Brkent 2006
Brkent 2006
End-Users’ Connections to
Public and Private Clouds
In a SASE World
Ryan Shoemaker, Technical Solutions Architect
CCIE 7405
@ersatzshoe
BRKENT-2006
Agenda
• Introduction to SASE
• SD-WAN Extension into Public Clouds
• SD-WAN and SSE
• Remote Workforce
• Conclusion
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Introduction to
Secure Access
Services Edge
(SASE)
Historic traffic flows
Led to the age of perimeter-based security and networking
Network: Internet
Centralized
TRAFFIC TRAFFIC
Security: Internal 80% Internal 80%
Single, on-premise Internet 20% Internet 20%
security stack Security stack
MPLS VPN
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Changes in the types of traffic and destinations
Have inverted the traffic model
Internet
Problems: SaaS IaaS
Private cloud Browsing
• App
performance
TRAFFIC TRAFFIC
• User experience
Internal 20% Internal 20%
• Security efficacy
Internet 80% Internet 80%
Bottle neck
• # Tools/vendors
• Integrations
MPLS VPN
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Network transformation
Transition from a DC-centric topology to one that’s cloud ready
Private
Internet Apps Internet SaaS
Perimeter security
appliances to protect network
S A S E
MPLS VPN
DC-centric Cloud-Enabled
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Cisco Digital Transformation Architecture
Visibility
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Branch User
Extensions into
Public and
Private Clouds
Cloud Edge Workflows – From Here Cloud Security
DNS/CBFW/SWG/DLP/CASB/RBI
Internet
Cloud
Security
SaaS
Branch
Worker Branch
IaaS
SD-WAN
Fabric
URL TLS
ZBFW IPS AMP
Filtering Proxy
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Cloud Edge Workflows – To Here CDFW
URL
Filtering
IPS AMP
Secure
Web GW
DNS
Security
Internet
SSE
SaaS
Branch
Worker Branch
IaaS
SD-WAN
Fabric
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Cloud Edge Workflows – To Here CDFW
URL
Filtering
IPS AMP
Secure
Web GW
DNS
Security
Internet
SSE
SaaS
Branch
Worker Branch
IaaS
SD-WAN
Fabric
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Extensions to
the Public Cloud
Improving Public Cloud Access CDFW
URL
Filtering
IPS AMP
Secure
Web GW
DNS
Security
Internet
SSE
SaaS
Branch
Bob
Azure
IaaS
AWS
IaaS
SD-WAN
Fabric GCP
IaaS
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Traditional Cloud Service Provider Access
Internet
Region 1
Branch CSP
Gateway
Branch
Worker
SD-WAN Internet
CSP Backbone
Data Center
CSP
Branch Gateway
IaaS
Region 2
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Virtual Routers in CSPs extend SD-WAN
Internet
Region 1
Benefits:
Branch - Simplified control plane
SD-WAN
vRouter integration
MPLS - One Management plane to
Branch connect in CSP locations
Worker
SD-WAN Internet
Challenges:
CSP Backbone
- How to instantiate vRouter?
- Use Marketplace?
- How to connect to SD-
WAN mgmt plane?
- How to connect hosts at CSP
Data Center
SD-WAN
to vRouter?
vRouter - How to define routing protocol?
- How to extend
IaaSsegmentation
strategy?
