Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Enable Traffic Visibility

Want to summarize with AI?

Log in

Learn how traffic visibility helps you understand cloud traffic and threats, and find the setup procedure for your AWS, Azure, or Google Cloud Platform account.


To understand traffic flows within your cloud account, enabling traffic visibility collects these types of logs:

  • VPC or VNet flow logs

  • DNS logs

  • Route53 query logging

Flow and DNS query logs help Multicloud Defense to understand traffic flow, correlate data with threat intelligence feeds, and gain insights into existing threats protected by Multicloud Defense.

Enabling traffic visibility varies by cloud account type. Identify the characteristics of your cloud account, including the region, VPC/VNet for monitoring, network security groups, and a cloud storage account for logs.

Note

Multicloud Defense does not support traffic visibility for OCI at this time. Enable asset discovery as an alternative action for this procedure: which means Multicloud Defense identifies and collects metadata for assets from an external environment and the resulting data collected creates an inventory that can be used to assist migration. For more information, refer to Enable Asset Discovery and Inventory.


Enable Traffic for an AWS Account

Use this procedure to enable traffic visibility for an AWS account using the Setup wizard:

Procedure

1.

In the Multicloud Defense Controller portal click Setup in the left navigation bar.

2.

In the setup wizard, click Enable Traffic Visibility.

3.

Enter the required information into the modal:

  1. CSP Account - Use the drop-down menu to select the cloud service provider account to which Multicloud Defense Controller deploys the Service VPC/VNet.

  2. Region - Use the drop-down menu to select the region where the cloud service provider you selected is located.

  3. VPCs - Scroll through the table of available VPCs that are applicable to the type of cloud service provider you selected and check the appropriate VPC. If the VPC does not appear, click the Refresh icon to update the list.

  4. S3 Bucket - Use the drop-down menu to select an existing S3 bucket from your account; stores DNS queries and VPC/VNet flow logs. This S3 bucket is already created in your account.

4.

Click Next.

What to do next

Ensure your account is secure.


Enable Traffic for an Azure Account

Use this procedure to enable traffic visibility for an Azure account from the Setup wizard:

Procedure

1.

In the Multicloud Defense Controller portal click Setup in the left navigation bar.

2.

In the setup wizard, click Enable Traffic Visibility.

3.

Enter the required information into the modal:

  1. CSP Account - Use the drop-down menu to select the cloud service provider account to which Multicloud Defense Controller deploys the Service VPC/VNet.

  2. Region - Use the drop-down menu to select the region where the cloud service provider you selected is located.

  3. Copy and run the script. If you are re-onboarding an Azure account and are reusing a cloud storage bucket, the script does not automatically create a new storage bucket. Use the default, or preexisting storage bucket. Otherwise, create a new storage bucket in the Azure dashboard or manually edit the script command before executing it to include the storage bucket name for the flow logs.

  4. Virtual Network (VNet) - Select at least one VNet for traffic to be visible on. Scroll through the table of available VNets applicable to the type of cloud service provider you selected, and check the appropriate one. Note that if you do not immediately see the VNet, click the Refresh icon to refresh the current list.

    Note

    You may see existing NSG Flow Logs, which will be supported by Multicloud Defense until it is deprecated by Microsoft Azure. You will no longer be able to create new NSG Flow Logs. Instead, you can create VNet Flow Logs.

  5. Storage Account - Enter the full Resource ID in the selected region.

4.

Click Next.

What to do next

Ensure your account is secure.


Enable Traffic for a GCP Project

Use this procedure to enable traffic visibility for a GCP account with the Setup wizard:

Procedure

1.

From the Security Cloud Control Home page, click Multicloud Defense .

2.

In the Multicloud Defense Controller portal click Setup in the left navigation bar.

3.

In the setup wizard, click Enable Traffic Visibility.

4.

Enter the required information into the modal:

  1. CSP Account - Use the drop-down menu to select the cloud service provider account to which Multicloud Defense Controller deploys the Service VPC/VNet.

  2. Cloud Storage - Select an available cloud storage bucket that has already been assigned to the GCP project you selected.

  3. Select VPC(s) - Select at least one VPC for traffic to be visible on. Scroll through the table of available VPCs that apply to the type of cloud service provider you selected, and check the appropriate VPC. Note that if you do not immediately see the VPC, click the Refresh icon to refresh the current list.

  4. Copy and run the script. Note that if you are re-onboarding a GCP project and reusing a cloud storage bucket, the script does not automatically create a new storage bucket. You can use the default or preexisting storage bucket. Otherwise, create a new storage bucket in the GCP dashboard or manually edit this script command before executing to include the storage bucket name for storing your GCP project's flow logs.

5.

Click Next.

What to do next

Ensure your account is secure.