gateway that is associated to the service VPC. By default, Multicloud Defense will randomly select a subnet in each availability zone for Transit Gateway attachment. You can change this option when you add a VPC or you can modify a VPC that is already assigned to the gateway.

Limitations

Be aware of the following limitations when creating a Multicloud Defense Gateway:

  • If you deploy a Multicloud Defense Gateway that uses a site-to-site VPN tunnel containing an IPSec profile, you must deploy the gateway with a service VPC or service VNet and without a Network Address Translation (NAT) gateway on either side of the VPN connection.

  • Autoscaling is not supported for gateways containing an IPSec profile.

  • Policy rules within the gateway must be Forwarding only.

  • If you intend to include an IPSec profile in a Multicloud Defense Gateway for an AWS or Azure account, the gateway instance must be configured with core 8. Multicloud Defense Gateway does not currently support gateways with core 2 or core 4 options.

FTDv Gateway Prerequisites and Limitations

Multicloud Defense orchestrates only the process of creating, deploying and maintaining the gateway. Any policy or rule creation occurs in Cloud-delivered Firewall Management Center. Consider the following prerequisites, limitations, and recommendations to support the integration of both managerial products before you create a gatway.

Prerequisites

You must have the following completed and configured before you create a Multicloud Defense Gateway for your FTDv:

  • You must create a new Service VPC. VPCs created before this feature do not support this functionality; note that when you create a new VPC it can still be used for both Multicloud Defense gateways or FTDv gateways.

  • You must have a cloud service provider onboarded to your Multicloud Defense tenant.

  • If you are using an AWS account as your designated cloud service provider for the FTDv gateway, you must manually accept the AWS Marketplace Terms of Service. Without it, the Multicloud Defense Controller cannot send the required API requests.

  • You must have at least one license purchased through your Cisco seller or partner.

  • You must have a subscription to Cloud-delivered Firewall Management Center.

For limitations and requirements for this environment, please refer to Firewall Threat Defense Virtual.


Resources Created by Multicloud Defense

The following resources are created by Multicloud Defense when you create a gateway, VPC, or VNet. These are created as part of the process and do not require any additional actions from the user. Note that difference resources are created per each cloud service provider requirements.

GCP Resources

Multicloud Defense creates two service VPCs and four firewalls. See the following for the exact resource allocation:

Service VPC

  • Management

  • Datapath

Firewall Rules

  • Management (ingress)

  • Management (egress)

  • Datapath (ingress)

  • Datapath (egress)

Note

The Service VPC CIDR cannot overlap with the Spoke VPC.

AWS Resources

Multicloud Defense creates three service VPCs to address the supported use cases (ingress, egress/ east-west). Created and affiliated with each of these VPCs is the following:

  • Four subnets in each availability zone.

  • One route table for each of the subnets.

  • Two security-groups: management and datapath.

  • One Transit Gateway.

    Note

    This Transit Gateway is created and attached to the gateway during the creation of the service VPC. This gateway can be reused with other service VPCs.

  • A Transit Gateway route table.

    Note

    The route table is attache to the Service VPC as part of the creation process.

Note

The AWS Gateway Load Balancer (GWLB) does not support add/remove of availability zones after initial deployment of a GWLB. You will need to redeploy the service VPC if you need to change availability zones. See AWS documentation for more information.

Azure Resources

Multicloud Defense created one Service VNet with the following resources:

  • One VNet.

  • Two network security groups.

The Service VNet CIDR value must not overlap with spoke VNet.

FTDv Resources

Multicloud Defense creates the following resources for Service VPCs that are used with Secure Firewall Firewall Threat Defense virtual (FTDv) devices:

  • Management subnet.

  • Datapath 1 subnet.

  • Datapath 2 subnet.

  • Three security groups corresponding to subnets.


Add a Multicloud Defense Gateway

Use the following procedure to add a Multicloud Defense Gateway for your cloud service provider:

Before you begin

Review the Before You Begin for information or requirements pertaining to your specific environment before you create a gateway.

If you are planning on using an AWS global accelerator or Azure load balancer, be sure the load balancer is already configured prior to adding it to a Multicloud Defense Gateway. See Advanced Gateway Configuration: Use Your Own Load Balancer for more information.

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Click Add Gateway.

3.

Select the cloud service provider you want to add the gateway to.