Region 2
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Orchestrating SD-WAN into Public Clouds
Cisco’s Approach
Benefits
Automate SD-WAN fabric into CSPs
Branch
MPLS
AWS Extend policy framework into cloud
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
CSP Connections with the Cloud GW
Automating AWS Transit GW Integration Internet
Cisco Automation
Branch
Transit VPC Host VPCs
Bob MPLS
VPC
Prod
TGW
VPC
SD-WAN Internet
CGW
Dev
Stuart
VPC
Demo
CGW
IaaS
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
CSP Connection Example – Cloud GW
Dynamic Routing to Host VPCs Internet
BGP
Stuart
Infra
VRF 20
Route Table: SD-WAN Internet
CGW Route 10.22.10.0/24
10.22.10.0/24 (Dev) Table
Dev VPC
BGP
CGW
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Automating Cloud Extensions in SD-WAN
Cloud OnRamp for Multicloud
1. Select Cloud OnRamp for Multicloud
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Automating Cloud Extensions in SD-WAN
Cloud OnRamp for Multicloud*
1. Select Cloud OnRamp for Multicloud
*Screenshots are of Catalyst SD-WAN Manager 20.13 BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Automating Cloud Extensions in SD-WAN
Cloud OnRamp for Multicloud*
1. Select Cloud OnRamp for Multicloud
*Screenshots are of Catalyst SD-WAN Manager 20.13 BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Automating Cloud Extensions in SD-WAN
Cloud OnRamp for Multicloud*
1. Select Cloud OnRamp for Multicloud
*Screenshots are of Catalyst SD-WAN Manager 20.13 BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Automating Cloud Extensions in SD-WAN
Cloud OnRamp for Multicloud*
1. Select Cloud OnRamp for Multicloud
*Screenshots are of Catalyst SD-WAN Manager 20.13 BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Automating Cloud Extensions in SD-WAN
Discover Host Private Networks
*Only Tagged VPCs will be available to map to SD-WAN VRFs
2. Add Tag
A. Name
B. Select Region
C. Select VPC
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Automating Cloud Extensions in SD-WAN
Stage C8Kvs for Cloud Gateway
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Automating Cloud Extensions in SD-WAN
Stage C8Kvs for Cloud Gateway
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Automating Cloud Extensions in SD-WAN
Create Cloud Gateway
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Reference
Automating Cloud Extensions in SD-WAN
Validating Deployment
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Automating Cloud Extensions in SD-WAN
Managing Intent
1. Select Cloud OnRamp for
Multicloud
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Reference
Automating Cloud Extensions in SD-WAN
Validating Intent
C8K – VRF 10 Routing Table – Prod and C8K – VRF 20 Routing Table – Dev VPC
Demo VPCs present present
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
CSP Connection Example – Cloud GW
AWS Transit GW Integration Region 1
Internet
Transit VPC
VPC
A
TGW
VPC
Branch CGW
B
MPLS VPC
C
Bob CGW
SD-WAN Internet
Transit GW Peering
VPC
D
CGW
VPC
E
Data Center
TGW
VPC
F
CGW IaaS
Transit VPC
Region 2
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
CSP Connection Example – Direct Connect
AWS Transit GW Integration Region 1
Internet
Transit VPC
VPC
A
TGW
Direct DXGW
Connect
VPN or Direct VPC
Branch CGW
Attachment B
MPLS VPC
C
Bob CGW
SD-WAN Internet
Transit GW Peering
VPC
D
Region 2
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Optimizing
Extensions to
the Public Cloud
What is the Middle Mile?
First mile Middle mile Last mile
WAN service, internet, SP core network, CSP network, ASN,
or private networks private network, ASN or private networks
Internet Route
AS4
AS5
AS3
Local Direct
Transport
Access Peering
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
What are we enabling with Cloud Interconnect?
