Alkira > Resources > Integrated Security and Network Services > Cloud Firewall Service Insertion Using Alkira

Cloud Firewall Service Insertion Using Alkira

Cloud Firewall Service Insertion Using Alkira

In our previous blog  for Multi-Cloud Traffic Inspection, we discussed the inline firewall deployment for different types of traffic flows, including east-west, north-south, egress, and ingress (IFA).

We also highlighted many enterprise customers’ firewall deployment challenges in our previous blog, such as it requires manual configuration, setting up the routing and security rules, and managing the firewall. Another challenge is the visibility of traffic and troubleshooting.

In this blog, we will focus on the Alkira capabilities of Cloud Firewall deployment with respect to lifecycle management, autoscaling, and manageability for a multi-cloud environment.

Lifecycle Management

Alkira’s Cloud Area Networking solution completely manages the lifecycle of a cloud firewall (FW); this includes deployment, modification, and deletion of the FW instances. The deployment consists of setting up the interfaces and infrastructure routing.

Figure 1: Creating a Cloud Firewall through Alkira UI Portal

Cloud Firewall Management Integration

Alkira’s Cloud Area Networking solution allows the seamless integration with FW Management systems for each supported vendor, including Palo Alto Panorama, Fortinet FortiManager, and Check Point Security Management.

Figure 2: Palo Alto Panorama Integration with Alkira Cloud Area Networking

Network Segmentation

Network segments created on the Alkira CXP are automatically mapped on a cloud firewall. This allows the routing between the firewall and Alkira CXP to be done seamlessly.

Groups-zones mapping

Using Alkira Cloud Area Networking, micro-segments or Alkira groups map to the firewall security zones, which allows the enterprise to use the same cloud firewalls for different traffic flows.

Figure 3: Cloud Firewall Segmentation and Micro-Segmentation Mapping Configuration

Cloud Firewall Autoscaling

Alkira provides the flexibility to deploy more than one firewall instance of the supported vendors. It also lets the customer decide based on their requirements if they want to deploy a fixed number of firewall instances for high availability or use Alkira’s auto-scaling capability to scale up or down on-demand.

Figure 4: Autoscaling with Fortinet

Policy Framework

Alkira provides a flexible policy framework that allows users to steer traffic per requirement. Using Traffic policies, customers can select what type of traffic they want to inspect based on their match criteria.

Figure 5: Traffic Policy

Figure 6: Policy Inspector

Cloud Firewall Network Visibility

Alkira provides visibility into all traffic that is going to traverse the cloud firewall. Customers can also look at the FW for security policies being applied for that traffic.

Figure 7: Flow Visibility

Cost Benefits

Last but not least, using the Alkira solution, the same set of cloud firewalls can be used for different types of traffic flows, including North-South (on-prem to Cloud), East-West (Cloud-to-Cloud), and Egress/Ingress (Cloud to Internet and Internet to Cloud).

Since the same FWs are being used, it provides significant cost benefits for enterprise customers. Whether in different regions in the same cloud or a multi-cloud environment, the same FWs can be leveraged for all traffic.

Modernize your cloud network with Alkira

Reach out and schedule a demo today to learn more about how Alkira can help simplify cloud networking for your organization.

You can also try our Cloud Insights tool for free, giving instant inventory and insights into your cloud networking resources.

About the Authors:    & 

You May Also Like

Alkira mobile app screens

Introducing the Alkira Mobile App: Network Visibility Wherever, Whenever

Enterprise networks are expected to run 24/7, and the teams responsible for them need visibility wherever work happens. Cloud environments, partner connections, security services, and provisioning workflows are constantly changing. When something needs attention, network and operations teams need a fast way to understand what happened, assess impact, and take the right next step. That...
Jacob Donovan
Simple diagram showing a network as a platform

The Network Needs To Be Part of Your AI Strategy

Enterprises are moving quickly on AI, but many are still running networking models designed for a slower, more centralized and static era. Today’s network has to connect clouds, data centers, campuses, branches, partner environments, and increasingly private AI infrastructure while enforcing consistent policy across all of it. That creates a new operational reality: every new...
Calvin Nguyen
Blue network shield checkmark illustration

Navigating DORA: Operational Resilience and Security by Design

The Digital Operational Resilience Act (DORA) is reshaping how financial institutions in the European Union manage operational risk related to information and communication technology (ICT). As the regulation takes effect, organizations must ensure that their critical ICT service providers support strong operational resilience, risk management, and oversight capabilities. For technology providers supporting financial institutions, this...
Misbah Rehman