4.

Click Next.

5.

Enter your gateway information.

  • Instance Type - Choose the type of cloud service provider. You may encounter different instance types, depending on your cloud service provider.

    • (Azure only) If you are creating a VPN, and you use Red Hat Enterprise Linux 9 (RHEL 9) as a base operating system, we recommended that you use a Dsv3-Series V3 instance type instead of a Dsv5-Series V5 instance type, as the V5 instance type may not be compatible.

  • Gateway Type - Select either Ingress or Egress.

    Note

    Select Egress if you have an east-west network flow.

  • Minimum Instances - Select the minimum number of instances that you plan to deploy.

  • Maximum Instances - Select the maximum number instances that you plan to deploy. This is the maximum number that is used for auto-scaling in each availability zone.

  • HealthCheck Port - Default is 65534. The port number used by Multicloud Defense load balancer to check the health of the instances. Datapath security groups assigned to the instance(s) must allow traffic on this port.

  • (Optional) Packet Capture Profile - Packet Capture Profile for threat and flow PCAPs.

  • (Optional) Diagnostics Profile - Diagnostics Profile used to store Technical Support information.

  • (Optional) Log Profile - Log Forwarding Profile used to forward Events/Logs to a SIEM.

  • (Optional) NTP Profile - Network Time Protocol (NTP) for time synchronization.

  • (Optional) BGP profile - Border Gateway Protocol (BGP) used to support VPN Connections. If you intend on utilizing site-to-site VPN tunnels with a Multicloud Defense Gateway you must include this profile.

6.

Click Next.

7.

Provide the following parameters:

  • Security - Select either Egress or Ingress.

    Note

    Select Egress if you have an east-west network flow.

  • Gateway Image - Image to be deployed.

  • Policy Ruleset - Select the policy ruleset to associate with this gateway.

  • Region - Select the region this gateway will be deployed into.

  • Resource Groups - Select the resource group to associate the gateway with.

  • SSHPublic Key - Paste the SSH public key. The controller uses this key to access the CLI of deployed gateway instances for debugging and monitoring.

  • VNet ID - Select the VNet to associate with the gateway.

  • (Azure only) User Assigned Identity ID - Enter the cloud service provider identity to associate with this gateway. User-assigned managed identities can be used in place of credentials for resources. For Azure services, these identities can access a private key stored in Azure Key Vault or write PCAP files to Azure Blob Storage.

  • Mgmt. Security Group - Select the security group to associate with the management interface.

  • Datapath Security Group - Select the security group to associate with the datapath interface.

  • Disk Encryption - Select the appropriate option from the drop-down menu. If you use a customer-managed encryption key, input the encryption key’s resource ID.

8.

Select the Availability Zone, the Mgmt Subnet and the Datapath Subnet. The available subnets will be based on the VPC or VNet you selected. For high availability purposes, you can deploy the gateway instances in multiple availability zones. Click the plus button to add a new availability zone and select the parameters for the selected zones. Some cloud service provider regions support only single availability zone and not multiple availability zones. In such regions, the gateway instances are deployed in only a single zone.

Note

If your gateway is deployed in hub mode, availability zones cannot be edited after the initial deployment. Reconfirm your zones before deploying.

9.

(Azure only, optional) If you are deploying in distributed model with Multicloud Defense Gateway in the same VNet as application, ensure you complete the following:

  • Add a route table in the Azure portal and associate the route table with all the subnets.

  • Add a default route for 0.0.0.0/0 with next-hop as the IP address of the Gateway Network Load Balancer.

10.

Click Next to view the Advanced Settings.

11.

By default, the Multicloud Defense Gateway enables the use of the public IP of the router available. If you do not want this enabled, check the Disable Public IP box.

12.

(AWS and Azure only) Attach Load Balancer. Click Add Load Balancer to create a row for your custom load balancer. You can also remove unnecessary rows by selecting them and clicking Remove.

  1. Expand the Load Balancer drop-down to select a load balancer from your AWS or Azure cloud service provider.

  2. Expand the Backend Pool drop-down to select a backend pool to be associated with your gateway.

13.

Click Save.

What to do next

Multicloud Defense deploys the gateway.

You must attach at least one ruleset to the gateway before you secure a spoke VPC/VNet. See Rule Sets and Rule Set Groups for more information.