Cisco SD-WAN service hosted at global colocation facilities. Megaport and Equinix are the first to
host our SD-WAN service.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Optimizing the Network Cloud
On-demand Connectivity
Region 1 “The Middle Mile” Reduce time from months to minutes
Sites
* for Multicloud connectivity
Connections worldwide
Programmability
Direct Connect / Dynamic/Automated High-Speed
Local Access Cross-Connects
Express Route
Controller APIs for partner orchestration
Cloud Management
Local Direct Peering
LocalAccess
Access Automate the connections through
single pane of glass
Colo
Colo Colo
Colo
Cisco Webex
Performance & Control
Region 2
Remove congestion risk by sending packets through a
Sites private backbone
Dynamic/Automated High-Speed
Cross-Connect
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Adding Cloud Interconnects
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
SSE
SaaS
Branch
Worker Branch
Megaport
IaaS
SD-WAN
Middle Mile
Fabric
Optimizations
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Adding Cloud Interconnects
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
SSE
SaaS
Branch
Worker Branch
IaaS
Megaport
Middle Mile
Optimizations
Private
SD-WAN DC
Fabric Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Optimizing Connection to CSP
… and to Other Sites
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
SSE
SaaS
Branch
Worker Branch
IaaS
Megaport
Middle Mile
Optimizations
Private
SD-WAN DC
Fabric Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Cloud Interconnect with SDCI
Option 2: Encrypted Multicloud Interconnects
Internet
CSP
CGW
Virtual
Branch
Workloads
ICGW
Branch
Worker CGW
Virtual Cross
Connect(s) (VXC)
SD-WAN
Transit VIF*
ICGW
DXGW TGW
Data Center
Public or Private
Public or Private
ERGW
vWAN
Virtual
Branch
Workloads
ICGW
Branch
Worker CGW
Virtual Cross
Connect(s) (VXC)
Transit VIF*
ICGW
DXGW TGW
Data Center
Public or Private
Public or Private
ERGW
vWAN
CGW
AWS VPC
A
DXGW
VPC
Branch
B
ICGW
TGW VPC
Branch C
Worker CGW
CGW VNet
D
ICGW
VNet
E
Data Center
vWAN
ERGW VNet
F
CGW Azure
Region 2
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Site Interconnect Connection Example
Megaport and Encrypted Multicloud EMEA North Region
Internet
Corp Region EUR North
CGW AWS VPC
Megaport Virtual A
Edge (MVE) DXGW
ICGW VPC
Branch EUR North 1 B
TGW
VPC
C
CGW
CGW VNet
D
ICGW
VNet
ICGW E
US East Region
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Automating Cloud Interconnects in SD-WAN
Cloud OnRamp for Multicloud
1. Select Cloud OnRamp for Multicloud
2. Select Interconnect
*Note: Two unique colors must be set – ensure they are private and not
used elsewhere in SDWAN
1. Transit Color – used for ICGW to ICGW connections
2. CGW SDWAN Color – used for ICGW to CGW
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Automating Cloud Interconnects in SD-WAN Reference
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Automating Cloud Interconnects in SD-WAN
Interconnect Connectivity
1. Once ICGW finishes deployment,
configure Interconnect Connectivity
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Automating Cloud Interconnects in SD-WAN
Interconnect Connectivity
1. Once ICGW finishes deployment,
configure Interconnect Connectivity
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Automating Cloud Interconnects in SD-WAN
Interconnect Connectivity
1. Once ICGW finishes deployment,
configure Interconnect Connectivity
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Automating Cloud Interconnects in SD-WAN
Interconnect Connectivity
1. Once ICGW finishes deployment,
configure Interconnect Connectivity
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Automating Cloud Interconnects in SD-WAN
Interconnect Connectivity
1. Once ICGW finishes deployment,
configure Interconnect Connectivity
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Reference
Automating Cloud Interconnects in SD-WAN
Validating Intent
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Want to Learn More?
Additional Sessions:
BRKENT-2283 4 Steps to Unify Multicloud Connectivity and Design with Cisco SD-WAN
Principles
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Optimizing and
Securing Public
Applications
Optimizing SaaS Flows SLA Measurement
of SaaS Apps
Branch ISP1
Worker Branch
SD-WAN
ISP2 Evolution of Cisco SD-WAN:
Fabric
- Historically leveraged to measure app
performance for on-prem apps
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Cloud OnRamp for SaaS
DNS ISP1
ISP Score SaaS
HTTP
ISP1
✓ 1 10 Application
DNS
ISP2
2 8
DNS requests is
User duplicated across all vQoE Scores are
available Internet HTTP ping packets calculated based on
egress points or are sent to probe the loss/ latency for
Gateway sites (loss/latency) path selection
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
57
Optimizing SaaS Flows
