Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Secure Your Account

Want to summarize with AI?

Log in

Learn how to secure a cloud account with a Cisco Multicloud Defense gateway deployed in a centralized or distributed model.


Secure your account with a gateway deployed in either a centralized or a distributed model.

In a Centralized model, Multicloud Defense orchestrates the VPC or VNet and additional components, and deploys the gateway within this construct.

In a Distributed model, Multicloud Defense builds and deploys a gateway within the existing infrastructure that your network already has available.

Follow one of these procedures to secure your account.


Centralized Model: Add a VPC or VNet

Follow these steps to create and add a VPC or VNet for your gateway and secure your account:

Before you begin

You must have at least one cloud service provider connected to the Multicloud Defense Controller before you begin this wizard. This procedure may vary for different providers based on their required parameters.

Procedure

1.

In the left pane of the Multicloud Defense Controller portal, choose Home > Easy Setup.

2.

In the setup wizard, on the Secure Your Account section, click Secure Account.

3.

Select Centralized so it is highlighted.

4.

Click Next.

5.

Add a Service VPC/VNet:

  1. Name - Enter a name for the Service VPC/VNet. Once created, this name is displayed in the Infrastructure > Gateways > VPCs/VNets page.

  2. (AWS only)CSP Account - Use the drop-down menu to select a cloud service provider account that is already connected to the Multicloud Defense Controller. Deploy the Service VPC/VNet to the selected account.

  3. Region - Use the drop-down menu to select the region where the selected cloud service provider is located.

  4. CIDR Block - Enter the unique value for the Transit Gateway to which the Service VPC/VNet is attaching.

  5. (GCP only) Datapath CIDR Block - Enter a valid CIDR block for datapath VPC, ensuring it does not overlap with spoke VPCs.

  6. (GCP only) Management CIDR Block - Enter a valid CIDR block for the management VPC.

  7. Availability Zones - Of the generated list, select at least one availability zone. Using two zones is strongly recommend for best results.

  8. (Azure only) Resource Group - Use the drop-down menu to select a resource group to associate the gateway to. If no resource groups are listed, you can Create Resource Group from this screen.

  9. (AWS only) Transit Gateway - Use the drop-down menu to select an available transit gateway for the VPC to assocaite with. If you do not have one available, click create_new to create a transit gateway from this window.

  10. (AWS and Azure only) Use NAT Gateway - Check this option to direct all egress traffic through the NAT gateway. Multicloud Defense automatically creates a NAT gateway for each availability zone that is selected.

  11. (Azure only) If you want to attach a Virtual WAN (VWAN), in vWAN Attachment set the toggle to Enabled .

  12. (Azure only) From the vHub drop-down list, choose a hub.

  13. (Azure only) In the Associate Route Table drop-down list, select a route table to associate.

  14. (Azure only) In the Propagate Route Tables drop-down list, select route tables to propagate.

6.

Click Next.

What to do next

Add a Gateway.


Distributed Model

Use the procedures specific to your cloud service provider for a distributed gateway model.


Azure Distributed Model: Create a Gateway

To create a gateway for your Azure account using the distributed model, follow these steps:

Procedure

1.

In the Multicloud Defense Controller portal click Setup in the left navigation bar.

2.

In the setup wizard, click Secure Account.

3.

Select Distributed so it is highlighted.

4.

Click Next.

5.

Enter the Gateway Information:

  1. Account - Use the drop-down menu to select an Azure account you want to deploy the gateway to.

  2. Name - Enter a name for the gateway. This name is displayed in the Infrastructure > Gateways > Gateways page.

  3. (Optional) Description - Enter a description for the gateway that might help identify it from other gateways.

  4. Instance Type - Use the drop-down menu to select the instance type that deploys the Gateway.

  5. Minimum Instances - Select the minimum number of instances deployed in auto scaling group per availability zone.

  6. Maximum Instance - Select the maximum number of instances deployed in auto scaling group per availability zone.

  7. HealthCheck Port - Enter the healthcheck port number. Multicloud Defense Controller uses 65534 as the default value.

  8. User Name - Enter the user name used to access the gateway once created.

  9. Packet Capture Profile - Use the drop-down menu to select where packets are stored in the cloud storage bucket. If options are not listed, click Create Packet Capture Profile to create one directly from this window.

  10. Log Profile - Use the drop-down menu to select which cloud service provider is used to forward logging to.

  11. Metrics Profile - Use the drop-down menu to select an entity to forward metrics to. If there are no option listed, click Create Metrics Forward Profile to create one from this window.

  12. NTP Profile - Use the drop-down menu to select the NTP profile associated with the gateway. If there are no options listed, click Create to create one from this window.

  13. Security - Select the type of traffic flow your gateway is expected to handle. Ingress security targets traffic that flows from the public internet to a private network; east-west and egress security targets outbound traffic from your private network and traffic moving between your data centers.

  14. Gateway Image - Use the drop-down menu to select the gateway image to be deployed to the gateway.

  15. Policy Ruleset - Use the drop-down menu to select a policy rulset to be deployed and start processing traffic. If there is not ruleset listed, click Create new to create a policy rulset from this window.

  16. Region - Use the drop-down menu to select the region your gateway is deployed to.

  17. VPC/VNet ID - Use the drop-down menu to select the VPC where the gateway is deployed to.

  18. Key Selection - Select either an SSH Public key or an SSH Key Pair. Enter the value that is applied to the gateway in the next text field.

  19. Resource Group - Use the drop-down menu to select an existing resource group that is applied to the gateway.

  20. User Assigned Identity ID - Enter a valid value.

  21. Mgmt. Security Group - Use the drop-down menu to select a security group used for the gateway management interface. Note that if you select a Multicloud Defense-created service VPC, a security group is created specifically for management.

  22. Datapath Security Group - Use the drop-down menu to select a security group used for the gateway datapath interface. If selecting Multicloud Defense-created service VPC, a security group is created specifically for the datapath.

  23. Disk Encryption - Enable disk encryption with either the Azure managed encryption or a customer-managed encryption key. Note that if you opt for a customer-managed encryption key, you need to create and deploy an IAM policy for successful deployment.

  24. Availability Zone - Use the drop-down menu to select an availabililty zone.

  25. Mgmt. Subnet - Use the drop-down menu to select a management subnet for the management interface.

  26. Datapath Subnet - Use the drop-down menu to select a datapath subnet for the datapth interface.

    To add more instance types, click the "+" icon. Subseuqntly, you can remove additional instance types with the "-" icon.

6.

Click Next.

7.

Enter the details for advanced settings.

8.

Click Next.

9.

Review.

What to do next