Create a Firewall Threat Defense Virtual Gateway

Use the following procedure to create a Firewall Threat Defense virtual gateway:

Create a Firewall Threat Defense virtual gateway for AWS, Azure, or GCP for Ingress, Egress, and East-West traffic.

Before you begin

Review the Before You Begin for information or environment limitations before you create a gateway.

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Click Add Gateway.

3.

Select the cloud service provider you want to add the gateway to.

4.

Click Next.

5.

Enter the following Gateway Information. Note that if you do not have the feature enabled, the options for "Gateway Type" may differ and you should refer to Add a Gateway.

  • Account - Expand the drop-down menu and select a cloud service provider account that is already onboarded to Multicloud Defense Controller. At this time, only AWS and Azure accounts are supported.

  • Gateway Type - Expand the drop-down menu and select FTDv Gateway.

  • Name - Enter a name for the gateway as it will be displayed in the Multicloud Defense Controller.

  • (Optional) Description - Enter a description for the gateway. We recommend using unique identifiers to differentiate this gateway from others that may have a similar name or purpose.

  • Instance Type - Choose the type of cloud service provider. This selection should match the cloud service provider that is selected in the before-mentioned "Account" field. Note that there may be multiple variations of instances depending on which cloud service provider you are using.

  • Minimum Instances - Select the minimum number of instances that you plan to deploy.

  • Maximum Instances - Select the maximum number instances that you plan to deploy. This is the maximum number that is used for auto-scaling in each availability zone.

  • HealthCheck Port - Default is 65534. The port number used by Multicloud Defense load balancer to check the health of the instances. Datapath security groups assigned to the instance(s) must allow traffic on this port.

6.

Click Next.

7.

Provide the following parameters where applicable. Note that several fields are auto-filled in based on the configuration of the Service VPC you created for this gateway. See Create a Service VPC or VNet for more information.

  • Security - Select Ingress, Egress, or East-West based on your requirement.

    • AWS - You can select Ingress, Egress, or East-West.

    • Azure - You can select Ingress, Egress, or East-West.

    • GCP - You can select Ingress or East-West and Egress.

  • FTDv Version - Select the version of software to run on the FTDv device when Multicloud Defense creates and deploys the device.

  • Policy Ruleset - Select the access control policy ruleset to associate with this gateway. If you do not already have an access policy ready you can either use the default policy or create a new policy from this menu.

  • Admin Password - Enter a password for the admin of the FTDv device. Follow the on-screen prompts for a strong password.

  • License Model - Click the toggle to highlight your preferred licensing model:

    • Multicloud Defense Licensing - The Multicloud Defense licensing model allows you to use all the Firewall Threat Defense virtual features without procuring individual feature licenses in Cisco Smart Licensing account.

    • Smart Licensing - Select this option if you intend to purchase a license or have an unused license already purchased through your Cisco Smart Account.

    • Pay-As-You-Go (PAYG) Licensing - Select this option if you intend to use the license on demand.

  • Performance Tier - Expand the drop-down menu and select the appropriate performance tier for your device. Note that FTDv50 is auto-selected. See the tiers listed in Licensing.

  • License Types - Expand the drop-down menu and select the appropriate license type that you have purchased or will purchase in the future. Note that the Base license is auto-selected. See the different licensing types listed in Licensing.

  • Region - Select the region this gateway will be deployed into.

  • VPC/VNet ID - Select the ID of the Service VPC or VNet to associate with the gateway. Identifying a Service VPC or VNet in this step confirms the management and datapath security groups as well as the availability zones. To modify these values, create a new service VPC and add it to this gateway.

  • (AWS only) Key Pair - Expand the drop-down menu and select the key pair that is associated with the cloud account you selected in the previous screen.

  • (Azure and GCP only) Key Selection - Select the type of key, its size, and its activation and expiration dates. Choose either SSH Public Key or SSH Key Pair. Based on your selection, enter the appropriate information in the text field when prompted.

  • Resource Groups - Select the resource group to associate the gateway with.

  • (AWS only) Gateway IAM Role - Expand the drop-down menu and select the IAM role that allows the gateway to perform READ and WRITE operations on your AWS account. Multicloud Defense creates this role for you when you save and deploy the gateway.

