Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Terraform Onboarding Scripts for Cloud Accounts

Want to summarize with AI?

Log in

Onboard a cloud service provider account to Multicloud Defense with a Terraform script as an alternative to the onboarding wizard or manual setup.


You an use the terraform script to onboard your cloud service provider account instead of using the onboarding wizard or the manual process.


About Terraform

Multicloud Defense customers can use the Terraform Provider to: discover - onboard public cloud accounts, gain continuous asset visibility and detect indicators of compromise (IoC); deploy - Multicloud Defense Gateways to protect ingress, egress and east-west traffic; and defend - with multicloud (AWS, Azure, GCP, OCI) dynamic policies with continuously discovered cloud assets.

As of Multicloud Defense Controller version 23.10, you can connect a GCP folder as well as a GCP project using the Terraform provider. See Terraform Repository for more information.

The Multicloud Defense terraform provider is a “Verified” provider available from the Terraform registry. Customers can now use the Terraform provider for Multicloud Defense to bake security into their operations, that is, onboard their cloud accounts into Multicloud Defense, deploy Multicloud Defense Gateways and specify security policies to protect against ingress attacks from the Internet (WAF, IDS/IPS, Geo-IP), stop exfiltration on egress traffic (TLS decryption, IDS/IPS, AV, DLP, FQDN/URL filtering), and prevent east-west attacks between VPCs/VNets. The security policies can be specified based on cloud asset tags (for example, “dev”, “test”, “prod”, “pci”, “web”, “app1” and more).

For more information, refer to:


Terraform Repository

Use case

Description

Github Repository

AWS onboarding

This is for onboarding AWS account using Terraform.

AWS Github Repo

AWS discovery CFT

This CFT deployment will include all necessary privileges needed to use Multicloud Defense's discovery feature. For full feature set, please use the native product CFT.

AWS Discovery Github Repo

AWS discovery

This is for onboarding AWS account for discovery only mode using Terraform.

AWS Github Repo

Azure onboarding

This is for onboarding Azure Subscription using Terraform.

Azure Github Repo

GCP Project onboarding

This is for onboarding GCP project using Terraform.

GCP Github Repo

GCP Folder onboarding

This is for onboarding GCP folder using Terraform.

GCP Github Repo


Exporting Configuration as Terraform Block

Customers can export security profiles into terraform resource blocks from Multicloud Defense Controller. To export configuration into Terraform block, navigate and select the intended security profile and click on Export button. This will download a file that has the terraform block for the selected object/security profile.

All objects and profiles support terraform export with the exception of:

  • Gateways

  • Service VPCs/VNets

  • Diagnostics