Measure loss and
vQoEpath
latency for best = 10
Enterprise
Apps
ISP1
Branch
Measure loss and
ISP2
latency for vQoE =8
best path
Bob
SD-WAN
Fabric • Router collects average loss and latency of
several 2 minute buckets
IaaS
• If actual loss and latency are less than expected,
app receives vQoE of 10
• If actual loss and latency are more than expected,
then app receives score of percentage of baseline
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Cloud OnRamp for Custom App
Bring Your Own App to Cloud OnRamp for SaaS
Extend Cloud OnRamp for SaaS support
across all apps
1500+
NBAR Recognized Apps
+
Any Custom App
BENEFITS
Dynamically route SaaS traffic Fast, secure and reliable user Gain real-time and historical visibility
to the best path experience into application performance
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Cloud Security
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
SSE
SaaS
Branch
Worker Branch
IaaS
SD-WAN
Fabric
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
SD-WAN and Cloud Security
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Cloud Security for Branch Users
Primary Function is Securing Internet Applications and Flows
Branch Internet
Worker
Branch
SaaS
DNS Non-Web
FW/IPS NAT
Security
Web Traffic
SWG CASB DLP
SSE
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Cloud Security for Branch Users
Primary Function is Securing Internet Applications and Flows
L3/4 and L7 firewall rules – web traffic is directed for additional checks
SSE
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Cloud Security for Branch Users
Primary Function is Securing Internet Applications and Flows
DNS
Protects at DNS layer – preventing access to malicious sites
Security
FW/IPS L3/4 and L7 firewall rules – web traffic is directed for additional checks
SWG Secure Web Gateway – policy for internet traffic, SSL decryption, RBI
CASB Content Access Security Broker – policy for SaaS applications, prevent shadow IT
DLP Data Loss Prevention – policy to protect data, multimode for in-line and out of band
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
SD-WAN and Secure Access
Integration
Enterprise
Apps
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Weighted Load-Balancing
ECMP
Cisco Secure
Cisco Load balancing is done by flow pinning, where a Access
flow is dictated by hashing the 4 Tuple
ECMP ECMP
IPSec
IPSec
load-balancing load-balancing
1:1 1:1
IPSec
IPSec
Source IP + Destination IP + Source Port + Destination 80% 20%
Port.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Catalyst SD-WAN and Secure Access Integration
Policy Groups – Adding Tunnels
• Add Secure Service Edge
• Tracker source IP address –
required, any 1918 address
• Add tunnel(s) for each
connection to Secure Access
• Each active/backup pair needs
unique source interface - if
multiple tunnels will use same
physical interface, then source
tunnel using Loopbacks
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Catalyst SD-WAN and Secure Access Integration
Policy Groups – Choosing HA
• Automatically or manually
choose Secure Access region
• Add Interface Pair – Up to 8
active + 8 backup tunnels
allowed
• Select active and backup
interfaces and weight for each
– default is ECMP
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Catalyst SD-WAN and Secure Access Integration
Policy Groups – Assigning SSE
1. Add Policy Group
2. Select SSE
Configuration
3. Save Policy Group
4. Associate Device(s)
5. Deploy
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Verify Integration
Cisco Secure Access
• Tunnels Connected at
Secure Access
• Leverage Network
Tunnel Group for all
tunnels from router
• Enables simplified policy
rules to enforce for all
traffic coming form
router 4 IPSec tunnels:
2 Primary
2 Secondary
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Directing Traffic to Secure Access
Cisco Secure
Access
IPSec
IPSec
All Traffic Google
SFDC
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Reference
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Remote Worker
Connecting to
Workloads
Extend Protection to Remote Workers
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
Remote
Worker SSE
SaaS
Bob
Private
DC
Data
Branch Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Cisco Secure Client
Suite of security service enablement modules
Internet
Remote
Worker SSE
Bob SaaS
Regional
Hub
IaaS
VPN Service
SD-WAN
(SDWAN RA)
Fabric
Private
DC
Data
Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Connecting Remote Workers to Internal Workloads
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
Remote
Worker SSE
Bob SaaS
Regional
Hub
IaaS
VPN Service
SD-WAN
(SDWAN RA)
Fabric
Private
DC
Data
Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Optimizing Remote Workers to Internal Workloads
URL Secure DNS
CDFW IPS AMP Security
Filtering Web GW
Internet
Remote