  • (Azure only) User Assigned Identity ID - Enter the cloud service provider identity to associate with this gateway. User-assigned managed identities can be used in place of credentials for resources. User-assigned managed identities can be used for Azure services such as a private key stored in Azure Key Vault or to write PCAP files to an Azure Blob Storage.

  • Mgmt. Security Group - Select the security group to associate with the management interface.

  • DataPath Security Group 1 - Select the security group to associate with the datapath 1 interface.

  • DataPath Security Group 2 - Select the security group to associate with the datapath 2 interface.

  • (GCP only) Datapath VPC - Select a VPC.

  • (GCP only) Datapath Network Tag 1 - Choose a security group from the drop-down list.

  • (GCP only) Datapath Network Tag 2 - Choose a security group from the drop-down list.

  • (GCP only) Management VPC - Select a Management VPC from the drop-down list.

  • (GCP only) Management Network Tag - Select a Management Network tag from the drop-down list.

  • (AWS only) EBS Encryption - Expand the drop-down menu and select the appropriate EBS encryption for your specific AWS account.

  • (Azure) Disk Encryption - Select the appropriate option from the drop-down menu. For customer managed encryption key, the user will need to input the resource ID of the encryption key.

8.

The Instance Details are auto-populated based on the VPC you select. Review the VPC configuration before you deploy the gateway. Click Next.

9.

(Optional) In the Advanced Settings window, check the Disable Public IP checkbox; if you opt to disable this step you reduce the exposure of your network to external threats. Private IP addresses can help protect against unauthorized access and potential attacks. They also offer better control of internal traffic.

10.

Click Next.

11.

Review the configuration of the gateway. If you are satisfied with the gateway and want to deploy it, click Finish. If you want to modify the settings, click Back.

What to do next

Clicking Finish at the end of this procedure deploys the gateway; creating and deploying the gateway may take up to 30 minutes. While Multicloud Defense deploys the gateway, it also registers the gateway instance in Cloud-delivered Firewall Management Center for your convenience, creates and applies subnets and security groups for the appropriate interfaces, and applies the access policy you selected in this procedure.

Once the gateway deploys and is displayed in the Cloud-delivered Firewall Management Center we recommend making any necessary updates or inclusions to the policy. Any network objects associated with the policy are shared and displayed in Multicloud Defense's Object page as network objects for visibility. Policy orchestration and management is done through Cloud-delivered Firewall Management Center.

We strongly recommend the following actions once the gateway is deployed:


Edit a Multicloud Defense Gateway

You can edit a gateway in any state, whether it is enabled or disabled.

Note

If you edit a gateway that is attached to an FTDv device, note that you cannot change the licensing model, only the performance tier of the smart license.

Use the following procedure to edit an existing Multicloud Defense Gateway:

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the Multicloud Defense Gateway you want to edit in the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Edit.

4.

Modify the gateway configuration as needed.

If you are modifying the license peformance tier for a gateway that is asssociated with an FTDv device, note that existing instances are automatically updated in Cloud-delivered Firewall Management Center; Multicloud Defense creates new instances to support the new license configuration and sync to Cloud-delivered Firewall Management Center for you.

5.

Click Save to confirm the changes. Alternatively, click Cancel to exit the changes.


Upgrade the Multicloud Defense Gateway

Multicloud Defense Gateways serve as an autoscaling self-healing Platform-as-a-Service (Paas), functioning as inline network-based security enforcement nodes. Unlike traditional firewalls, Multicloud Defense eliminates the need for customers to construct virtual firewalls, configure high-availability setups, or manage software installations.

Multicloud Defense Gateway instances operate on highly optimized software, incorporating a single-pass datapath pipeline for efficient traffic processing and advanced security enforcement. Each gateway instance comprises three core processes: a "worker" process responsible for policy enforcement, a "distributor" process for traffic distribution and session management, and an "agent" process communicating with the controller. Gateway instances can seamlessly transition "in service" for a "datapath restart," enabling smooth upgrades without disrupting traffic flow.

New instances are spun up with new image. Once the instances are fully up, they are placed in the loadbalancer's (layer 4 sprayer of flows to gateway instances) target pool. The old instances are put in flow draining mode or flow timeout mode for the existing flows going through them. New flows will hit the new instances. Once the timeout (Azure) or the flows are drained (AWS), the old instances are reaped by the controller.

Use the following procedure to

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the checkbox for the gateway you want to upgrade. You can make only one selection at this time.

3.

Select Actions > Upgrade.

4.

From the Gateway Image list, select the desired image.

5.

Click Save.

6.

Confirm the cloud service provider resource allocation necessary for the upgrade.

7.

Click Yes if the resource allocation is sufficient. Click No if the resource allocation is insufficient, increase the resource allocation in the cloud service provider, and return to continue the upgrade.

Note

You can view the upgrade progress and new gateway instances being created from theinstances info for the gateway. Select the gateway and view the Instances in the Details pane.


Upgrade Your Firewall Threat Defense Virtual Device

This procedure explains how to upgrade the Firewall Threat Defense virtual devices that are affiliated with a cloud service povider and a Multicloud Defense Gateway. We strongly recommend upgrading your FTDv device through the Multicloud Defense Controller.

Procedure

1.

Navigate to Infrastructure > Gateway > Gateways and select the gateway associated with your Firewall Threat Defense virtual device.

2.

Click Actions and select Upgrade.

3.

Expand the FTDv Version drop-down menu and select the version you want to upgrade to. If there are no versions listed, click the refresh icon located to the right of the drop-down menu or confirm with the Cisco Secure Firewall Threat Defense release notes to see if a new version is publicly available.

4.

Click Save. Multicloud Defense initiates the upgrade and redeploys that gateway.


Abort a Multicloud Defense Gateway

You can only abort a Multicloud Defense Gateway that is currently going through an in-progress gateway update.

Use the following procedure to abort an existing Multicloud Defense Gateway:

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the Multicloud Defense Gateway you want to abort in the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Abort.

4.

Confirm you want to abort the gateway and click Yes. To back out of the action, click No.


Enable a Multicloud Defense Gateway

You can only enable gateways that have been disabled. Use the following procedure to enable a

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the Multicloud Defense Gateway you want to enable in the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Enable.

4.

Multicloud Defense validates the gateway configuration. If the validation is successful, a table of current and required resources for an upgrade generate for review. If you approve of the gateway resource allocation, click Yes to confirm the action.

What to do next

Wait a few minutes for the Multicloud Defense Gateway to successfully enable.

If you've disabled a Multicloud Defense Gateway and deleted the site-to-site VPN tunnels affiliated with it, you must create a new site-to-site VPN tunnel connection, or recreate the previous VPN tunnel connection and then add it to the gateway. When a gateway is disabled, Multicloud Defense forgets the public IP address associated with the VPN tunnel. You must create a new tunnel connection to establish a new IP for the gateway instance.


Disable a Multicloud Defense Gateway

You can only disable a Multicloud Defense Gateway if it is currently enabled. You cannot disable gateways that are already disabled.

Use the following procedure to disable a Multicloud Defense Gateway:

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the Multicloud Defense Gateway you want to disable in the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Disable.

4.

Confirm you want to disable the gateway and click Yes. To cancel this action, click No.

What to do next

Wait a few minutes for the gateway to succesfully disable.

To completely disable the gateway, you must delete any site-to-site VPN tunnels affiliated with the gateway.


Export a Multicloud Defense Gateway

Use the following procedure to export the configuration of a Multicloud Defense Gateway:

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the Multicloud Defense Gateway you want to export in the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Export.

4.

Multicloud Defense generates an export wizard.

5.

Either click Download to download the terraform locally or scroll down and click Copy Code to copy the JSON resource.

6.

Manually paste into the terraform script.

7.

Within the terraform prompt, execute the command provided in the lower half of the window: terraform import "ciscomcd_gateway"."object-name" <object name>.

8.

Follow the prompts within the terraform prompt to complete the task. Close the export window in Multicloud Defense. There are no more steps in the dashboard.


Delete a Multicloud Defense Gateway

Use the following procedure to delete a Multicloud Defense Gateway. Note that this action is different from disabling the gateway.

Procedure

1.

Navigate to Infrastructure > Gateways > Gateways.

2.

Select the Multicloud Defense Gateway you want to delete in the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Delete.

4.

Confirm the action and click Yes. To cancel the deletion action, click Cancel.

What to do next

We strongly recommend deleting any site-to-site VPN tunnel connections associated with this gateway after it is successfully deleted from the gateway table.