Worker SSE
Bob SaaS
IaaS
Regional Megaport
Hub
VPN Service
(SDWAN RA) Middle Mile
Optimizations
Private
SD-WAN DC
Fabric Data
Center
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Enabling a Distributed Remote Access
Benefits
• Extends SD-WAN benefits to RA users
• Application visibility, AAR, AppQoE
• Integrated into SD-WAN segmentation
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Conclusion
Cisco SASE Workflows
Any Location to Any Workload Cloud Security
DNS/CBFW/SWG/DLP/CASB/RBI
Internet
Cloud
Security
Remote Worker
SSO SaaS
Remote
Access
Megaport
Branch
IaaS
Middle Mile
Optimization
Branch Worker
Private
Data DC
Center
Branch
SD-WAN
Fabric BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Optimizing and Protecting All Workflows
• Secure Edge workloads can be easily extended to CSPs through SD-
WAN built in automation
• Partnerships with Co-Lo’s provide enhanced connections to both CSPs
and other sites
• Rich integrations between SD-WAN and Cisco Secure Access allow on-
prem workers to be secured easily
• Inspection of SaaS performance from SD-WAN fabric provides an
optimized path for inside to outside workloads
• Remote Access VPN capabilities integrated into SD-WAN fabric provide
a distributed, optimized path for outside to inside workloads
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Thank you
Reference
Catalyst SD-WAN and Umbrella
Simple, effective integration for DNS Security
Ashburn New York
• Auto-Deploy DNS integration with (Primary DC) (Backup DC)
Umbrella APIs Cloud
Cloud
Security Security
• Anycast architecture for highly available
integration – directs clients to not just
closest DC but also includes awareness of
load distribution
• Macro-segmentation extension through
VPN/VRF aware identity sources
Anycast IP
• DNScrypt support for enhanced security
• Local domain bypass
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Integrating Viptela SD-WAN to Umbrella DNS
1.
2.
1. Select Configuration -> Security
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Viptela and Umbrella DNS (Cont.)
4.
4. Add Unified Security Policy
5. Skip NG Firewall to move to DNS
5.
Security and Add DNS Security
Policy
6. Complete Data for Policy
A. Note: Umbrella Registration 6.
Status will display green flag if
registered correctly
B. Choose match all VPNs or
subset
C. Create a domain bypass list for
local domains
D. Under Advanced, ensure
DNSCrypt is enabled to convey
source VPN info to Umbrella
E. Save DNS Policy
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Viptela and Umbrella DNS (cont.)
7.
7. Name and save security policy
8. Assign policy to template
A. either traditional template
B. or UX2.0
8a.
8b.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Viptela and Umbrella DNS (cont.)
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Umbrella DNS in Action
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Viptela and Umbrella Integration
Layer on Full Umbrella SIG
• Auto-provision and Auto-deploy highly
available tunnels with a few clicks
• Active-Active and Active-Standby design
• Support for auto or manual DC selection
• ECMP or weighted load-balancing
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Viptela and Umbrella Integration
Layer on Full Umbrella SIG Enterprise
Apps
Miami
• Auto-provision and Auto-deploy highly Dallas (Primary DC)
(Backup DC)
available tunnels with a few clicks
Cloud Cloud
• Active-Active and Active/Standby design Security Security
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Integrate SD-WAN with Umbrella SIG
Create Umbrella API Key 1.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Integrate SD-WAN with Umbrella SIG
3.
5. SIG feature template:
A. A. Create number of IPSec Tunnels
B. Identify A/A or A/S configuration
C. Allow auto selection of SIG DCs or select
manually
B.
5.
A.
3. SIG integration in device template:
A. SIG feature template added to VPN0
B. For multiple active tunnels, need multiple source
interfaces (can by physical or loopback)
B.
4. Verify Cisco SIG Credentials under Additional Templates
has automatically selected “Cisco-Umbrella-Global-
Credentials” C.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Viptela and Umbrella SIG
7. Assign Tunnels as Identities
6. In Umbrella Dashboard,
for FW and Web Policies in:
Tunnels appear automatically
Policies -> (Firewall or
in: Core Identities ->
Web) <Policy> -> Ruleset
Network Tunnels
Identities -> Edit
6. 7.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Viptela and Umbrella SIG
8.
8. Select the Number next to
“Tunnels” to get a list of all
Network Tunnels and then
check the applicable tunnels
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Viptela and Umbrella SIG
6.
8.
7.
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Umbrella SIG in Action
BRKENT-2006 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 101